Was Your Cologuard Data Leaked? What the Exact Sciences Breach Means for You
Bottom line up front
On August 7, 2026, Have I Been Pwned added a breach for Exact Sciences — the company behind the Cologuard colon-cancer screening test, bought by Abbott in March — covering 10.9 million email addresses along with names, dates of birth, phone numbers, home addresses and personal health data. Abbott says the intrusion started with a vishing attack and that notification letters are still being prepared. You will probably hear from a scammer before you hear from Abbott. Freeze your credit, read your Explanation of Benefits statements, and treat every call about this breach as a stranger until you have called back on a number you looked up yourself.
If you have ever mailed in a Cologuard kit, or had an Oncotype DX test ordered for you, or works in a clinic that sends specimens to Exact Sciences, there is a reasonable chance your details are sitting in a file that criminals published online last week. That is an unsettling sentence to read with your coffee, and there is no version of it that lands gently.
So here is the useful part first. This breach is bad in a specific way, and being clear about which way it is bad tells you exactly what to do. The stolen file does not appear to be a wallet full of card numbers. It is something more durable: who you are, where you live, when you were born, and the fact that you had a cancer screening relationship with a laboratory. Card numbers get reissued in a week. The rest of that does not change.
What to do this week: six steps
None of these takes long. Do them in this order.
- Do not wait for a letter. Abbott said on August 5 that it is still analyzing the data and will make “any required notifications to affected individuals” once that review is done. The criminals published the file two days later. The notice will arrive on the company's timeline, not the attacker's.
- Check Have I Been Pwned — but note that this one is flagged as a sensitive breach, so it is not publicly searchable. You have to prove you own the address by requesting a verification email, which is exactly the protection you would want on a file that implies a cancer screening.
- Freeze your credit at all three bureaus. It is free, it takes about fifteen minutes total, and you can thaw it temporarily whenever you need to. Abbott has not confirmed that Social Security numbers were taken; the attackers claim they were. A freeze costs you nothing and settles the question.
- Pull your Explanation of Benefits statements from your health insurer and actually read them. Look for a doctor you have never seen, a test you never had, a date that does not match your life. This is the early-warning system for medical identity theft, and almost nobody uses it.
- Assume every inbound message about this breach is hostile until proven otherwise. Not the ones you go find — the ones that come to you. Call back on a number from your insurance card or the lab's official site, never the number in the message.
- Never pay anyone offering to remove your data or fast-track a settlement. Data removal from a criminal leak is not a service that exists. Anyone selling it is running the second scam.
Definition
The Exact Sciences data breach is the July 2026 theft and August 2026 publication of records from Abbott's Cancer Diagnostics business, the maker of the Cologuard screening test. Have I Been Pwned lists 10.9 million email addresses alongside names, dates of birth, phone numbers, addresses and personal health data.
What is the Exact Sciences breach?
Abbott closed its roughly $21 billion acquisition of Exact Sciences on March 23, 2026. Exact Sciences is the Madison, Wisconsin company that makes Cologuard, the at-home stool DNA test that spares a lot of people a colonoscopy, and Oncotype DX, a set of genomic tests that help oncologists judge recurrence risk and whether chemotherapy is likely to help. Between the two, the company's records touch millions of people at a moment in their lives when they were paying attention to something other than data security.
Roughly twelve weeks after the deal closed, someone got in.
Abbott disclosed the incident on July 16, in a statement it updated on August 5. Both versions are short and worth reading in the original, because the company is careful about what it does and does not claim. The confirmed parts: unauthorized access to “a limited number of internal systems in our Cancer Diagnostics business only,” no effect on manufacturing, lab operations, product availability or patient care, and — the line that matters most for anyone reading this — “some of the impacted files contain personal information and/or personal health information.”
How it happened: a phone call
Abbott's August 5 update contains one sentence that ought to be printed and taped to every help desk in the country:
“This was a vishing attack; not an encryption malware event.”
Vishing is voice phishing — a phone call instead of an email. Someone rang employees, sounded like they belonged, and talked their way to a credential. Security reporting from BleepingComputer and others says the calls landed in mid-June and produced access to a Microsoft single sign-on account tied to the legacy Exact Sciences environment. Abbott has confirmed the vishing; it has not publicly detailed the account.
