Hackers have dumped data stolen from Abbott’s cancer diagnostics business after the healthcare giant apparently declined to pay up, with the leak containing 10.9 million unique email addresses alongside personal and health information. Have I Been Pwned added the Exact Sciences breach to its database on Friday after data stolen by the ShinyHunters extortion crew was published online. The leak includes names, email and physical addresses, phone numbers, dates of birth, genders, and personal health information belonging to customers, patients, and healthcare providers. Abbott, which acquired cancer diagnostics outfit Exact Sciences earlier this year, first disclosed the break-in on July 16. In an update on August 5, it acknowledged that some of the files accessed contained personal information and/or personal health information, but said it was still analyzing the data and had yet to determine who needed to be notified. The company also revealed that the intrusion began with a vishing attack, and stressed that this was “not an encryption malware event.” It said only a limited number of internal systems within its cancer diagnostics business were affected, with no disruption to products, manufacturing, laboratory operations, or patient services. ShinyHunters has a rather different way of describing what happened. On its dark web leak site, seen by The Register, the extortion crew told Abbott it “should’ve paid the ransom” and claimed the company had failed to reach an agreement despite being given multiple chances to do so. The crooks claim that they made off with more than 30 million rows of customer information, including more than one million Social Security numbers and 7.5 million dates of birth. More concerning are claims that the haul includes 22 million-plus rows of client notes containing confidential doctor-patient conversations and health information, as well as more than 20 million medical-order records containing patient IDs, prescription types, order dates, and refill information. ShinyHunters also claims to have siphoned more than 425 million rows of assorted data from Databricks, 130,000 files from SharePoint, and 89,000 contracts from Coupa, though those figures have not been independently verified. Abbott has not said how the vishing attack led to the theft of the data, how long the intruders had access to its systems, or whether it received an extortion demand. Its latest update says the investigation remains ongoing and that affected individuals will be notified where required. For those caught up in the breach, however, that review may come a little late. Whatever number Abbott eventually puts on the incident, a sizeable chunk of the stolen data is already in the wild. ®

Source note

First published by The Register

This article was supplied by The Register through its RSS feed and formatted for Crooli Signal. The reporting remains with the original publisher.

Read the original at The Register