Was Your Cologuard Data Leaked? What the Exact Sciences Breach Means for You

Cover graphic on a deep navy field reading Was Your Cologuard Data Leaked, showing a laboratory specimen envelope with a torn corner and records escaping from it, and the line 10.9 million records published

Bottom line up front

On August 7, 2026, Have I Been Pwned added a breach for Exact Sciences — the company behind the Cologuard colon-cancer screening test, bought by Abbott in March — covering 10.9 million email addresses along with names, dates of birth, phone numbers, home addresses and personal health data. Abbott says the intrusion started with a vishing attack and that notification letters are still being prepared. You will probably hear from a scammer before you hear from Abbott. Freeze your credit, read your Explanation of Benefits statements, and treat every call about this breach as a stranger until you have called back on a number you looked up yourself.

If you have ever mailed in a Cologuard kit, or had an Oncotype DX test ordered for you, or works in a clinic that sends specimens to Exact Sciences, there is a reasonable chance your details are sitting in a file that criminals published online last week. That is an unsettling sentence to read with your coffee, and there is no version of it that lands gently.

So here is the useful part first. This breach is bad in a specific way, and being clear about which way it is bad tells you exactly what to do. The stolen file does not appear to be a wallet full of card numbers. It is something more durable: who you are, where you live, when you were born, and the fact that you had a cancer screening relationship with a laboratory. Card numbers get reissued in a week. The rest of that does not change.

What to do this week: six steps

None of these takes long. Do them in this order.

  1. Do not wait for a letter. Abbott said on August 5 that it is still analyzing the data and will make “any required notifications to affected individuals” once that review is done. The criminals published the file two days later. The notice will arrive on the company's timeline, not the attacker's.
  2. Check Have I Been Pwned — but note that this one is flagged as a sensitive breach, so it is not publicly searchable. You have to prove you own the address by requesting a verification email, which is exactly the protection you would want on a file that implies a cancer screening.
  3. Freeze your credit at all three bureaus. It is free, it takes about fifteen minutes total, and you can thaw it temporarily whenever you need to. Abbott has not confirmed that Social Security numbers were taken; the attackers claim they were. A freeze costs you nothing and settles the question.
  4. Pull your Explanation of Benefits statements from your health insurer and actually read them. Look for a doctor you have never seen, a test you never had, a date that does not match your life. This is the early-warning system for medical identity theft, and almost nobody uses it.
  5. Assume every inbound message about this breach is hostile until proven otherwise. Not the ones you go find — the ones that come to you. Call back on a number from your insurance card or the lab's official site, never the number in the message.
  6. Never pay anyone offering to remove your data or fast-track a settlement. Data removal from a criminal leak is not a service that exists. Anyone selling it is running the second scam.

Definition

The Exact Sciences data breach is the July 2026 theft and August 2026 publication of records from Abbott's Cancer Diagnostics business, the maker of the Cologuard screening test. Have I Been Pwned lists 10.9 million email addresses alongside names, dates of birth, phone numbers, addresses and personal health data.

What is the Exact Sciences breach?

Abbott closed its roughly $21 billion acquisition of Exact Sciences on March 23, 2026. Exact Sciences is the Madison, Wisconsin company that makes Cologuard, the at-home stool DNA test that spares a lot of people a colonoscopy, and Oncotype DX, a set of genomic tests that help oncologists judge recurrence risk and whether chemotherapy is likely to help. Between the two, the company's records touch millions of people at a moment in their lives when they were paying attention to something other than data security.

Roughly twelve weeks after the deal closed, someone got in.

Abbott disclosed the incident on July 16, in a statement it updated on August 5. Both versions are short and worth reading in the original, because the company is careful about what it does and does not claim. The confirmed parts: unauthorized access to “a limited number of internal systems in our Cancer Diagnostics business only,” no effect on manufacturing, lab operations, product availability or patient care, and — the line that matters most for anyone reading this — “some of the impacted files contain personal information and/or personal health information.”

