Skip to main content
Home/Blog/ShinyHunters Just Vished Their Way Into a Medical Device Giant. Your Business Is Next.
Cybersecurity

ShinyHunters Just Vished Their Way Into a Medical Device Giant. Your Business Is Next.

Abbott Laboratories disclosed two simultaneous cyber incidents last week — both traced to social engineering. Here's what every business leader needs to understand about healthcare data risk, vishing attacks, and why your employees are your biggest exposure right now.

July 20, 2026·7 min read

Last Friday, Abbott Laboratories — one of the largest medical device and diagnostics companies in the world — disclosed not one but two simultaneous cybersecurity incidents. Both happened within weeks of each other. One was traced directly to a vishing attack that compromised employee accounts. The other involved an unauthorized intrusion into an external portal.

The threat actor behind the first incident? ShinyHunters, the same group responsible for breaching Medtronic earlier this year. Their method was the same too: they called Abbott employees, impersonated IT support, and talked their way into a Microsoft Entra single sign-on account. From there, they claim to have accessed systems including SharePoint, ServiceNow, Databricks, and Coupa — walking away with what they allege is more than 30 million rows of customer personally identifiable information, including over one million Social Security numbers, and more than 22 million clinical notes containing doctor-patient conversations.

Abbott says its operations are unaffected and the incident is contained. ShinyHunters has set a deadline of July 21 to negotiate or they publish. The investigation is ongoing.

Let that sink in for a moment. A Fortune 500 healthcare company with a dedicated security team was social-engineered through a phone call.

The Phone Call Is Still the Most Dangerous Tool in an Attacker's Kit

We spend enormous amounts of money on firewalls, endpoint detection, MFA rollouts, and vulnerability scanning. And attackers look at all of it and say: that's fine, we'll just call someone.

Vishing — voice phishing — is not new. What has changed is the sophistication and the targeting. ShinyHunters didn't cold-call Abbott's main line and guess. They researched employees, identified specific roles likely to have access to IT systems or credentials, and conducted what reads as a highly targeted, operationally prepared social engineering campaign. They knew what they were looking for before they dialed.

The same group used the exact same playbook against Medtronic in April — calling employees, compromising an account, spending six days inside the system before detection, and ultimately exposing 3.8 million patients.

Two major healthcare companies, same threat actor, same entry vector, within three months of each other. This isn't a pattern emerging. This is an established, repeatable attack model that is actively working.

Two Incidents at Once: The Dual-Front Attack Problem

What makes the Abbott situation especially instructive for business leaders is that they were managing two separate incidents simultaneously. While the internal cancer diagnostics breach was being investigated, a second threat actor — using the name ShadowByt3$ — independently claimed access to Abbott's LabCentral customer portal, exploiting compromised customer credentials to access API endpoints over days.

Two different attackers. Two different entry points. Same company. Same week.

This is not unusual anymore. When an organization shows up on a threat actor's radar — or when one breach signals that a target has soft spots — other groups test the perimeter too. Security incident response is hard enough when you're focused on one breach. Managing two simultaneously, while maintaining business continuity and navigating legal disclosure requirements, is a different problem entirely.

What the Data Being Claimed Means in Practice

ShinyHunters claims 30 million customer records with names, emails, phone numbers, addresses, dates of birth, and more than one million Social Security numbers. They also claim 22 million clinical notes — doctor-patient conversations from diagnostics interactions.

We don't know yet how much of this is accurate. Breach claims frequently exceed actual data exposure. But here is what matters for your risk calculus: even a fraction of that data, in the wrong hands, represents significant exposure.

Medical records with SSNs and clinical notes are the highest-value data available. They don't expire. They can't be reset. They enable targeted fraud, identity theft, medical identity theft, and insurance fraud at a scale that harms real people for years.

And here's the part that should keep executives awake: Abbott did not know this was happening for weeks. The vishing attack succeeded in mid-June. The disclosure came July 17. That's a month of dwell time — during which ShinyHunters was negotiating, claiming access, and positioning for either a ransom payment or a data sale.

Three Questions Every Business Leader Should Ask Right Now

You don't need to be in healthcare for this story to be relevant. Every organization that stores customer data, employee records, or operational information is a target. Here are the questions that matter:

1. Can your employees recognize and report a vishing attempt? Security awareness training that doesn't explicitly cover vishing — with realistic simulations of IT impersonation calls — is incomplete. Your people are your first and last line of defense when a threat actor calls. Do they know what to do? Do they know they can hang up and verify through official channels?

2. What access does a compromised SSO account actually have? ShinyHunters compromised one Entra account and allegedly walked into SharePoint, ServiceNow, Databricks, and Coupa simultaneously. If one credential gives a threat actor that kind of lateral reach, your least-privilege access model has gaps. Map it. Understand what a single compromised identity can actually touch.

3. How quickly would you know? Abbott had a month before disclosure. Some incidents run longer. If a threat actor was inside your systems today, how many days before your team would detect the anomaly? What does your monitoring actually cover? If the honest answer is 'I don't know,' that's where the conversation with your security team should start.

The Bigger Pattern Here

We are now firmly in an era where the human layer is the primary attack surface. Not unpatched software, not misconfigured cloud buckets — people. Specifically: employees who receive a convincing phone call from someone who sounds like IT and asks for help with a quick access verification.

ShinyHunters exploited this at Medtronic. They exploited it at Abbott. The passkey-hijacking campaign we wrote about last week exploited the same pattern through Microsoft 365. These aren't isolated incidents. They're a concentrated, coordinated push by financially motivated threat actors who have found that phone calls are cheaper and more reliable than zero-days.

Your security stack can be excellent and still be defeated by a well-researched call to the right employee at the right moment. The organizations that close this gap are the ones investing in human-layer security just as seriously as they invest in technology.

What TrustPoint Cyber Recommends

If you want to reduce your exposure to this class of attack, start with three things: a targeted vishing simulation program to test and train your people under realistic conditions; a privilege audit to map what a single compromised identity can actually access; and an incident detection review to establish honest baseline timing on how quickly your team would know something was wrong.

These aren't multi-year projects. They're conversations and assessments you can start this week. The threat actors are not waiting for your next security budget cycle.

If you'd like to understand where your organization stands, that's exactly the kind of assessment TrustPoint Cyber does. Reach out — and let's have the conversation before the threat actor does.

Get Protected

Ready to strengthen your security?

TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.