← All posts

A Phone Call Breached a $200 Billion Healthcare Giant — And Your Company Could Be Next

On July 16, Abbott Laboratories — a Fortune 50 healthcare company with a $200 billion market cap — confirmed that an unauthorized third party had accessed internal systems in its Cancer Diagnostics business. The attacker's reported entry point wasn't a zero-day exploit or a sophisticated malware campaign. According to reports citing the ShinyHunters extortion group, it was a series of phone calls.

The group told BleepingComputer that it compromised Abbott employees through voice phishing — "vishing" — in mid-June, manipulating them into handing over credentials that unlocked the company's Microsoft Entra single sign-on environment. From there, the attackers allegedly moved laterally through connected systems. ShinyHunters claims to have exfiltrated sensitive data including patient records, medical orders, and employee information, though Abbott has stated it does not expect any material impact on business or financial results.

The incident is a case study in why every board of directors needs to stop thinking of cybersecurity as a technology problem.

The Phone Is the New Front Door

If you still picture hackers hunched over keyboards writing code, it's time to update your mental model. Mandiant's M-Trends 2026 report found that voice phishing accounted for 11% of all initial infection vectors globally in 2025, making it the second most common entry point — behind only software exploits. For cloud-related compromises specifically, vishing was the most common vector at 23%.

This shift matters because vishing attacks bypass every technical control your security team has deployed. Firewalls, endpoint detection, email filters — none of them see a phone call. The attacker isn't breaking through your defenses. They're asking an employee to hold the door open.

And employees are doing it at alarming rates. KnowBe4's 2026 Phishing by Industry Benchmarking Report found that healthcare and pharmaceutical companies have a baseline "phish-prone percentage" of 42.7% — the highest of any industry. In large healthcare organizations with more than 10,000 employees, that number climbs to 54%. More than half the workforce, statistically likely to fall for a social engineering attack.

Two Attacks, One Lesson

What makes the Abbott situation particularly instructive for executives is that the company disclosed two apparently unrelated cyber incidents simultaneously. The ShinyHunters vishing compromise targeted Cancer Diagnostics. A separate threat actor, ShadowByt3$, claimed to have breached Abbott's Core Laboratory business through its LabCentral customer portal using compromised customer credentials and API endpoint exploitation, reportedly beginning on July 4, 2026.

Two different attackers. Two different business units. Two different methods. One company.

This is modern enterprise risk. Your attack surface isn't a single wall that needs to be tall enough. It's dozens of doors across dozens of buildings, and attackers are trying all of them simultaneously. If your board is asking "Are we secure?" the answer is always more complex than a single metric can capture.

The Three Questions Your Board Should Be Asking

In Cyber Risk Is Business Risk, I outline a framework built around three questions every board should ask their CISO:

What can go wrong? Most organizations assess this question through the lens of technical vulnerabilities — unpatched software, misconfigured cloud environments, exposed APIs. But Abbott's experience shows that the answer must include human vulnerabilities. If your risk assessment doesn't account for an employee picking up the phone and being manipulated by a professional social engineer, you have a blind spot.

What are we doing about it? Technical controls are necessary but insufficient. The Abbott breach reportedly pivoted through a single sign-on environment — a technology designed to improve security by centralizing authentication. When the human layer fails, SSO becomes a force multiplier for the attacker rather than a defense for the company. Your "what are we doing" answer needs to include continuous security awareness training, simulated vishing exercises, and multi-factor authentication methods that are resistant to social engineering — not just checkbox compliance with HIPAA's administrative safeguards.

How do we know it's working? This is where most organizations fall short. KnowBe4's research offers a bright spot: organizations that commit to a full year of continuous training reduce their phish-prone percentage by an average of 87%, bringing susceptibility down to roughly 4%. That's a measurable, reportable metric your board can track quarter over quarter. If your CISO can't tell you the organization's current phish-prone rate and its trend line, that's a conversation worth having.

What to Ask Your CISO This Week

If the Abbott breach prompts one conversation in your organization, make it this one:

"What is our exposure to voice-based social engineering, and how are we measuring it?"

Specifically, push on these points:

Do we run simulated vishing exercises, or only email phishing simulations? Most security awareness programs test employees against phishing emails but never make a phone call. Attackers have noticed.

Does our MFA implementation resist social engineering? If your organization relies on push-notification MFA, an attacker who has vished an employee's password can often fatigue them into approving a fraudulent login. Phishing-resistant methods like FIDO2 security keys eliminate this risk.

If an attacker compromised one SSO account today, what could they reach? The principle of least privilege should mean the answer is "not much." In practice, SSO environments often grant broad access across SaaS platforms, internal tools, and sensitive data repositories. Map the blast radius before an attacker does.

What is the response plan when — not if — a social engineering attack succeeds? Abbott's public statement credited swift incident response with containing the damage. Does your organization have a playbook that specifically addresses credential compromise through social engineering, including immediate session revocation and forensic scoping?

The Board's Role

Abbott's disclosure said the company "does not expect any material impact on the business or financial results." That's the best-case outcome, and it likely reflects strong incident response execution. But the incident still happened. Two threat actors still gained access. And the company's public disclosures, reputation, and patient trust are all in play.

For boards, the lesson is structural. Cybersecurity governance cannot be delegated entirely to the CISO and forgotten between quarterly updates. The threat environment has shifted beneath the boardroom table. When a phone call can bypass every technical control your company has purchased, the conversation has to change from "How much did we spend on security?" to "How prepared are our people?"

The answer to that question is a board-level responsibility.