10.9M unique email addresses in the published Exact Sciences file, alongside names, dates of birth, genders, phone numbers, physical addresses and personal health data.
Source: Have I Been Pwned, breach added August 7, 2026. Have I Been Pwned noted that about 75% of the addresses had already appeared in earlier breaches.

How it happened: a phone call

Abbott's August 5 update contains one sentence that ought to be printed and taped to every help desk in the country:

“This was a vishing attack; not an encryption malware event.”

Vishing is voice phishing — a phone call instead of an email. Someone rang employees, sounded like they belonged, and talked their way to a credential. Security reporting from BleepingComputer and others says the calls landed in mid-June and produced access to a Microsoft single sign-on account tied to the legacy Exact Sciences environment. Abbott has confirmed the vishing; it has not publicly detailed the account.

The extortion crew behind it, ShinyHunters, is a name that keeps recurring — we covered the same group earlier this year. Their business model is not encryption. They steal, they demand payment to stay quiet, and if nobody pays, they publish. Nobody paid. On August 6 and 7 the file went out, and Have I Been Pwned indexed it on the 7th.

Figure 1 — From acquisition to publication ScamDrill
Mar 23 Abbott closes the acquisition Mid-June Vishing calls reach employees Jul 16 Abbott discloses the incident Aug 5 “Vishing attack” confirmed Aug 7 10.9M addresses published Notification letters to affected individuals: still pending as of Abbott’s August 5 statement.
Dates from Abbott's July 16 and August 5 statements and Have I Been Pwned's breach record.

What was actually in the file

This is where most coverage gets sloppy, and where being precise actually helps you. There are three tiers of claim floating around, and they deserve different amounts of your trust.

What Have I Been Pwned verified in the published data: email addresses, names, dates of birth, genders, phone numbers, physical addresses, and personal health data. Troy Hunt's project loads the actual file and enumerates what is in it, so this list is the closest thing to ground truth available right now.

What Abbott has confirmed: that some impacted files contain personal information and/or personal health information, and that the review is ongoing. The company has not published categories or counts.

What the attackers claim: considerably more, including Social Security numbers, millions of medical orders, and clinical notes. These are assertions from the people running the extortion, who have every reason to make the haul sound worse than it is. Abbott has confirmed none of them.

Figure 2 — Confirmed vs. claimed ScamDrill
VERIFIED IN THE PUBLISHED FILE Enumerated by Have I Been Pwned • Email addresses • Full names • Dates of birth • Genders • Phone numbers • Physical addresses • Personal health data CLAIMED BY THE ATTACKERS Not confirmed by Abbott • Social Security numbers • Millions of medical orders • Doctor–patient notes • Internal system access Treat as unproven — but freeze your credit anyway. A freeze is free and reversible.
Left column: Have I Been Pwned breach record, August 7, 2026. Right column: threat-actor statements reported by security press; Abbott has not corroborated them.

Why bother with the distinction? Because scammers will quote the attackers' numbers at you. A caller who says “we're contacting you because your Social Security number was in the Abbott breach” is stating something nobody has confirmed. That is a tell, not a credential.

How to check if your address is in it

Have I Been Pwned classified this one as a sensitive breach, which changes how you check. Sensitive breaches are not searchable from the front page, because simply appearing in this file suggests a cancer-screening relationship, and that is not something a stranger, an employer or an ex should be able to look up about you.

To check, you go to Have I Been Pwned, use the notification path, and confirm ownership through a link sent to that address. It takes a couple of minutes. Do it for every address you have used with a doctor's office, a lab, or an insurance portal — including the old one you barely check.

Do not use a “breach checker” you found in an email

In the days after any large leak, look-alike checking sites appear. They ask for your email, then your date of birth, then the last four of your Social Security number “to confirm your record.” You are not checking a breach at that point. You are filling one in. Type the address of a site you already trust, or use our phishing link checker to see where a link actually goes before you click it.

