← All posts

You Bought the Company. You Also Bought Its Login Screen.

On March 23 of this year, Abbott closed a $21 billion acquisition of Exact Sciences — one of the largest medtech deals in years, and a serious bet on the future of cancer screening. Less than three months later, an extortion group posted Abbott to its leak site.

Abbott's public statement is worth reading closely, because every word in it was chosen carefully. The company confirmed "unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only," said there was no impact to operations, products, manufacturing, or patient care, and added one line that deserves an executive's full attention: the legacy Exact Sciences systems are separate from Abbott's.

That sentence is true. It is also the entire story.

Separate Is Not the Same as Secure

When a board approves an acquisition, the integration plan gets discussed in terms of people, facilities, product lines, and synergies. Systems integration shows up as a cost line and a timeline. What almost never gets discussed is the interim period — the twelve, eighteen, twenty-four months when the acquired company's technology stack still runs on its own identity infrastructure, its own help desk, its own access policies, and its own security maturity, while carrying your name and your ticker symbol.

During that window, "separate" cuts both ways. It genuinely limits blast radius — Abbott appears to have contained the incident to one business unit, which is a real security outcome and not an accident. But separateness also means the acquired environment is not yet under your controls, not yet in your monitoring, and not yet governed by your policies. It is a subsidiary of your company for reporting purposes and a foreign country for security purposes.

Attackers understand this arithmetic better than most acquirers do. A newly acquired business is a target-rich moment: employees are anxious, org charts are in flux, unfamiliar names are sending unfamiliar requests, and "we're transitioning systems" is a plausible explanation for almost any strange login prompt.

How These Attacks Actually Work

The group claiming the Abbott intrusion, ShinyHunters, told reporters it started with voice phishing calls to several Abbott employees in mid-June, which let it compromise a single Microsoft Entra single sign-on account. Those specifics are the attacker's account of events, not a confirmed finding, and the group's claims about what it took — tens of millions of records, medical orders, patient-visit notes — remain unverified by anyone independent. Abbott has said it does not expect a material impact on its business or financial results.

But the method is not in dispute, because it is now the dominant pattern in the sector. On July 24, Health-ISAC — the health sector's threat-intelligence sharing organization — issued an advisory warning of an observed increase in successful attacks of exactly this type. Its summary of the mechanic is the most useful sentence any executive will read this month:

"SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale."

Here is what that means without the jargon. Your company almost certainly uses single sign-on: employees authenticate once, and that one identity unlocks dozens of cloud applications — email, file storage, CRM, HR, finance, ticketing, data platforms. It is a genuine security improvement over dozens of separate passwords. It is also a master key.

The attack chain doesn't involve exotic malware. Someone calls an employee or, more often, calls the help desk pretending to be an employee, and talks a human being into resetting a password, resetting multifactor authentication, or enrolling a new device. That's it. From there the attacker logs into the SSO dashboard, sees the full list of applications that identity can reach, and starts downloading. Health-ISAC notes attackers are now using purpose-built kits that let them manipulate authentication prompts in real time while the call is in progress.

No firewall was defeated. No zero-day was burned. A person was persuaded.

The Second Incident, and the Value of Knowing What You Hold

Abbott is investigating a second, separate claim: an actor calling itself ShadowByt3$ says it accessed Abbott's LabCentral customer portal in early July using compromised customer credentials and pulled documents through the site's programming interfaces. The attacker characterized the haul as sensitive technical and regulatory documentation.

Abbott disputed that characterization, saying the portal houses publicly available technical reference material — operating manuals, troubleshooting checklists, product specifications — and no proprietary or sensitive customer information.

Notice what Abbott was able to do there. Within days, the company could state with confidence what data lived in a specific externally-facing system and what that data was worth. That is not a lucky guess; it is the product of knowing your own inventory. Most organizations cannot answer that question about their own portals in a week, let alone a day, and the resulting silence is what turns an attacker's press release into your company's narrative.

The Governance Gap

In Cyber Risk Is Business Risk, I make the case that the Three Questions — what are we protecting, what would it cost to lose it, and are we spending in proportion to that answer — have to be asked about the whole enterprise as it exists today, not the enterprise as your architecture diagram wishes it were. Acquisitions break that alignment on day one.

The deeper governance problem is timing. Cyber diligence in M&A, when it happens at all, tends to happen before signing: a questionnaire, a review of past incidents, maybe a scan. That answers "did we buy a company that was already breached?" It does not answer "have we created a period of elevated risk by owning a company we don't yet control?" Those are different questions, and only the second one is actionable after closing.

There's a personal-liability dimension too. When an acquired unit is breached, the disclosure obligations, the regulatory exposure, and the shareholder scrutiny attach to the parent — to your 8-K, your risk factors, your board minutes. The seller is gone. "Their systems, not ours" is an accurate technical statement and a worthless legal one.

What to Ask Your CISO This Week

"For every business we've acquired in the last three years, whose identity system are those employees using?" If the answer is "theirs, for now," you have an open exposure with a name and a headcount. Ask when it closes.

"Can someone call our help desk, claim to be an employee, and get a password or MFA reset on that same call?" Health-ISAC's single highest-priority recommendation is a "no same-call" policy — resets require a ticket and a verified callback to a previously known number, with manager approval for privileged accounts. This is a process change, not a purchase.

"Which of our people have phishing-resistant multifactor authentication, and which still have codes by text message?" Hardware-backed methods like FIDO2 security keys defeat this attack chain outright. Executives, administrators, finance, and help desk staff should be first, not last.

"If a single employee's SSO account were taken over tomorrow, what could that identity reach — and how fast could we revoke every active session?" The first half is a scoping question. The second half is a drill, and you should know whether it has ever been run.

"What's on our externally-facing customer portals, and who decided it belonged there?" Abbott could answer this. Most companies discover the answer during the incident.

Acquisitions are where strategy and risk meet most directly, and where cyber exposure is most reliably underwritten as someone else's problem. The systems you inherit don't wait politely for integration. Neither do the people who call your help desk.