ShinyHunters Names Exact Sciences as Its Latest Target

The extortion group ShinyHunters has claimed Exact Sciences Corporation, the Abbott-owned diagnostics company behind the widely used Cologuard colon cancer screening test, as its newest victim. The claim appeared alongside a separate listing from another group, Chaos, which says it breached Sleeman Breweries, a Canadian brewing company. Both claims surfaced as part of the ongoing churn of dark web leak sites where ransomware and data extortion groups publicly name organizations to pressure them into paying.

As is typical with these claims, the specifics of what data ShinyHunters says it obtained have not been independently verified by Exact Sciences or Abbott at the time of this reporting. Extortion groups routinely post victim names before any data is confirmed stolen, using the threat of exposure as leverage. What makes this claim notable is not just the corporate name attached, but the nature of the business itself: Exact Sciences handles diagnostic testing tied to cancer screening, which means any data exposure could touch on deeply sensitive health and genetic information rather than routine account credentials.

Why Health and Genetic Data Breaches Carry Outsized Risk

Not all data breaches carry the same weight. When a retailer's customer database is exposed, the fallout usually involves stolen passwords, payment details, or loyalty account information, all of which can be changed or monitored. Health and genetic data is different. A patient's diagnostic history, test results, or genetic markers cannot be reset like a password. Once that kind of information is exposed, it stays exposed permanently.

Diagnostic companies like Exact Sciences sit at the intersection of healthcare records and laboratory data, meaning a breach could potentially expose not just names and contact details but also details about medical conditions, test results, and insurance information. This combination is valuable to criminals because it enables highly targeted phishing, medical identity theft, and insurance fraud that is harder for victims to detect than a simple credit card compromise.

This is not the first time ShinyHunters has gone after health-adjacent data. The group previously claimed an 8.8TB breach of Amazon One Medical, another instance where a healthcare-linked company found itself named on a leak site. The recurrence of health sector targets suggests a deliberate strategy: sensitive medical data creates urgency and fear, which extortion groups can exploit to accelerate ransom negotiations.

Steps Patients Should Take Now

If you have used Cologuard or any Exact Sciences diagnostic service, there are practical steps worth taking while the claim is investigated and confirmed or denied by the company:

  • Watch for official communication. Legitimate breach notifications will come directly from Exact Sciences or Abbott, not from unsolicited emails or calls asking you to verify account details.
  • Monitor for phishing attempts. Scammers often use breach headlines to send fake "your results are ready" or "account verification" messages. Be skeptical of any message referencing your test results that asks you to click a link or provide personal information.
  • Review insurance and medical statements. Medical identity theft often shows up first as unfamiliar charges or services on insurance explanations of benefits.
  • Consider a credit freeze or fraud alert if you're concerned about identity theft stemming from any exposed personal details, even if genetic data itself cannot be "frozen."
  • Ask your provider about data retention. Patients have the right to ask how long a lab or diagnostics company retains test data and whether it is shared with third parties.

A Pattern of Healthcare and Institutional Targeting

ShinyHunters has built a reputation for claiming large-scale breaches across a range of sectors, not just healthcare. The group has previously claimed 275 million records in a breach tied to Instructure, the company behind the Canvas learning platform, and separately claimed to have stolen 297 GB of data from the Council of Europe's HR systems. Educational institutions have also felt downstream effects of these campaigns, as seen when a second Canvas-related breach disrupted exams at Penn State and other universities.

Taken together, these claims show a group willing to pursue targets across education, government, and now health diagnostics, wherever large volumes of sensitive personal data are concentrated. The Sleeman Breweries claim by Chaos, occurring in the same news cycle, reflects how common this extortion model has become across industries far removed from traditional cybersecurity concerns.

What This Means For You

Even before Exact Sciences confirms or denies the scope of this incident, the claim itself is a reminder that health and diagnostic companies are attractive targets precisely because the data they hold cannot be easily replaced. Patients should treat any communication referencing test results or account access with caution until official statements clarify what happened.

Key Takeaways

  • ShinyHunters has claimed Exact Sciences Corporation, owned by Abbott, as a new victim on a dark web leak site.
  • Health and genetic data breaches carry long-term risk because this information cannot be reset like a password.
  • Patients who have used Cologuard or Exact Sciences services should watch for phishing attempts and review medical and insurance statements for irregularities.
  • This claim fits a broader pattern of ShinyHunters targeting large repositories of sensitive personal data across healthcare, education, and institutional sectors.

As details emerge, staying informed through verified company statements, rather than reacting to unconfirmed dark web claims, remains the most effective way for patients to protect themselves.