Critical

Exact Sciences Breach: 10.9M Records with Health Data (2026)

By Yazoul AI · automated

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email add...

Overview

In July 2026, Exact Sciences - the maker of the Cologuard at-home colorectal cancer screening test - was hit by a ShinyHunters extortion campaign that exposed 10,869,543 unique email addresses. The stolen data, now publicly leaked, includes names, phone numbers, postal addresses, and personal health information belonging to customers, patients, and healthcare providers. Abbott Laboratories, which now owns Exact Sciences, confirmed in a public notice that “some of the impacted files contain personal information and/or personal health information,” though a full review is still pending.

This is not a run-of-the-mill credential dump. The presence of health records tied to a cancer screening product elevates this to a critical privacy event, because medical data carries lasting stigma and discrimination risks that a stolen password does not.

What Was Exposed

The leaked dataset contains:

  • 10.9 million unique email addresses - these serve as the primary identifier for targeted phishing
  • Full names - enabling personalized social engineering
  • Phone numbers - opening the door to SMS-based scams
  • Physical addresses - a vector for mail fraud and doxxing
  • Personal health information - including details related to cancer screenings, a deeply sensitive category

The combination is what makes this dangerous. A phishing email that references your Cologuard test, your name, and your address will be far more convincing than a generic scam.

How the Breach Happened

ShinyHunters, a well-known threat actor group, ran a “pay or leak” campaign. They initially demanded payment to keep the data private, then published it publicly when the ransom was not met. The group has a track record of targeting healthcare and consumer data, and their MO typically involves exploiting misconfigured cloud storage, compromised credentials, or third-party vendor access rather than sophisticated zero-day attacks.

The exact entry point has not been disclosed. Abbott’s notice suggests they are still mapping the scope of what was taken, which means the intrusion may have gone undetected for some time.

Identity Theft and Health Data Risks

For most people, exposed emails and names are a nuisance. But health data changes the calculus. Details about colorectal cancer screenings, test dates, and related communications can be used for:

  • Targeted extortion - threatening to reveal sensitive health history
  • Insurance fraud - using medical details to file false claims
  • Discrimination - employment or coverage decisions based on health status

Even if the health records in this dump are limited, the perception of exposure can cause real harm. Accuracy matters less than the fear it generates.

How to Check If You’re Affected

Visit Have I Been Pwned and search your email address. The breach has been indexed there, so if your email appears, you are among the 10.9 million affected. You should also watch for official notification from Abbott Laboratories, which has said it will provide more specifics after its review.

What to Do Right Now

  1. Enable two-factor authentication on your email account immediately. This is your primary defense against account takeover.
  2. Do not click links in unsolicited emails referencing Cologuard or Exact Sciences. If you need to check anything, go directly to the official site.
  3. Be alert for smishing - SMS phishing referencing your health data is likely given the phone numbers involved.
  4. Monitor your health insurance statements for claims you did not file.
  5. Consider a credit freeze if you are concerned about broader identity theft, since names, addresses, and birth dates may allow fraudsters to pivot.

Security Insight

This breach reveals a critical weakness in healthcare-adjacent companies: the assumption that medical data is safe because the product is regulated. Exact Sciences may have had strong HIPAA compliance for clinical data, but consumer-facing records - emails, appointment details, test result notifications - often sit in less protected systems. Compare this to the 2024 Change Healthcare breach, where a lack of multifactor authentication on a customer portal exposed far more than anyone expected. The lesson for Abbott is that when you acquire a company with 10 million patient records, you acquire its security debt. ShinyHunters will keep targeting this sector because health data is the most valuable personal information a person holds - it cannot be changed or reissued, only endured. For the full picture of recent healthcare extortion trends, see our cybersecurity news coverage.

Further Reading

Investigate Breaches Safely with NordVPN

Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.

Get NordVPN for Research

Affiliate link — we may earn a commission at no extra cost to you.

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.