AI Weekly Malaysia

Back to items Summaries

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses

ID
11997
Status
summarized
Published
07 Aug 2026, 10:53 PM
Fetched
07 Aug 2026, 11:58 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/cyber-crime/2026/08/07/shinyhunters-called-cancer-diagnostics-biz-and-tricked-staffers-into-giving-them-access-now-theyve-dumped-109m-email-addresses/5284857
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
5.5
Created
07 Aug 2026, 11:59 PM
Tags
Audience
developersdatabase_learnerssaas_founders

What happened

ShinyHunters used a vishing (voice phishing) attack to trick staff at Abbott's cancer diagnostics unit Exact Sciences into granting access, then dumped 10.9 million email addresses plus personal health data after Abbott refused to pay ransom. The crew claims to have exfiltrated 30M+ rows of customer info, 22M+ rows of doctor-patient notes, 20M+ medical-order records, and 425M+ rows from Databricks. Abbott disclosed the breach on July 16 and confirmed it began with a phone-based social engineering attack, not malware.

Why it matters

The Databricks exfiltration of 425M+ rows is the detail builders should note: if your analytics warehouse is accessible via credentials a phone call can extract, your data lake is one social-engineering attempt away from a breach. Review whether production Databricks access requires MFA and whether human-operated credential resets have an approval chain that a convincing caller can't bypass.

Discussion angle

How much of your Databricks or warehouse access is one convincing phone call away from compromise, and what would you actually change tomorrow to close that gap?

Top