Abbott Laboratories is investigating two separate cybersecurity incidents involving unauthorized access to internal systems and alleged data theft, with attackers reportedly making extortion demands.
Abbott Laboratories confirmed it is probing two distinct cyber incidents affecting its operations. The first involves unauthorized access to legacy systems within its Cancer Diagnostics business unit, which operates under the Exact Sciences brand. The second investigation centers on a breach of the company's LabCentral portal, where attackers allegedly stole company data.
According to the company's findings, unauthorized parties gained access to internal Exact Sciences infrastructure. The scope and nature of data accessed through the Cancer Diagnostics systems breach remain under investigation.
Separately, Abbott is examining claims that the LabCentral portal was compromised in a distinct attack. Threat actors have reportedly made extortion demands in connection with the alleged LabCentral breach, a common tactic used by cybercriminals to pressure organizations into paying ransoms or fees.
Abott has not disclosed the extent of data potentially compromised through either incident or confirmed whether extortion demands have been made regarding both breaches or only the LabCentral incident. The company is working to assess the full scope of unauthorized access and determine what information may have been exposed.
The incidents underscore ongoing cybersecurity challenges facing healthcare and diagnostics companies, which handle sensitive patient and operational data. Such organizations remain high-value targets for cybercriminals seeking valuable intellectual property, patient information, and operational data they can leverage for extortion schemes.
Abott did not provide a timeline for completing its investigation or indicate whether it has notified affected customers or regulatory authorities. The company said it is taking the incidents seriously and working to secure its systems. Further details about the breaches, including potential impacts and remediation steps, are expected as investigations progress.
A critical remote code execution vulnerability affecting all Chromium versions is currently being exploited in the wild. The flaw bypasses the browser's sandbox protection, allowing attackers to execute arbitrary code with full system access.
Mullvad is discontinuing its public encrypted DNS servers and redirecting resources to sponsor Quad9, an alternative privacy-focused DNS provider. The move consolidates the privacy DNS landscape.
Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.