Exact Sciences Data Breach (July 2026)
Attackers reached legacy systems at the Cologuard maker, now part of Abbott, and Have I Been Pwned verified 10.9 million records containing names, contact details, dates of birth and health information after ShinyHunters published them.
- Organization
- Exact Sciences
- Sector
- Healthcare
- Country
- United States, WI
- Incident date
- July 15, 2026
- Disclosed
- July 16, 2026
- Records affected
- 10.9 million
- Attack type
- Social engineering
- Threat actor
- ShinyHunters
- Status
- Confirmed
- Email addresses
- Names
- Physical addresses
- Phone numbers
- Dates of birth
- Genders
- Personal health data
- Voice phishing calls to Abbott employees, according to the group's account reported by BleepingComputer and relayed by HIPAA Journal
- Unauthorized access to legacy Exact Sciences cancer diagnostics systems, per the Have I Been Pwned breach date
- Abbott announces the intrusion, saying it does not expect a material impact on the business
- The group's publication deadline, extended after negotiation, passes
- Have I Been Pwned loads 10.9 million verified email addresses from the published data
What Happened
Exact Sciences makes the Cologuard at-home colorectal cancer screening test and was acquired by Abbott Laboratories in late 2025. On July 16, 2026, Abbott announced that an unauthorized third party had accessed certain legacy Exact Sciences cancer diagnostics systems, that those systems were separate from Abbott's own, and that it did not expect a material effect on the business, according to HIPAA Journal's account.
The ShinyHunters extortion group claimed responsibility and threatened to publish the data if it was not paid. HIPAA Journal reports that Abbott negotiated and the publication deadline was pushed to July 21. The data was later published. On August 7, Have I Been Pwned loaded 10.9 million unique email addresses from it, belonging to customers, patients and healthcare providers, alongside names, addresses, phone numbers, dates of birth, genders and health records. Abbott's public notice, as quoted by Have I Been Pwned, said that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once the review was complete.
The attack type is recorded as social engineering on the strength of the group's own account, relayed by BleepingComputer and reported by HIPAA Journal: voice phishing calls to Abbott employees in mid-June that compromised a single sign-on account. Abbott has not confirmed that route. The group also claimed one million Social Security numbers were in the data; that figure is a claim, not a verified count, and it is not in the Have I Been Pwned data classes.
A patient has since filed a proposed class action against Abbott and Exact Sciences, per BankInfoSecurity.
What was Exposed
This is a health data breach, which puts it in a different category from a retail leak. The verified classes include personal health data alongside the identity details, which means a stranger can know that a specific named person, at a specific address, was screened for colorectal cancer, and potentially what the result was.
The practical risks are two. First, targeted fraud: a call or letter that references your test, your doctor or your result is far more convincing than a generic scam, and the data supports exactly that. Second, the Social Security number claim: unverified, but if it is true, the exposure is identity theft rather than spam.
What to do if you are Affected
The full sequence, including the difference between a freeze and a fraud alert, is in what to do after a data breach. The other healthcare breaches on record here show how often this sector is hit through exactly this route.
What is not Known Yet
The confirmed number of individuals, whether Social Security numbers were in the data, and what Abbott's completed review says about the health information involved. Under HIPAA the breach will also appear on the HHS Office for Civil Rights portal once reported, and that entry will fix the individual count.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.