Independent Reviews
Open clinical drawer with frosted glass record layers and a stethoscope
Data Breach Published 7 Aug 2026 5 min read2 sources

Exact Sciences Added to Have I Been Pwned: Health Data Breach Lessons

Have I Been Pwned added an Exact Sciences breach affecting 10.9 million email addresses after Abbott disclosed a cyber incident in its cancer diagnostics business.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Have I Been Pwned added a verified Exact Sciences breach on 7 August 2026, listing 10,869,543 unique email addresses and data classes including names, phone numbers, physical addresses and personal health data.
  • Abbott's 5 August update says some impacted files contain personal information and/or personal health information and describes the incident as a vishing attack, not an encryption-malware event.
  • A VPN can protect network traffic, but it cannot remove health records from a breached system or stop targeted phishing that uses already-exposed data.

What happened?

Have I Been Pwned added a verified Exact Sciences breach on 7 August 2026. The listing says the breach contains 10,869,543 unique email addresses and data classes including dates of birth, email addresses, genders, names, personal health data, phone numbers and physical addresses.

Abbott, which now owns Exact Sciences, published an update on 5 August saying it was continuing to investigate a cyber incident affecting a limited number of internal systems in its Cancer Diagnostics business. Abbott said some impacted files contain personal information and/or personal health information, and that more specific information would follow once review and required notifications are complete.

Why it matters

Health-related data can be unusually sensitive because it may connect a person to tests, conditions, addresses, phone numbers and family or insurance context. Even when a company says operations and products are not affected, exposed personal health information can create privacy, phishing and emotional harms for individuals.

Abbott's update also matters because it describes the incident as a vishing attack rather than an encryption-malware event. That points to social engineering as a route into systems, which means awareness, call-back procedures, identity checks and privileged-access controls are part of the defence.

What you can do now

If you may be affected, check Have I Been Pwned, watch for Abbott or Exact Sciences notices, and be cautious with calls or messages that mention cancer diagnostics, lab results, billing, insurance or appointments. Do not provide passwords, one-time codes, payment details or identity documents to someone who contacts you unexpectedly.

Use strong unique passwords for healthcare, email and insurance accounts, turn on multi-factor authentication where available, and save any suspicious messages. If official notification confirms exposure, follow the specific monitoring or support steps in that notice rather than relying on generic breach advice alone.

Where a VPN helps — and where it does not

A VPN can protect your connection on public Wi-Fi and reduce what a local network or ISP can see when you access patient portals, email or insurance sites. That is useful network hygiene, especially when travelling.

But a VPN cannot remove data from a breached file, cannot stop a trusted organisation from storing information internally, and cannot prevent vishing if a person is tricked into approving access. For health-data incidents, account security and scam verification matter more than IP masking.

VPN Rocks view

The Exact Sciences listing is a reminder that breach impact is about context, not just record count. An email address in a health-data incident can invite more targeted scams than the same email address in a low-risk forum leak.

Use a VPN as one layer for safer connections, but pair it with unique passwords, multi-factor authentication and scepticism toward urgent medical or billing calls. If a caller creates pressure, hang up and contact the organisation through a verified route.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps