Skip to content
FortaRisks
Back to blogThreat Intelligence

Abbott: one phone call was enough

July 29, 2026 · 4 min read

In mid-July, medical technology giant Abbott confirmed it is investigating two separate cyber incidents. The more serious one is claimed by ShinyHunters, one of the most active extortion groups of the moment: according to the group's account to the trade press, it all began in mid-June with a voice phishing campaign, phone calls to employees impersonating internal IT support, ending in the compromise of a Microsoft Entra SSO account.

Abbott, for its part, confirms unauthorized access to "a limited number of internal systems," confined to its Cancer Diagnostics business, on systems inherited from its acquisition of Exact Sciences and separate from its core environment. The company states there is no operational impact and "no known exposure of sensitive customer or business information." The group claims tens of millions of records, figures no independent source has validated to date, and has placed Abbott on its leak site with an ultimatum.

Whether the claims prove accurate or inflated, the attack mechanics described deserve every risk owner's attention, because they are becoming the dominant playbook.

Vishing beats MFA as deployed

The ShinyHunters attack chain documented by Mandiant researchers is devastatingly effective precisely because it exploits no software flaw.

  • A phone call, not an exploit. The attacker calls an employee posing as IT support, with a credible pretext and a professional tone. They obtain credentials, or get a login approved.
  • MFA is bypassed by enrollment. Once credentials are captured, the attacker registers their own device as a second factor. MFA keeps working perfectly; it now protects the attacker.
  • One SSO account opens everything else. This is the structural point. SSO has concentrated access to the entire SaaS estate onto a single identity. In Abbott's case, the group claims to have pivoted into ServiceNow, SharePoint, Databricks and Coupa from that one account. The blast radius of a compromised identity is now the whole company.

This playbook is not specific to Abbott. The same group ran a 2025 vishing wave against dozens of Salesforce tenants, claiming more than a billion records, and researchers observed attack infrastructure staged against over a hundred organizations in early 2026. The medical technology sector has been hit repeatedly for months.

The acquisition blind spot

One detail of the incident goes beyond identity: the affected systems are legacy Exact Sciences systems, from Abbott's recent acquisition, not yet integrated into the core environment. This is a recurring pattern that security programs underestimate. An acquisition brings systems, accounts, access paths and technical debt nobody fully knows yet, and the period between deal close and full integration is a window of maximum exposure: the acquirer carries the liability without yet having the visibility.

For a board, the consequence is clear: identity consolidation and the decommissioning timeline for legacy systems are not integration details. They are quantifiable risks that belong in pre-deal due diligence and post-close executive reporting.

What actually protects you

The countermeasures are known, and the incident helps rank them.

  • Phishing-resistant MFA. FIDO2 keys and passkeys cannot be "handed over" on the phone. For privileged accounts and access to sensitive data, that is the standard to aim for.
  • Control over MFA enrollment. Adding a new second-factor device is a security event: strengthened identity verification, user notification, a waiting period. It is the link the attacker exploits.
  • One simple rule for employees. IT support never calls to ask for a credential, a code or an MFA approval. One sentence, repeated, tested in exercises.
  • Monitoring identity signals. Unusual SSO logins, device enrollments, bulk exports from SaaS platforms: that is where this attack gets detected, not in the antivirus. Watching for data exfiltration at the SaaS API level becomes a first-order control.
  • A plan for extortion without ransomware. No encryption here: data theft, a leak site, an ultimatum, media pressure. Your business continuity planning must cover the scenario where everything runs normally yet the crisis is real: negotiation, notification obligations, communications.

The board question

Identity has become the perimeter. The question to ask is no longer "do we have MFA," to which everyone answers yes, but: "if a single SSO account fell tonight over the phone, what would be reachable, would we see it, and how fast?" If the honest answer is "a lot, probably not, and too late," the topic deserves a line in the risk register and an owner.

Where FortaRisks comes in

The FortaRisks Compliance module maps your identity and access controls across more than 30 frameworks and turns them into measured, prioritized, tracked gaps, from phishing-resistant MFA to support procedures. And because incidents like this are decided in the preparation, our free cyber risk score places you in minutes across the dimensions that matter, identity included.

See your real risk in a 30-minute demo.

A member of our team walks you through FortaRisks on threats relevant to your sector. No chatbot.