Abbott investigates unauthorised access to oncology diagnostic systems
Abbott reported an investigation into unauthorised access to a limited number of internal systems within its oncology diagnostics business and a potential breach of a specialised portal.

News summary
Abbott reported an investigation into unauthorised access to a limited number of internal systems within its oncology diagnostics business and a potential breach of a specialised portal.
External portals must be treated as entry points: strong authentication, segmentation and continuous session monitoring help to limit potential compromise.
Source: Reuters — 27 July 2026
What happened
According to Reuters, Abbott reported an investigation into unauthorised access to a limited number of internal systems in its cancer diagnostics business, as well as a possible breach of a specialised portal.
The company did not disclose the access method or the volume of information that may have been affected. The case combines two common vectors: specific internal systems and an external portal serving users outside the organisation.
What it teaches a mid-sized business
Portals for customers, patients, distributors or partners are convenient and necessary, but they are exposed to the internet by definition. When they are designed with only ease of use in mind, they end up with weak passwords, sessions that never expire and direct connections to internal databases.
For a business in Catalonia offering a private area to customers or suppliers, the lesson is to treat that portal as another entry point: with strong authentication, separated from internal systems and monitored. Whether an incident stays limited to a small number of systems usually depends on architecture decisions made long before.
What to review
Four specific points for any external portal:
- Multi-factor authentication for users with access to sensitive information and for administrator accounts.
- Separation between the portal and internal systems, with access only to the data that is strictly needed.
- Session expiry and periodic review of external users who are inactive or should no longer have access.
- Access logs retained and reviewed to detect unusual downloads or queries.
Frequently Asked Questions
- Why are external portals a frequent target?
- Because they are reachable from the internet, used by people outside the organisation and often connected to internal data, which makes them an attractive way in.
- Is a strong password enough for a customer portal?
- Not for sensitive information. Multi-factor authentication greatly reduces the risk of a stolen credential granting access.
- How can the scope of unauthorised access be limited?
- Through segmentation, least-privilege permissions per user and logs that allow access to be detected and cut off quickly, so one compromise does not open the way to other systems.
Concepts mentioned in this article: Monitoring
Moving from news to prevention requires concrete measures. Seintec can help you prioritise them according to your company’s size, activity and budget. Contact our technical team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.