Skip to content
Cyber Security Firms
ConfirmedHealthcare

Exact Sciences Data Breach (July 2026)

Attackers reached legacy systems at the Cologuard maker, now part of Abbott, and Have I Been Pwned verified 10.9 million records containing names, contact details, dates of birth and health information after ShinyHunters published them.

Disclosed Updated
Organization
Exact Sciences
Country
United States, WI
Incident date
July 15, 2026
Disclosed
July 16, 2026
Records affected
10.9 million
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Email addresses
  • Names
  • Physical addresses
  • Phone numbers
  • Dates of birth
  • Genders
  • Personal health data
Timeline
  1. Voice phishing calls to Abbott employees, according to the group's account reported by BleepingComputer and relayed by HIPAA Journal
  2. Unauthorized access to legacy Exact Sciences cancer diagnostics systems, per the Have I Been Pwned breach date
  3. Abbott announces the intrusion, saying it does not expect a material impact on the business
  4. The group's publication deadline, extended after negotiation, passes
  5. Have I Been Pwned loads 10.9 million verified email addresses from the published data

What Happened

Exact Sciences makes the Cologuard at-home colorectal cancer screening test and was acquired by Abbott Laboratories in late 2025. On July 16, 2026, Abbott announced that an unauthorized third party had accessed certain legacy Exact Sciences cancer diagnostics systems, that those systems were separate from Abbott's own, and that it did not expect a material effect on the business, according to HIPAA Journal's account.

The ShinyHunters extortion group claimed responsibility and threatened to publish the data if it was not paid. HIPAA Journal reports that Abbott negotiated and the publication deadline was pushed to July 21. The data was later published. On August 7, Have I Been Pwned loaded 10.9 million unique email addresses from it, belonging to customers, patients and healthcare providers, alongside names, addresses, phone numbers, dates of birth, genders and health records. Abbott's public notice, as quoted by Have I Been Pwned, said that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once the review was complete.

The attack type is recorded as social engineering on the strength of the group's own account, relayed by BleepingComputer and reported by HIPAA Journal: voice phishing calls to Abbott employees in mid-June that compromised a single sign-on account. Abbott has not confirmed that route. The group also claimed one million Social Security numbers were in the data; that figure is a claim, not a verified count, and it is not in the Have I Been Pwned data classes.

A patient has since filed a proposed class action against Abbott and Exact Sciences, per BankInfoSecurity.

What was Exposed

This is a health data breach, which puts it in a different category from a retail leak. The verified classes include personal health data alongside the identity details, which means a stranger can know that a specific named person, at a specific address, was screened for colorectal cancer, and potentially what the result was.

The practical risks are two. First, targeted fraud: a call or letter that references your test, your doctor or your result is far more convincing than a generic scam, and the data supports exactly that. Second, the Social Security number claim: unverified, but if it is true, the exposure is identity theft rather than spam.

What to do if you are Affected

The full sequence, including the difference between a freeze and a fraud alert, is in what to do after a data breach. The other healthcare breaches on record here show how often this sector is hit through exactly this route.

What is not Known Yet

The confirmed number of individuals, whether Social Security numbers were in the data, and what Abbott's completed review says about the health information involved. Under HIPAA the breach will also appear on the HHS Office for Civil Rights portal once reported, and that entry will fix the individual count.

Sources

  1. Have I Been Pwned: Exact Sciences
  2. HIPAA Journal, Abbott Investigating Cyberattack Claims From Two Threat Actors
  3. BankInfoSecurity, Patient Sues Abbott Labs, Exact Sciences in Data Theft
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →