If you have ever used an Exact Sciences cancer screening service, your data may have been caught in a hunter’s snare. Exact Sciences, now owned by Abbott, is investigating a cyberattack involving legacy systems from its cancer diagnostics business. The attack was attributed to the cybercriminal group ShinyHunters, which claimed it stole data and threatened to publish it unless the company paid a ransom. Apparently, Abbot refused to pay (which is the recommendation of cybersecurity professionals), because the group later published a large collection of information to the dark web.
The word "legacy" is an important one here. Legacy systems are older computer systems that organizations may still need to keep around because they contain valuable information or support older operations. They can become difficult to maintain and secure, creating an attractive target for criminals.
According to Have I Been Pwned, the published data contains 10.9 million unique email addresses associated with customers, patients and healthcare providers, along with names, addresses, phone numbers, and health information.
Abbott has not publicly confirmed all of the information ShinyHunters claims to have stolen. The company has said it is investigating unauthorized access to a limited number of internal systems in its Cancer Diagnostics business. However, there are reports that it was the result of a vishing (voice phishing) attack and an employee gave up credentials to the attackers.
If you have received services from Exact Sciences, be especially cautious about unexpected emails, texts, or phone calls referencing your healthcare, screening tests, or personal information. Be very careful not to panic if they claim to have serious healthcare results or make an attempt to scare you into giving up information.
- Don't assume a message is legitimate simply because it contains accurate information about you. It is so difficult to detect phishing these days. So much information is published on the dark web or even put up on social media by us. This makes exercising extreme caution when receiving messages a critical activity.
- Don't click unexpected links, provide passwords, or send personal information in response to an unsolicited message.
And remember, healthcare data is particularly valuable to criminals because it can be used for identity theft, targeted scams, and highly convincing impersonation attempts.
If you are asked by anyone for login credentials, don’t give them up. No one, even the IT personnel, should be asking for that information.
The bottom line: You don't need to panic, but you should pay attention. If your information was involved, the most likely danger isn't someone suddenly accessing your medical records. It's what criminals can do with the information afterward.