10,869,543 Exact Sciences Email Addresses Are Already Public — With Health Records Attached. Abbott Says It Still Hasn’t Sent the Notification Letters, 36 Days After the Breach.
The stolen Cologuard-maker data was not just threatened; it was published, and Have I Been Pwned indexed it on August 7 as a verified breach of 10.9 million email addresses carrying names, addresses, phone numbers, dates of birth and personal health data. Abbott’s own incident page — last updated August 5 — confirms impacted files contain personal and health information and says notifications will follow “once we have completed our review.” Eight proposed class actions were filed in eight days. What does not exist: a settlement, a claim form, or an administrator.
By Settlement Insight Data Desk ·
The number, and where it comes from
When the Exact Sciences hack surfaced in mid-July, the story was a threat: the ShinyHunters extortion group claimed data and set a “pay or leak” deadline. Reporting in late July noted the group had not actually begun leaking.
That changed. On August 7, 2026, Have I Been Pwned — the breach index run by security researcher Troy Hunt — added Exact Sciences as a verified breach, describing data the group “later published publicly.” The catalogued size is precise: 10,869,543 unique email addresses, with a breach date of July 15, 2026.
The categories HIBP records in that corpus are: email addresses, names, physical addresses, phone numbers, dates of birth, genders, and personal health data. The record is flagged sensitive. Exact Sciences makes the Cologuard at-home colorectal cancer screening test, which is what makes the last category consequential — a mailing list tied to cancer screening is not a neutral fact about a person.
One correction worth making, since it is being repeated widely: several write-ups state that one million Social Security numbers were taken. Social Security numbers are not among the categories HIBP catalogued in the published data. The SSN figure traces back to the attackers’ own extortion claims, not to the corpus that was indexed. Treat it as unverified — and be sceptical of anyone using it to sell you an urgent service.
What Abbott has actually said — twice
Abbott acquired Exact Sciences in March 2026, so Abbott speaks for this incident. It has published one statement, updated once, and both versions are still on its newsroom page.
The July 16, 2026 statement said Abbott was investigating unauthorised access to “a limited number of internal systems in our Cancer Diagnostics business only,” with no impact on operations, products, manufacturing, lab operations or patient service, and noted that “the legacy Exact Sciences systems are separate from Abbott’s.”
The August 5, 2026 update went further on two points. First, it confirmed the sensitive part: “We are aware that some of the impacted files contain personal information and/or personal health information.” Second, it disclosed the method — “This was a vishing attack; not an encryption malware event.” Vishing is voice phishing: someone talked their way in over the phone. No ransomware needed to be deployed for eleven million records to end up online.
On notification, the update says Abbott will provide more specific information “once we have completed our review, including making any required notifications to affected individuals.” That is the sentence to hold on to. As of publication — 36 days after the breach date and 15 days after that update — Abbott has not said letters have gone out.
Eight proposed class actions in eight days
The litigation did not wait for the notifications. Between July 16 and July 23, 2026, at least eight proposed class actions naming Exact Sciences or Abbott were docketed in two federal courts — the Western District of Wisconsin, where Exact Sciences is headquartered in Madison, and the Northern District of Illinois, Abbott’s home district:
- Petersen v. Exact Sciences Corporation, 3:26-cv-00643 (W.D. Wis., filed July 16) — the same day Abbott posted its first statement
- Nettles v. Exact Sciences Corporation, 3:26-cv-00650 (W.D. Wis., July 20)
- Terlikowski v. Exact Sciences Corporation, 3:26-cv-00651 (W.D. Wis., July 20)
- Skiff v. Exact Sciences Corp., 3:26-cv-00653 (W.D. Wis., July 20)
- Cano v. Exact Sciences Corporation, 3:26-cv-00657 (W.D. Wis., July 20)
- Curtis v. Abbott Laboratories, Inc., 1:26-cv-08572 (N.D. Ill., July 20)
- Troesch v. Abbott Laboratories, Inc., 1:26-cv-08706 (N.D. Ill., July 22)
- Sanchez v. Exact Sciences Corporation, 3:26-cv-00674 (W.D. Wis., July 23)
A ninth Wisconsin case filed on July 17 is coded as an employment matter and we have excluded it. Trade coverage described the July 22 Illinois complaint as the first of its kind; the Wisconsin index shows a filing six days earlier.
The complaints run along familiar lines — failure to implement adequate safeguards, claims for damages, and requests that the companies harden their systems and fund long-term credit monitoring. When one incident produces this many parallel filings in two districts, the usual next step is a fight about consolidation. That is a process story, and it is worth being blunt about what it means for you: consolidation, motions to dismiss and any eventual settlement are measured in years, not weeks.