Why this data is worth more to a scammer than a card number

A stolen card is a nuisance with a defined ending. You call the bank, the charges come off, a new card arrives. The file from this breach has no such ending.

Start with what it enables. A caller who knows your full name, your date of birth, your address, your phone number, and the name of the laboratory that processed your screening does not sound like a scammer. They sound like the lab. Every question you would normally ask to test a stranger — who are you, how do you know me, what is this about — they can answer, correctly, before you finish asking. That is the whole game. Most fraud does not defeat your judgment; it borrows enough facts to keep your judgment from switching on. We wrote about the machinery behind that in how scammers persuade you, and this file is a persuasion toolkit.

Then there is the health angle, which is genuinely different. Health information is not just embarrassing to have loose — it is the raw material for medical identity theft, where someone uses your details to get care, prescriptions or equipment billed to your insurance. The FTC's warning about that is blunt: if the thief's health information gets mixed into your record, it can affect the care you are able to get later. A wrong blood type or a fabricated allergy in your chart is a different order of problem than a fraudulent charge.

And it does not expire. You can change a password tonight. You cannot change your date of birth, your medical history, or the fact that a lab has your name on file.

The best defense is having seen it before

ScamDrill sends your household realistic practice scams — including the “we're calling about your recent breach” script — so the real one feels familiar instead of convincing. Nobody gets graded; you just get a heads-up when someone clicks.

Start your family plan →

The four scams that follow a breach like this

These are predictable enough that you can pre-load your reaction to them.

1. The notification lure

An email or text that looks like the official breach notice, with a button to “view your exposure” or “activate your free credit monitoring.” It is timed to land while you are already worried and already expecting a letter. The link goes to a credential-harvesting page or a form that collects the identifiers the leak was missing. If a message like this arrives, paste it into our email scam checker before you touch anything in it.

2. The lab or insurer on the phone

A caller identifies themselves as Exact Sciences, Abbott, your insurer, or your doctor's billing office. They recite your date of birth to establish trust, then ask you to “verify” the pieces they do not have: your Social Security number, your Medicare number, your bank details for a refund. Hang up. Call back on a number from your insurance card or the company's own website. A real caller will not object; they deal with this constantly.

3. The settlement and the removal service

Class-action law firms really are advertising investigations into this breach, and a legitimate settlement may well exist eventually. What will not exist is anyone who can take your data back off a criminal forum, or who needs a fee up front to secure your place in a settlement. Charging you to recover from a breach is the shape of a recovery scam, and people who have already been hit once are the preferred target.

4. The fake pharmacy or test-kit follow-up

Because the file identifies people with a screening relationship, expect pitches tailored to that: a “replacement kit” needing a card for shipping, a “results portal” needing a login, a “your sample was inconclusive” message engineered to make you act before you think. Your real results come through your provider or the portal you already use. Go there directly.

What a real notice will look like

Abbott has said it will make required notifications once its review is complete. Based on how US breach notification works, here is what to expect and what should make you suspicious.

What you can fix, and what you can't

Let us be straight about the ceiling here. Nobody can un-publish that file. Anyone promising to is lying to you, and I would rather say so plainly than sell you comfort.

What you can do is make the leaked details useless as a key. The FTC's guidance gives the shape of it:

The one habit that matters most

Verify by calling back, always, on a number you looked up yourself. Not the number that called you, not the number in the email, not the number the caller reads out. This single rule defeats the entire category of scam this breach enables — and it is the same rule Abbott's own employees needed in mid-June.

If you're helping a parent through this

US guidelines put routine colorectal screening at ages 45 to 75, so a lot of the people in this file are older — and a lot of them will get the call rather than the email. Two things help more than a lecture.

First, take a job off their plate. Offer to place the three credit freezes while you are sitting together, on their laptop, with their consent. It is a fifteen-minute chore that is much easier with company, and doing it together means they know it was done properly.