The extortion crew behind it, ShinyHunters, is a name that keeps recurring — we covered the same group earlier this year. Their business model is not encryption. They steal, they demand payment to stay quiet, and if nobody pays, they publish. Nobody paid. On August 6 and 7 the file went out, and Have I Been Pwned indexed it on the 7th.
What was actually in the file
This is where most coverage gets sloppy, and where being precise actually helps you. There are three tiers of claim floating around, and they deserve different amounts of your trust.
What Have I Been Pwned verified in the published data: email addresses, names, dates of birth, genders, phone numbers, physical addresses, and personal health data. Troy Hunt's project loads the actual file and enumerates what is in it, so this list is the closest thing to ground truth available right now.
What Abbott has confirmed: that some impacted files contain personal information and/or personal health information, and that the review is ongoing. The company has not published categories or counts.
What the attackers claim: considerably more, including Social Security numbers, millions of medical orders, and clinical notes. These are assertions from the people running the extortion, who have every reason to make the haul sound worse than it is. Abbott has confirmed none of them.
Why bother with the distinction? Because scammers will quote the attackers' numbers at you. A caller who says “we're contacting you because your Social Security number was in the Abbott breach” is stating something nobody has confirmed. That is a tell, not a credential.
How to check if your address is in it
Have I Been Pwned classified this one as a sensitive breach, which changes how you check. Sensitive breaches are not searchable from the front page, because simply appearing in this file suggests a cancer-screening relationship, and that is not something a stranger, an employer or an ex should be able to look up about you.
To check, you go to Have I Been Pwned, use the notification path, and confirm ownership through a link sent to that address. It takes a couple of minutes. Do it for every address you have used with a doctor's office, a lab, or an insurance portal — including the old one you barely check.
Do not use a “breach checker” you found in an email
In the days after any large leak, look-alike checking sites appear. They ask for your email, then your date of birth, then the last four of your Social Security number “to confirm your record.” You are not checking a breach at that point. You are filling one in. Type the address of a site you already trust, or use our phishing link checker to see where a link actually goes before you click it.
Why this data is worth more to a scammer than a card number
A stolen card is a nuisance with a defined ending. You call the bank, the charges come off, a new card arrives. The file from this breach has no such ending.
Start with what it enables. A caller who knows your full name, your date of birth, your address, your phone number, and the name of the laboratory that processed your screening does not sound like a scammer. They sound like the lab. Every question you would normally ask to test a stranger — who are you, how do you know me, what is this about — they can answer, correctly, before you finish asking. That is the whole game. Most fraud does not defeat your judgment; it borrows enough facts to keep your judgment from switching on. We wrote about the machinery behind that in how scammers persuade you, and this file is a persuasion toolkit.
Then there is the health angle, which is genuinely different. Health information is not just embarrassing to have loose — it is the raw material for medical identity theft, where someone uses your details to get care, prescriptions or equipment billed to your insurance. The FTC's warning about that is blunt: if the thief's health information gets mixed into your record, it can affect the care you are able to get later. A wrong blood type or a fabricated allergy in your chart is a different order of problem than a fraudulent charge.
And it does not expire. You can change a password tonight. You cannot change your date of birth, your medical history, or the fact that a lab has your name on file.
The best defense is having seen it before
ScamDrill sends your household realistic practice scams — including the “we're calling about your recent breach” script — so the real one feels familiar instead of convincing. Nobody gets graded; you just get a heads-up when someone clicks.
Start your family plan →The four scams that follow a breach like this
These are predictable enough that you can pre-load your reaction to them.
1. The notification lure
An email or text that looks like the official breach notice, with a button to “view your exposure” or “activate your free credit monitoring.” It is timed to land while you are already worried and already expecting a letter. The link goes to a credential-harvesting page or a form that collects the identifiers the leak was missing. If a message like this arrives, paste it into our email scam checker before you touch anything in it.