There is no settlement, no claim form, and no administrator
We say this in every one of these pieces because it is the moment when people lose money. No settlement exists in the Exact Sciences matter. No claim form exists. No settlement administrator has been appointed, because there is nothing yet to administer.
So there is nothing to file, and nothing legitimate to pay for. Any site inviting you to “claim your Exact Sciences settlement,” any caller offering to secure your payment for a fee, and any email with a countdown timer is either harvesting your data or taking your money. A real administrator is appointed by a court, is named in a court order, and never charges you.
What is worth doing now is unglamorous and free: check whether your address is in the corpus at haveibeenpwned.com; if it is, assume the name, phone number, date of birth and health details attached to it are also circulating, and expect targeted phishing that references your cancer screening. Given that the breach itself was a voice-phishing attack, treat unexpected phone calls about it with the same suspicion. Consider a credit freeze, which is free at each bureau. Keep any records of costs you incur — if a settlement is ever reached, documented out-of-pocket losses are the tier that pays more than the flat amount.
The one date worth watching
There is no claim deadline here, because there is no claim process. The date that matters is the notification itself — and it carries a legal outer limit.
Exact Sciences is a clinical laboratory, which makes it a HIPAA covered entity. Under the Breach Notification Rule, 45 C.F.R. § 164.404(b), a covered entity must notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.
Abbott has not publicly stated its discovery date, so nobody outside the company can name the exact expiry. But the first public statement is dated July 16 and HIBP records the breach as July 15 — which puts the outer limit somewhere around mid-September 2026, on the order of three to four weeks from now.
When those letters arrive they will matter for a practical reason beyond the disclosure: notification letters are what establish who is in a class, and they typically arrive with an offer of complimentary credit monitoring that has its own enrolment deadline. Read that letter rather than binning it — and verify it independently, the same way you would a Kroll envelope.
The Data Behind This Story
- Settlement status
- None. No settlement, no claim form, no administrator, no fund
- Records published
- 10,869,543 unique email addresses (Have I Been Pwned, verified breach, indexed August 7, 2026)
- Data categories in the published corpus
- Email addresses, names, physical addresses, phone numbers, dates of birth, genders, personal health data — flagged sensitive
- Social Security numbers
- Not among the catalogued categories. The “1 million SSNs” figure comes from attacker claims and is unverified
- Breach date
- July 15, 2026 — 36 days before publication
- Attack method
- Vishing (voice phishing), not encryption malware — per Abbott, August 5, 2026
- Notification letters
- Not sent as of publication. Abbott: notifications will follow “once we have completed our review”
- HIPAA outer limit
- 60 calendar days after discovery (45 C.F.R. § 164.404(b)) — roughly mid-September 2026 if discovery tracks the July 15–16 dates; Abbott has not stated its discovery date
- Lawsuits
- At least 8 proposed class actions filed July 16–23, 2026 (W.D. Wis. and N.D. Ill.)
- Corporate context
- Abbott Laboratories acquired Exact Sciences, maker of Cologuard, in March 2026
- Source: Have I Been Pwned breach record “ExactSciences”, retrieved via the public API on August 20, 2026: PwnCount 10,869,543; BreachDate 2026-07-15; AddedDate 2026-08-07; IsVerified true; IsSensitive true; DataClasses = dates of birth, email addresses, genders, names, personal health data, phone numbers, physical addresses; description noting the data was “later published publicly”.
- Source: Abbott, “Abbott statement on cyber incident in Cancer Diagnostics business”, corporate newsroom — initial statement July 16, 2026, updated August 5, 2026; read August 20, 2026. Source of the personal/health information confirmation, the vishing characterisation, and the pending-notification language.
- Source: Federal dockets via CourtListener/RECAP, read August 20, 2026: Petersen 3:26-cv-00643, Nettles 3:26-cv-00650, Terlikowski 3:26-cv-00651, Skiff 3:26-cv-00653, Cano 3:26-cv-00657, Sanchez 3:26-cv-00674 (all W.D. Wis.); Curtis 1:26-cv-08572 and Troesch 1:26-cv-08706 (N.D. Ill.). A further W.D. Wis. case filed July 17 is coded as an employment matter and excluded.
- Source: 45 C.F.R. § 164.404(b) — HIPAA Breach Notification Rule, individual notice no later than 60 calendar days after discovery.
- Source: Contemporaneous trade coverage (BankInfoSecurity, July 24, 2026) on the ShinyHunters extortion campaign and the first-filed Illinois complaint.
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.