Consumer breaches get the headlines because everyone recognizes the brand. But the breaches that do the most durable damage tend to involve data you never chose to hand over — collected about you by an institution, in a context where opting out wasn’t available.

The week of July 17–23, 2026 produced three of them.

Abbott Laboratories: 30 million rows, a million SSNs

The largest is Abbott Laboratories, and it’s actually two separate incidents.

The serious one hit Abbott’s Cancer Diagnostics business. The threat actor ShinyHunters obtained more than 30 million rows containing:

  • Customer names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Dates of birth
  • More than one million Social Security numbers

A second, unrelated intrusion by an actor identifying as ShadowByt3$ reached Abbott’s LabCentral portal. Per the disclosure, that one exposed corporate data only — no personal information.

The Cancer Diagnostics figure is the one to focus on, for a reason beyond raw scale.

Why health-adjacent data is different

Every breach involving SSNs is bad. This one carries an additional layer, because of what the context of the data reveals independent of its contents.

A record’s presence in a cancer diagnostics database is itself a health disclosure. You don’t need a diagnosis field. Association with an oncology diagnostics operation implies that a person was tested for, screened for, or treated in connection with cancer. That inference is available to anyone holding the file.

The consequences of that inference are not symmetric with ordinary identity theft:

  • It’s permanent. A compromised SSN can, with substantial effort, be replaced. A compromised health inference cannot be retracted from anyone who has already seen it.
  • It’s targetable. People navigating a serious diagnosis are a documented target for medical fraud, fake charity solicitations, and predatory “treatment” scams. A list of them is commercially valuable to the worst actors on the internet.
  • It carries social and economic risk. Employment, insurance, and personal relationships are all domains where an unwanted health disclosure does real harm.
  • You had no choice. You did not sign up for a diagnostics vendor. Your provider selected it. Your data went there as a condition of receiving care.

ShinyHunters, meanwhile, is not an opportunistic actor. The group has spent years running large-scale data theft and extortion operations across major enterprises, with a consistent playbook: exfiltrate at scale, extort the company, sell or leak the data when extortion fails. Data in ShinyHunters’ hands has a reliable tendency to end up circulating.

Estée Lauder: eleven months, and a full HR file

Estée Lauder disclosed a breach originating from a vulnerability in Oracle E-Business Suite. The intrusion began in August 2025 and was detected in June 2026.

Ten months of undetected access. And what was in reach was the complete contents of a corporate HR and finance system:

  • Names, addresses, email addresses, dates of birth
  • Social Security numbers
  • Passport numbers
  • Financial account details
  • Health information
  • Payroll records

This is close to the worst-case composition for a single breach. SSN plus date of birth plus address is the full identity theft kit. Passport numbers extend the exposure into travel and international identity fraud, and unlike a credit card, a passport number is genuinely painful to change. Payroll and financial account data enables direct-deposit redirection fraud. Health information carries the same permanence problem as Abbott’s.

The victims here are overwhelmingly employees — current and former — plus contractors. People whose only “consent” was accepting a job.

Oracle E-Business Suite vulnerabilities have been a persistent source of enterprise breaches through 2025 and 2026. EBS instances are exactly the systems that tend to be under-patched: business-critical, heavily customized, expensive to test, and consequently updated on a cautious schedule. That caution is rational from an uptime perspective and catastrophic from a security one.

Ernst & Young: the tax file problem

Ernst & Young disclosed a compromise of a third-party support ticket system in March–April 2026. The exposed material: personal and financial data “contained in or used to prepare tax filings.”

The affected count wasn’t disclosed, which is itself worth noting.

Tax preparation data is among the most concentrated personal datasets that exists. A complete filing package can include SSNs for an entire household including dependents, income from every source, employer details, bank account and routing numbers, mortgage and property information, investment holdings, charitable giving, and medical expense deductions.

That last item means tax data frequently contains health information by implication. Someone deducting substantial medical expenses is disclosing something about their health, in a document held by an accounting firm’s support ticket system.

And the vector — a third-party support ticket system — is the recurring enterprise failure of this era. The crown-jewel data isn’t sitting unprotected in the primary system. It’s sitting in a ticket attachment, in a vendor’s SaaS product, because a client emailed a document to support and someone attached it to a case. The security perimeter of your tax return is the security perimeter of your accountant’s least-considered vendor.

The common thread

Abbott, Estée Lauder, and Ernst & Young have nothing in common as businesses. Their breaches share a structure:

The affected people were not customers of the breached system. They were patients whose provider chose a diagnostics vendor. Employees whose employer chose an ERP. Clients whose accountant chose a helpdesk tool.

The data was of the highest sensitivity available. Not passwords and email addresses — SSNs, passports, payroll, health.

Detection was slow. Ten months at Estée Lauder. Unknown at Abbott. Months at EY.

Notification is uncertain. Where notification does occur, it typically arrives with an offer of twelve or twenty-four months of credit monitoring — a product that detects new credit accounts opened in your name and does nothing whatsoever about a permanent SSN exposure or a health disclosure.

Credit monitoring as the standard remedy is worth naming for what it is: a service that costs the breaching company a few dollars per person, addresses one narrow harm out of several, and expires long before the data stops circulating. Your SSN doesn’t expire in twelve months.

What to do

Because these datasets contain SSNs, the highest-value action is a credit freeze.

  1. Freeze your credit at all three bureaus — Equifax, Experian, TransUnion. It’s free, it’s federally mandated, it takes about fifteen minutes total, and it blocks new account opening outright. Unlike credit monitoring, which tells you after fraud has occurred, a freeze prevents it. Do this whether or not you think you’re affected; the aggregate of circulating SSN data makes it prudent regardless.
  2. Freeze your children’s credit too. Dependent SSNs appear in tax filings, and child identity theft typically goes undetected for years.
  3. Get an IRS Identity Protection PIN. Any US taxpayer can request one. It blocks fraudulent returns filed in your name — the specific attack that tax preparation data enables.
  4. If you hold a passport exposed in an incident like Estée Lauder’s, note the number and monitor for misuse; consider replacement if you have other indicators of fraud.
  5. Watch for direct-deposit redirection. Payroll exposure enables fraudsters to contact HR posing as an employee and change deposit details. Check that your pay is landing where it should.
  6. Treat unsolicited medical or charitable outreach as suspect if you were in a health-adjacent breach. Verify independently, always.

If you’re on the corporate side:

  • Inventory where personal data actually lives, including ticket attachments, shared drives, and vendor SaaS. It is never only in the database.
  • Prioritize patching for internet-reachable ERP and business suite instances, and accept the uptime risk.
  • Set and enforce retention limits. Abbott’s 30 million rows are 30 million rows partly because nothing was ever deleted.

The pattern

There is a category of privacy advice — use a password manager, enable 2FA, minimize what you share — that is good advice and completely irrelevant to these three incidents. No consumer behavior would have prevented a single record’s exposure. The data was collected about people by institutions acting on their behalf, held in systems those people never saw, and lost through vendor relationships they never knew existed.

Which means the only mechanisms that can actually address this class of breach are institutional: retention limits that shrink the target, real accountability for slow detection, and remedies proportionate to permanent harms. Twelve months of credit monitoring for a lifetime SSN exposure is not proportionate. It is a settlement price, and it’s been low enough for long enough that nothing changes.

Freeze your credit. Then notice that freezing your credit is the most any individual can do about a thirty-million-row file that shouldn’t have existed in that form in the first place.

Sources: