CHICAGO (CN) — A group of Illinois patients said in a class action filed in Illinois federal court Monday that a Midwestern diagnostics company and its multinational parent company failed to protect their private information from a data breach adequately.
Medical device giant Abbott Laboratories said in a statement published on its website July 16 that it was investigating a “cyber incident” after unauthorized access to patient data in some internal systems of Abbott and its subsidiaries’ cancer diagnostics businesses.
One of Abbott’s affected subsidiaries included Exact Sciences, a Wisconsin-based diagnostics company specializing in at-home cancer screening tests. Patients had to provide Exact Sciences and, by proxy, Abbott with their sensitive and confidential personal information to use these at-home tests, which a group of hackers then stole in a ransomware attack.
Abbott maintained in its statement that it did not expect any material impact on the business or financials from the attack, but the class noted in the complaint “the fraudulent activity resulting from the data breach may not come to light for years. There may be a time lag between when harm occurs versus when it’s discovered, and also between when private information is stolen and when it is used.”
In a 46-page complaint filed in U.S. District Court for the Northern District of Illinois, the patients maintained they were under the impression not only that defendants would safeguard their sensitive information but that defendants would delete any sensitive information after they were no longer required to maintain it.
The class of patients reiterated throughout the complaint that defendants knew their businesses were prime targets for data thieves, as hackers regularly target healthcare companies due to their custody of highly sensitive information.
A person’s private and sensitive information is highly valuable to cybercriminals because it can be sold for more on the black market. If a hacker stole someone’s credit card information, for example, the victim could simply cancel or close their credit cards. The information compromised in this data breach, however, is “impossible to ‘close’ and difficult, if not impossible to change — namely Social Security number,” plaintiffs wrote in the complaint.
Notorious black hat cybercriminal group ShinyHunters took responsibility for the attacks. ShinyHunters specializes in large-scale data breaches, extortion and selling stolen data on the internet. The hacking group, formed in 2019, told cybersecurity publication BleepingComputer on July 17 that it gained access to the data via a voice phishing attack aimed at Abbott employees. The attack purportedly allowed the group to compromise employees’ Microsoft Entra single sign-on accounts.
The cybercrime group further told BleepingComputer it stole more than 30 million rows of customer data from multiple datasets containing names, email addresses, phone numbers, physical addresses, birth dates and more than 1 million Social Security numbers. The group also said it stole more than 22 million client notes containing doctor-patient conversations and more than 20 million medical orders. Neither BleepingComputer nor Courthouse News has independently verified ShinyHunters’ claims regarding the stolen data.
A representative from Abbott Laboratories did not respond to Courthouse News’ request for comment. The Abbott Park, Illinois-based healthcare company ranked 107th on the Fortune 500 this year with $44.3 billion in revenue. The company also faces a class action from its employees, who said Abbott overcharged them for health insurance.
Subscribe to our free newsletters
Our weekly newsletter Closing Arguments offers the latest about ongoing trials, major litigation and rulings in courthouses around the U.S. and the world, while the monthly Under the Lights dishes the legal dirt from Hollywood, sports, Big Tech and the arts.