Second, give them one sentence rather than a list of red flags. Something like: “If anyone calls about my medical records, I hang up and call the number on my insurance card.” A rule you can recall while your pulse is up beats a checklist you cannot. Our guide to protecting elderly parents goes further on having these conversations without making anyone feel supervised.

And if a call already got through and information was handed over, skip the recriminations. These calls are designed by professionals to work on competent, careful people — that is the entire point of the design. Abbott's own staff, with corporate security training behind them, took the same call in June.

The supplier side of the same story

One more thing worth knowing, especially if you work in healthcare rather than just receive it. This breach is not an isolated event. It is part of a run of 2026 medtech incidents in which the confirmed entry point was almost never a clever exploit — it was a person talked into something over a phone or an email. If you run or work at a clinic, a billing vendor, a contract manufacturer or an IT shop that serves any of these companies, the 2026 medtech breach wave and what it means for suppliers covers the same story from the inside, with the controls that would have stopped it.

Frequently asked questions

Was my Cologuard data leaked in the Exact Sciences breach?

Possibly. Have I Been Pwned indexed the published file on August 7, 2026 and lists 10.9 million unique email addresses belonging to customers, patients and healthcare providers, along with names, dates of birth, genders, phone numbers, physical addresses and personal health data. Exact Sciences makes Cologuard and Oncotype DX, so people with a screening or testing relationship are the likely population. Abbott has confirmed only that some impacted files contain personal information and/or personal health information and that its review is ongoing.

How do I check if I am in the Exact Sciences breach?

Have I Been Pwned flagged this as a sensitive breach, so it is not searchable from the front page. You have to prove you own the email address by requesting a verification link sent to that address, then review the results. Check every address you have used with a doctor, a lab or an insurance portal, including old ones. Do not use a breach checker that arrives in an email or text; look-alike sites appear after every large leak and collect the details the attackers did not already have.

Were Social Security numbers stolen in the Exact Sciences breach?

That has not been confirmed. Have I Been Pwned's enumeration of the published data does not list Social Security numbers, and Abbott has not said they were taken. The attackers claim they hold Social Security numbers among other records, but that is an unverified assertion from people whose leverage depends on the file sounding severe. Freezing your credit at all three bureaus is free and reversible, so it is a sensible precaution regardless of how that question resolves.

What should I do right now if I think I am affected?

Freeze your credit at Equifax, Experian and TransUnion. Request your Explanation of Benefits statements from your health insurer and read them for providers you have not seen or services you did not receive. Turn on two-factor authentication for your email and patient portals. Treat every inbound call, text or email about the breach as unverified until you call back on a number you looked up yourself. If you find misuse, report it at IdentityTheft.gov to get a recovery plan and pre-filled letters.

Has Abbott sent breach notification letters yet?

Not as of its August 5, 2026 statement. Abbott said it was continuing to analyze the data and would provide more specific information once the review was complete, including making any required notifications to affected individuals. The stolen data was published by the attackers on August 6 and 7, which means the criminal copy was circulating before the official notices went out. Expect the real notice by postal mail, and expect it may take months.

Can I pay someone to remove my data from the leak?

No. Once a file is published on criminal forums it is copied endlessly, and no service can retrieve it. Anyone charging a fee to delete your records, secure your place in a settlement, or restore your privacy after this breach is running a recovery scam, and people who have already been affected once are the preferred target. Legitimate credit monitoring offered by a breached company is free to the people it notifies.

What scams should I expect after this breach?

Four patterns are predictable. Fake breach notification emails with a button to view your exposure or activate monitoring. Phone calls from someone claiming to be the lab, Abbott or your insurer, reciting your date of birth to build trust and then asking you to verify a Social Security or Medicare number. Settlement and data-removal offers that require an upfront fee. And follow-ups tailored to screening, such as a replacement kit that needs a card for shipping or a results portal that needs a login.