Were you recently affected by a data breach?

Abbott Cancer Diagnostics Data Breach

Abbott’s Cancer Diagnostics business disclosed a cyber incident involving unauthorized access to internal systems, with some impacted files containing personal and health information. Affected individuals may be entitled to compensation.

Abbott Cancer Diagnostics
Date of Breach: Incident occurred July 8, 2026; Oregon notification filed August 5, 2026
CAU logo

Who was affected:

Clients of Abbott Cancer Diagnostics

Impacted Data:

Personal information and personal health information contained in affected files

Abbott’s Cancer Diagnostics business has disclosed a cybersecurity incident that resulted in unauthorized access to a limited number of internal systems, with some of the accessed files found to contain personal information and personal health information. Companies that handle sensitive patient and consumer data have a responsibility to protect it with reasonable security safeguards.

Abbott Cancer Diagnostics’s Data Breach Investigation

Abbott Cancer Diagnostics is a business unit of Abbott Laboratories that also incorporates systems inherited from the legacy Exact Sciences organization. Abbott first publicly acknowledged the incident on July 16, 2026, stating that an unauthorized party had gained access to a limited number of internal systems within the Cancer Diagnostics business only, and that no other Abbott businesses, sites, or systems were affected.

In an update posted August 5, 2026, Abbott confirmed that some of the impacted files contain personal information and/or personal health information, and that the company continues to analyze the data to determine the full scope before making any required notifications to affected individuals. Abbott has also disclosed that the incident was the result of a vishing attack — a voice-phishing social engineering technique — rather than encryption-based ransomware or malware.

According to a notice filed with the Oregon Department of Justice on August 5, 2026, the underlying incident occurred and was discovered on July 8, 2026. Oregon’s filing reflects only the number of Oregon residents affected; Abbott has not yet disclosed a nationwide total number of affected individuals.

Healthcare and diagnostics companies are frequent targets for cybercriminals because the personal and medical information they store can be extremely valuable on the black market and can enable both identity theft and medical insurance fraud. Vishing attacks specifically target employees through phone-based social engineering rather than exploiting a technical vulnerability, which means an organization’s own internal security awareness training and verification procedures are often the last line of defense against this style of intrusion.

Abbott has stated that the incident did not affect its ability to support business operations, product availability, manufacturing, laboratory operations, or its ability to serve patients, and that customers can remain confident that Abbott products continue to function and deliver results as intended. Abbott says it has engaged third-party cybersecurity experts and notified law enforcement, and is working to determine exactly what information was accessed before notifying affected individuals directly.

Because Abbott has not yet completed its individual notifications, the exact scope of personal and health information exposed — and how many people nationwide are affected — remains uncertain. Anyone who receives a notice from Abbott or Exact Sciences regarding this incident, or who has used Exact Sciences oncology diagnostic products or services, should take the notice seriously and consider their legal options.

When Did This Breach Occur?

Abbott’s Oregon filing states the incident occurred and was discovered on July 8, 2026. Abbott publicly acknowledged the incident on July 16, 2026, and issued an update on August 5, 2026 confirming that some impacted files contain personal and health information. Individual notifications to affected people had not been completed as of the August 5 update.

What Information Was Breached?

Abbott has confirmed that some of the files accessed in the incident contain personal information and/or personal health information, but has not yet publicly itemized the specific data elements (such as Social Security numbers, medical record numbers, or diagnosis information) involved. Abbott says it continues to analyze the affected data and will provide more detail as its review is completed.

What You Can Do

If you have used Exact Sciences oncology diagnostic products or services, or believe you may have been affected by this incident, consider taking the following steps:

  • Watch for a notification letter from Abbott or Exact Sciences and keep a copy for your records.
  • Monitor your financial accounts and insurance statements for unauthorized activity.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus.
  • Be cautious of unsolicited phone calls asking you to verify personal information, given the vishing method used in this incident.
  • Enroll in any credit monitoring or identity protection services Abbott offers once notifications are sent.

File a Data Breach Lawsuit Against Abbott Cancer Diagnostics

If you were notified, or believe you may have been affected, by the Abbott Cancer Diagnostics data breach, you may have legal options. Companies that collect and store sensitive personal and health information have a duty to reasonably safeguard it from unauthorized access.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Underlying vendor incident occurred May 29 - June 1, 2026; New Era notified employees in 2026
Date of Breach: Incident occurred July 8, 2026; Oregon notification filed August 5, 2026
Date of Breach: Hacker group's claim of responsibility posted on or around August 5, 2026; not yet confirmed by the company
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.