Exact Sciences data breach (2026): was your email exposed?
Attackers reached legacy cancer-diagnostics systems at Exact Sciences, now part of Abbott, in June 2026, and after an extortion deadline passed the stolen records were published: known breach databases now hold 10.9 million email addresses from the set, along with names, addresses, dates of birth and health details. Check whether your email was caught up in it — and lock down your accounts before the data is misused.
See which breaches hold my email — free →The records from this one were published, and known breach databases have indexed them. Health-related breaches, though, are deliberately kept out of public email lookups - so that nobody can type in a neighbour's address and learn something medical about them. That protection cuts both ways: our free check will not confirm this breach for you either, and any site claiming it can search this particular set by email is either mistaken or fishing for your details. Abbott's notification is the confirmation. The check is still worth running for a different reason - it shows which other breaches already hold your email.
That is how many unique email addresses are in the set that reached known breach databases on August 7, 2026. It is not a figure Abbott has confirmed, and it is not a headcount - one person can appear more than once. The attackers separately claimed 30 million rows of customer data, over a million Social Security numbers and 22 million notes from doctor-patient conversations; those came from the group running the extortion and nobody outside it has verified them. Source: Abbott's public statements of mid-July 2026, reporting by security and healthcare press through early August 2026, and the record set indexed by known breach databases on August 7, 2026.
Abbott updated its own public statement on August 5, 2026 and confirmed what had until then only been claimed: some of the files taken in the Exact Sciences intrusion do contain personal information and health information. The company says it is still analysing the data and has not yet made the required notifications to affected individuals, and it describes the intrusion as a vishing attack - staff talked out of their credentials over the phone - rather than encryption malware. Two things follow from that. Most people will not have a letter yet, so nothing that arrives before one should be trusted on its own, least of all a caller who already knows your address and what you were screened for. And the first proposed class actions were filed in an Illinois federal court in late July, while the review is still open, so any email offering to pay out your claim is premature by definition - there is nothing to claim yet.
Abbott's own statement, updated August 5, 2026, and press coverage of the first class-action filings
What happened in the Exact Sciences breach?
Exact Sciences and Abbott: one company. Exact Sciences is the cancer-screening company behind the Cologuard and Oncotype DX tests, and it is now part of Abbott Laboratories. The intrusion hit Exact Sciences systems, but Abbott is the name on the public statements, so the same incident is reported under either name.
The break-in started with phone calls. In mid-June 2026 attackers rang Abbott employees and talked their way into a single sign-on account, the same approach the crew trading under the name ShinyHunters has used against a long list of large companies this year. From there they reached systems belonging to Exact Sciences, the cancer-screening business Abbott now owns. Abbott went public in mid-July, describing unauthorized access to a limited number of internal systems in its cancer diagnostics business, and said the incident did not affect its operations, its products or its ability to serve patients.
Then came the extortion clock. The group listed Abbott on its leak site with a deadline, pushed it back to July 21, and claimed to be holding 30 million rows of customer data, more than a million Social Security numbers, over 22 million notes covering doctor-patient conversations and around 20 million medical orders. None of that has been verified by anyone outside the group, and Abbott has disputed how the incident was characterised. Read those numbers as a claim, not a count.
In early August the data stopped being a claim. A set of records from the incident reached the databases that index leaked data: 10.9 million unique email addresses, carrying names, phone numbers, postal addresses, dates of birth, gender and health-related details. That is the part worth planning around, and it is what makes this breach heavier than an ordinary one. An email and password can be changed. A file that ties your name and address to the fact that you were screened for cancer cannot be, and it does not expire.
That combination is exactly what makes the follow-on scams work. Someone who already knows your name, your address, your date of birth and roughly what you were tested for does not sound like a stranger on the phone. The two scripts to expect are a bill for a test you thought was covered, and a call offering to verify your record before results are released. Neither is real. Notifications for something this size go out in writing first, and no legitimate caller needs your Social Security number to discuss a screening you already had. And if the Social Security numbers in the attackers' claim turn out to be genuine, the step that blocks the damage rather than reporting it afterwards is a credit freeze at all three bureaus - it is free, and it is better done now than after a letter arrives.
What data was exposed in the Exact Sciences breach?
The Exact Sciences breach exposed names, email addresses, phone numbers, physical addresses, dates of birth, genders and personal health data. The more of these are tied to you, the more ways an attacker can impersonate you or break into your other accounts.
How the leaked Exact Sciences data can be used against you
Because the Exact Sciences breach exposed names, email addresses, phone numbers, physical addresses, dates of birth and genders and more, your email address becomes a target for convincing phishing, often referencing this very breach to look legitimate; your phone number fuels scam calls and smishing (fraudulent texts); your address can be used to locate you, sold on to people-search sites, or used in doxxing; and exposed medical and insurance details enable medical identity theft — treatment or prescriptions billed in your name — and make health-themed scam calls far more convincing.
