A colon cancer test company got breached. If you took Cologuard, expect a phone call.
Exact Sciences, the Abbott company behind the at-home Cologuard colon cancer test, was breached and 10.9 million email addresses are public. What to do before the notification letter arrives.
If you ever mailed a Cologuard sample back in a prepaid box, the company that processed it has been broken into, and the stolen data is already public.
Exact Sciences makes Cologuard, the at-home colon cancer screening test. Abbott bought the company in March. Have I Been Pwned added the Exact Sciences breach on Friday, August 7. The published file holds 10.9 million unique email addresses, along with names, dates of birth, genders, phone numbers, home addresses and health information belonging to customers, patients and healthcare providers.
Abbott has confirmed the incident. Its August 5 update says "some of the impacted files contain personal information and/or personal health information," and that it is still reviewing the data before making any required notifications. Abbott has since filed an initial breach report in at least one state, listing a single affected resident there and a notice date of August 5. The wider round of letters has not gone out yet.
One phone call opened the door
Abbott has been specific about how this started. It was a vishing attack, not a ransomware event. Vishing is phishing done by voice. Somebody calls an employee, sounds like the help desk or a coworker, and talks them into handing over a login. With that login, the data was copied and carried out.
What was actually taken
Abbott has not itemized the data yet, so this splits into two lists.
Confirmed and sitting in the published file, according to Have I Been Pwned, are:
- Names
- Dates of birth
- Genders
- Email addresses
- Phone numbers
- Physical addresses
- Personal health data

Abbott has not said whether test results were included, and until it does, nobody can say either way. It also has not named which of its cancer tests the records came from, only that they came from its Cancer Diagnostics business.
Claimed by the group that stole it, ShinyHunters, but unconfirmed elsewhere:
- More than 30 million rows of personal information
- Over a million Social Security numbers
- 22 million client notes containing doctor and patient conversations
- 20 million medical order records
Those numbers come off an extortion site, from people whose business is making a haul sound enormous. Treat them as unverified until Abbott publishes its own accounting.
The real risk is a very good phone call
A credit freeze is most people's reflex after a breach, but that isn't the most helpful in this case. A home address does not open a credit card. What sits in the stolen files is a list of adults, most of them 45 and older because that is who Cologuard is for. The list contains real names, real birthdays, real phone numbers, and one private fact attached, that they were screened for cancer.
That combination is a script. Somebody calls, gets your name and date of birth right, and mentions the test. They'll say there is a problem with your result or your billing. Every detail checks out, because every detail was stolen. The details being right is what gets you to believe the vishing attempt.
The same list works by email, and a fake patient-portal notice is the easy second act. Our phishing guide covers what those look like.
The FTC put out an alert on August 3 about the people who make a living off breach victims, buying lists of people who have already been taken and calling back to offer help getting the money returned. Its advice fits this week. Look up the contact information yourself, and "Don't use any number they give you."
What to do this week
- Check Have I Been Pwned, but sign in to do it. This breach is flagged sensitive, so it will not turn up in the search box on the front page. You have to verify the address is yours first, through the dashboard or the notification email. A hit means your email was in the file. It does not tell you which of your other details came with it.
- Check the letter yourself when it arrives. Look up Abbott's contact information on your own, then ask whether the letter is real, rather than whether Abbott mailed it. Companies hire outside firms to print and send breach notices, so a real letter can show up from a name you have never heard of. We wrote about that exact problem in That sketchy letter from your hospital might be real. Nothing Abbott has published so far carries a phone number for customers.
- Expect the call to be convincing, and hang up anyway. Do not confirm a birthday, do not answer a security question, do not do anything that has to happen while they have you on the phone. Hang up, find the number yourself, call back. If the call was real, calling back costs you nothing. Screening your calls helps too, and there are controls on your phone for that.
- Freeze your credit if you want to, but know what it buys. A freeze is free and reversible and it blocks somebody from opening new accounts in your name. Nothing financial has been confirmed stolen here, and a freeze doesn't help with a phone call. If Abbott's letter tells you your Social Security number was in the file, freeze and do not think twice. Otherwise it is a good habit, but not an urgent step.
- Read your Explanation of Benefits statements. There is no freeze for medical records. Medical identity theft usually shows up as a bill or an insurance statement for care you never received, and the FTC's page on it walks through what to do next.
This is not a reason to skip screening
You mailed the box because your doctor asked you to, and that was the right call. Colorectal cancer screening saves lives and a break-in at a lab does not change that.
What it does change is how you treat your phone calls. For the next several months, someone out there may know your name, your birthday, your address and one private fact about your health. If somebody with that combination calls you, the fact that they know everything is the reason to hang up.
If somebody already got you on a call like this, start here.
Source: Abbott statement on cyber incident in Cancer Diagnostics business
The breach entry: Have I Been Pwned, Exact Sciences
Reporting: The Register and BleepingComputer
The FTC: Have you lost money to a scam? and What to know about medical identity theft