Visualização normal

Antes de ontemStream principal
  • ✇Malwarebytes
  • Healthcare giant Abbott probes two cyber incidents amid extortion claims
    Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked da
     

Healthcare giant Abbott probes two cyber incidents amid extortion claims

20 de Julho de 2026, 11:31

Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.

The incidents reportedly involve Abbott’s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.

According to a statement released by Abbott on July 16:

“Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only. This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.”

Regarding LabCentral, Abbott told reporters that it is an externally hosted portal and that there has been “no known exposure of sensitive customer or business information.”

ShinyHunters told BleepingComputer it stole internal documents, contracts, customer information, more than 22 million doctor‑patient notes, over 20 million medical orders, and more than one million US Social Security numbers, along with personally identifiable information (PII) such as names, addresses, dates of birth, emails, and phone numbers.

On July 18, ShinyHunters gave Abbott until July 21 to respond before leaking the alleged data:

Extended deadline
Extended deadline

“This is a final warning to reach out by 21 July 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline”

The threat of “digital problems” is a familiar one from ShinyHunters. During the Canvas attacks, the group defaced school login pages and the Canvas app with an on‑screen ransom message.

Separately, ShadowByt3$ claims it accessed the LabCentral portal on July 4, using compromised customer credentials plus a “weak point” in the environment, allegedly exfiltrating technical documentation, manufacturing certificates, operating manuals, technical specs, and regulatory docs for Abbott lab systems.

If the attackers’ claims prove accurate, the breach could affect healthcare providers that use Abbott’s diagnostic systems and potentially expose sensitive patient and healthcare data. Abbott, however, says it has found no evidence that sensitive customer or business information was exposed through the LabCentral incident and has not confirmed any patient data was compromised.

What we can reasonably assume to be true

  • There was a genuine compromise affecting Cancer Diagnostics systems. Abbott has publicly acknowledged unauthorized access and engaged incident response and law enforcement. This doesn’t appear to be a purely “fake” extortion attempt.
  • There was also a separate cyber incident involving the LabCentral portal. Abbott says the portal primarily hosts public reference material and that it has found no evidence that sensitive customer or business information was exposed.
  • Both ShinyHunters and ShadowByt3$ have listed Abbott on their extortion sites and have provided narrative details to media outlets, so this is not just generic name‑dropping.
  • As of the latest reporting, neither group has publicly released samples of the data they claim to have stolen.

What Abbott customers can do

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose and store one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for impersonation scams. Criminals may contact you pretending to be the company. Check the company’s website to see how it is contacting affected customers, and verify anyone who contacts you using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and create a false sense of urgency with messages about missed deliveries, suspended accounts, or security alerts.
  • Consider not storing your card details. It’s definitely more convenient to get sites to remember your card details for you, but we highly recommend not storing that information on websites.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online and helps you recover if your identity is stolen.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse

Nintendo America employee records were exposed via TinyPulse after Shadowbyt3 claimed theft of HR files, tax forms, bank data, and staff survey responses.
  • ✇Firewall Daily – The Cyber Express
  • Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack Ashish Khaitan
    Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees.  In a statement addressing the TinyPulse cyberattack, Nintendo said it was aware of an issue involving TinyPulse,
     

Nintendo Confirms Employee Data Exposed in TinyPulse Cyberattack

TinyPulse cyberattack

Nintendo of America has confirmed that employee survey data was exposed in the recent TinyPulse cyberattack, although the company emphasized that its own systems were not breached and that no customer or financial information was accessed. The disclosure follows claims by the threat actor Shadowbyt3$, which alleged it had stolen sensitive information linked to Nintendo employees.  In a statement addressing the TinyPulse cyberattack, Nintendo said it was aware of an issue involving TinyPulse, a third-party platform used for internal employee surveys. According to the company, the incident was limited to data held by the service provider rather than Nintendo's internal infrastructure.  “We are aware of an issue involving TinyPulse, a third-party service used for internal employee surveys at Nintendo of America,” Nintendo stated.  The company further clarified that “Nintendo’s systems have not been compromised, and no personal customer or financial data has been accessed.” 

Nintendo Says Exposure Was Limited in the TinyPulse Cyberattack

According to Nintendo, the data affected by the TinyPulse cyberattack consisted of internal survey content involving only a small subset of employees. The company added that most of the information dated back several years.  “The data involved is limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years,” Nintendo told media outlets.  Nintendo of America, a subsidiary of the Japanese gaming giant Nintendo, oversees operations across the United States, Canada, and parts of Latin America. TinyPulse is an employee engagement and feedback platform that supports anonymous surveys, workplace culture assessments, engagement analytics, and feedback collection.  Nintendo said it is currently “working with the service provider to address the issue.”  The Cyber Express has also reached out to Nintendo for additional details regarding the TinyPulse cyberattack. However, no further statement had been received at the time of publication. 

Shadowbyt3$ Claims Broader Data Theft

Despite Nintendo's assessment of the incident, the threat actor Shadowbyt3$ has claimed that the stolen information extends beyond employee survey responses and includes personal employee data.  In an initial message, Shadowbyt3$ alleged that nearly 1GB of data had been exfiltrated from Nintendo and gave the company 48 hours to enter negotiations before the information would be leaked.  The threat actor claimed the dataset contains full names, email addresses, analytics and survey data, bank statements, W-9 forms with employee IDs, progress plans, and reports spanning from 2016 to 2026.  “If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars,” the Shadowbyt3$ post stated. 

Threat Actor Issues Additional Warnings

In a follow-up message, Shadowbyt3$ clarified that the alleged breach “doesn't affect nintendo gaming” but instead impacts “a small amount of employees that work for nintendo and have used tinypulse.”  The threat actor later published another post warning that more victims would emerge. The message included a link to allegedly leaked data containing direct messages and employee conversations, suggesting Nintendo did not agree to pay the $2 million ransom demand.  As of now, Nintendo maintains that the TinyPulse cyberattack was limited in scope and did not compromise its internal systems, while Shadowbyt3$ continues to assert that more sensitive employee information was stolen. 
❌
❌