ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses
- ID
- 11997
- Status
- summarized
- Published
- 07 Aug 2026, 10:53 PM
- Fetched
- 07 Aug 2026, 11:58 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/08/07/shinyhunters-called-cancer-diagnostics-biz-and-tricked-staffers-into-giving-them-access-now-theyve-dumped-109m-email-addresses/5284857
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 5.5
- Created
- 07 Aug 2026, 11:59 PM
- Tags
- Audience
- developersdatabase_learnerssaas_founders
What happened
ShinyHunters used a vishing (voice phishing) attack to trick staff at Abbott's cancer diagnostics unit Exact Sciences into granting access, then dumped 10.9 million email addresses plus personal health data after Abbott refused to pay ransom. The crew claims to have exfiltrated 30M+ rows of customer info, 22M+ rows of doctor-patient notes, 20M+ medical-order records, and 425M+ rows from Databricks. Abbott disclosed the breach on July 16 and confirmed it began with a phone-based social engineering attack, not malware.
Why it matters
The Databricks exfiltration of 425M+ rows is the detail builders should note: if your analytics warehouse is accessible via credentials a phone call can extract, your data lake is one social-engineering attempt away from a breach. Review whether production Databricks access requires MFA and whether human-operated credential resets have an approval chain that a convincing caller can't bypass.
Discussion angle
How much of your Databricks or warehouse access is one convincing phone call away from compromise, and what would you actually change tomorrow to close that gap?