How to check if you were affected
The records were published and indexed, but breaches involving health data are excluded from public email lookups by design, so no tool that checks an address will return this one - ours included. Abbott's notification is the confirmation, and if a letter or email arrives, use only the contact details printed on it, because scam waves follow every notification rollout. What you can check right now is the rest of your exposure: which known breaches hold your email, and what leaked in them.
Check my email against known breaches — free →What to do if your Exact Sciences account was breached
These steps are prioritized for exactly the kind of data the Exact Sciences breach exposed.
Add 2FA — ideally an authenticator app or a passkey rather than SMS — to your email, banking and other important accounts, so a stolen password alone can’t get in.
Leaked numbers feed robocalls and smishing. Never act on an unsolicited call or text, enable your carrier’s spam filter, and remove your number from data-broker sites that resell it.
Exposed addresses spread to people-search sites that anyone can look up. Opting out of data brokers makes your home harder to find and lowers your doxxing risk.
Health data misuse shows up as care you never received: a bill, an explanation-of-benefits letter, or a claim on your policy for a treatment that isn’t yours. Read those statements instead of filing them, and query anything unfamiliar with the provider and your insurer — medical identity theft is usually caught this way rather than by credit monitoring.
Scammers reference real breaches to sound credible, so treat any email mentioning Exact Sciences with suspicion, and never use a password-reset link you didn’t request — go to the site directly instead.
Leaked data is resold for years, so a one-time clean-up isn’t enough. Ongoing breach and dark-web monitoring tells you the moment your details reappear, so you can act before an account is misused.
This one came out of the “pay or leak” extortion campaign
The same crew has published data from more than thirty companies since April 2026, always in the same order: break in, demand payment, post the files when the deadline passes. The hub tracks every company named so far, explains how people keep turning up in several of them at once, and covers what to do when your details are in a set that is already public.
See every company named so far →Medical records breached? What to do
Health data has no reset button and no bureau to freeze it at, so the steps differ from a normal breach: read the claims your insurer processes, ask each provider for a copy of your record, and query care you never received.
Read the guide →The Exact Sciences breach, answered
Was I affected by the Exact Sciences breach?
If you used a Cologuard kit, had an Oncotype DX test ordered for you, or dealt with Exact Sciences as a healthcare provider, treat it as likely. You cannot confirm it yourself: the published set is indexed by known breach databases, but health-related breaches are kept out of public email lookups, so no checking tool will return this one, ours included. The company's notification is the confirmation, and with a set this size the rollout can take months. In the meantime, act as though you are in it - the steps cost nothing and none of them are wasted if you turn out not to be.
Is the Exact Sciences breach letter I received genuine?
Letters from a real notification rollout do arrive by post and can look alarming. Verify it the safe way: use only the phone number or web address printed on the letter itself, typed in by hand — never a link in an email or text about the breach. Notification waves are followed by scams that copy the wording of the real letter.
What data was involved in the Exact Sciences breach?
Per the disclosure, the data included names, email addresses, phone numbers, physical addresses, dates of birth, genders and personal health data. Affected people: 10.9m email addresses. That is how many unique email addresses are in the set that reached known breach databases on August 7, 2026. It is not a figure Abbott has confirmed, and it is not a headcount - one person can appear more than once. The attackers separately claimed 30 million rows of customer data, over a million Social Security numbers and 22 million notes from doctor-patient conversations; those came from the group running the extortion and nobody outside it has verified them.
What should I do after the Exact Sciences breach?
Watch medical bills and insurance statements for care you never received, since that is how health-data misuse usually surfaces. Be sceptical of any call or email about this breach, especially one asking you to confirm details — the company contacts people by post first.
When did the Exact Sciences breach happen?
The incident is dated June 2026 and became public in July 2026. Source: Abbott's public statements of mid-July 2026, reporting by security and healthcare press through early August 2026, and the record set indexed by known breach databases on August 7, 2026.
Is there compensation for this breach?
Breaches this size often end in a class action, and a settlement can take a year or more to reach a claim form. If one opens for Exact Sciences, it will be run by a court-appointed administrator and announced on the company’s own breach page — never through an unsolicited email asking you to confirm bank details. Our guide to breach settlement claims covers who qualifies, what a payout actually covers, and the deadlines that decide it.
Was your email in the Exact Sciences breach?
Check free in about a minute — then we’ll help you remove your exposed data and keep it monitored.
Run my free breach check →