Cybercrime,
Data Privacy,
Data Security
Cyberattacks Are Latest to Target Third-Party Healthcare Vendors

Cybercriminals continue to focus their malicious activities on healthcare targets, particularly third-party vendors and suppliers which have emerged as prime candidates for attacks. Recently, two notable victims have surfaced: the U.K.-based software company Craneware Group and the U.S.-based medical technology giant Abbott. These entities’ vulnerabilities highlight a growing concern in the healthcare sector, particularly as cyber threats evolve and become more sophisticated.
Craneware, which provides financial and operational software utilized by roughly 2,000 U.S. healthcare pharmacies and hospitals, reported a data theft incident that has compromised employee information as well as a select group of customer and partner records. The information was disclosed to the London Stock Exchange, where the company confirmed it is conducting an investigation into the breach. An official statement from Craneware reassured stakeholders that the incident has been contained and that there has been no disruption to customer services or operational capabilities. Furthermore, external specialists involved in the incident have verified that there are no lingering indicators of compromise present within the company’s systems.

Preliminary findings indicate that a “significant volume” of file names were accessed and exfiltrated; however, a large proportion of the data involved reportedly pertained to non-sensitive or public regulatory documentation. Notably, a spokesperson for Craneware refrained from providing further details regarding the incident, shrouding specific aspects of the breach in mystery.
Across the Atlantic, Abbott, a prominent player in clinical laboratory testing and medical devices, acknowledged on Thursday its own cyber incident, specifically affecting its IT systems. The company stated that the breach appears to have involved unauthorized access to a limited range of internal systems within its Cancer Diagnostics business line. Importantly, Abbott assured that this breach has not adversely affected its overall business operations, product availability, manufacturing processes, or its capacity to serve patients.
Further clarifying the situation, Abbott noted that only its “legacy Exact Sciences systems,” which are distinct from the broader organizational infrastructure, were impacted. This clarification comes on the heels of Abbott completing a substantial $23 billion acquisition of Exact Sciences in March 2026, positioning itself as a leading force in the burgeoning $60 billion cancer screening market.
Compounding Abbott’s cyber troubles, a cybercrime group known as ShinyHunters recently claimed responsibility for stealing a trove of data from Abbott’s Exact Sciences division. Adding to the complexity, a second group, ShadowByt3$, stated that it too had acquired sensitive data from Abbott through a separate incident.

Reportedly, ShadowByt3$ gained access to Abbott’s LabCentral customer portal using compromised credentials. This enabled them to gradually extract files by targeting specific API endpoints, thus obtaining an assortment of documents such as manufacturing certificates, operational manuals, technical specifications, and other pertinent product documentation related to Abbott’s laboratory diagnostic systems. Abbott has acknowledged awareness of a potential incident concerning access to its LabCentral portal and is actively investigating the circumstances. Fortunately, they emphasized that no impact has been detected on either business operations or customer information.
The healthcare sector, characterized by its reliance on third-party vendors, has increasingly become a favored target for cybercriminals. The ramifications of these attacks extend beyond the immediate impact on the organizations concerned, affecting countless healthcare clients and potentially millions of patients. A notable trend has emerged, wherein groups like ShinyHunters particularly target healthcare third-party vendors. For instance, they previously claimed to have compromised more than 9 million medical records from Medtronic, while another incident in May resulted in the theft of 234 gigabytes of data impacting 2.6 million individuals from DentaQuest, one of the largest dental benefits administrators in the U.S.
The data breaches reported across the healthcare industry this year indicate that vendor-related incidents have accounted for approximately half of all individuals impacted by significant health data security breaches, based on recent statistics from the U.S. Department of Health and Human Services. Such alarming data underscores the pressing need for enhanced cybersecurity measures among healthcare providers and their partners.