2. The lab or insurer on the phone
A caller identifies themselves as Exact Sciences, Abbott, your insurer, or your doctor's billing office. They recite your date of birth to establish trust, then ask you to “verify” the pieces they do not have: your Social Security number, your Medicare number, your bank details for a refund. Hang up. Call back on a number from your insurance card or the company's own website. A real caller will not object; they deal with this constantly.
3. The settlement and the removal service
Class-action law firms really are advertising investigations into this breach, and a legitimate settlement may well exist eventually. What will not exist is anyone who can take your data back off a criminal forum, or who needs a fee up front to secure your place in a settlement. Charging you to recover from a breach is the shape of a recovery scam, and people who have already been hit once are the preferred target.
4. The fake pharmacy or test-kit follow-up
Because the file identifies people with a screening relationship, expect pitches tailored to that: a “replacement kit” needing a card for shipping, a “results portal” needing a login, a “your sample was inconclusive” message engineered to make you act before you think. Your real results come through your provider or the portal you already use. Go there directly.
What a real notice will look like
Abbott has said it will make required notifications once its review is complete. Based on how US breach notification works, here is what to expect and what should make you suspicious.
- It will most likely come by mail. Formal breach notices are typically posted letters, not text messages.
- It will not ask you to verify your identity to read it. A notice tells you what happened. It does not interrogate you.
- Any credit monitoring offer will have an enrollment code that works when you type the monitoring provider's address into your browser yourself. If the offer only works through the link in the message, that is a problem.
- It will not demand payment. Ever, for anything.
- It may arrive months from now. Companies routinely notify long after the news cycle ends. A gap is not proof the notice is fake, and speed is not proof it is real.
What you can fix, and what you can't
Let us be straight about the ceiling here. Nobody can un-publish that file. Anyone promising to is lying to you, and I would rather say so plainly than sell you comfort.
What you can do is make the leaked details useless as a key. The FTC's guidance gives the shape of it:
- Freeze credit at Equifax, Experian and TransUnion. Free, reversible, and it blocks new accounts opened in your name.
- Read every Explanation of Benefits statement. You are looking for providers you have not seen and services you did not receive.
- Request your medical records from any provider where you suspect misuse, and report errors in writing. Providers must respond to a correction request within 30 days and must tell other providers who received the same wrong information.
- Use IdentityTheft.gov if something actually happens. It generates a recovery plan and the pre-filled letters, which is a genuine time-saver when you are in it. Our first-60-minutes guide covers the sequence when money is already moving.
- Turn on two-factor authentication on your email and patient portals. Your email is the master key to everything else.
- If a Social Security number turns out to be involved, the follow-on steps are laid out in what to do when a scammer has your SSN.
The one habit that matters most
Verify by calling back, always, on a number you looked up yourself. Not the number that called you, not the number in the email, not the number the caller reads out. This single rule defeats the entire category of scam this breach enables — and it is the same rule Abbott's own employees needed in mid-June.
If you're helping a parent through this
US guidelines put routine colorectal screening at ages 45 to 75, so a lot of the people in this file are older — and a lot of them will get the call rather than the email. Two things help more than a lecture.
First, take a job off their plate. Offer to place the three credit freezes while you are sitting together, on their laptop, with their consent. It is a fifteen-minute chore that is much easier with company, and doing it together means they know it was done properly.
Second, give them one sentence rather than a list of red flags. Something like: “If anyone calls about my medical records, I hang up and call the number on my insurance card.” A rule you can recall while your pulse is up beats a checklist you cannot. Our guide to protecting elderly parents goes further on having these conversations without making anyone feel supervised.
And if a call already got through and information was handed over, skip the recriminations. These calls are designed by professionals to work on competent, careful people — that is the entire point of the design. Abbott's own staff, with corporate security training behind them, took the same call in June.
The supplier side of the same story
One more thing worth knowing, especially if you work in healthcare rather than just receive it. This breach is not an isolated event. It is part of a run of 2026 medtech incidents in which the confirmed entry point was almost never a clever exploit — it was a person talked into something over a phone or an email. If you run or work at a clinic, a billing vendor, a contract manufacturer or an IT shop that serves any of these companies, the 2026 medtech breach wave and what it means for suppliers covers the same story from the inside, with the controls that would have stopped it.