Fraud & Scams

Exact Sciences Data Breach Exposes Personal and Health Information

Becky Ross
By 
Becky Ross
  •  
August 18, 2026
Exact Sciences Data Breach Exposes Personal and Health Information

If you have used Exact Sciences or Cologuard, your personal information may have been exposed in a recent data breach. Here’s what happened and the steps you can take now to stay safe.

In July 2026, cancer diagnostics company Exact Sciences, now owned by Abbott Laboratories, experienced a significant data breach involving some of its older computer systems. The stolen information was later published online, potentially exposing personal and health information belonging to millions of people. Even though this data breach originally happened in July, Carefull is currently picking up on an increase in identity breaches related to this event. 

What happened in the Exact Sciences breach?

Abbott first disclosed the cyber incident on July 16, 2026, saying an unauthorized party had accessed a limited number of internal systems within its Cancer Diagnostics business. Abbott said the affected legacy Exact Sciences systems were separate from its other systems and that the attack was the result of vishing, or voice phishing (a phone call where a scammer impersonates a trusted source to trick someone into handing over credentials or system access) rather than ransomware or encryption malware.

The cybercriminal group ShinyHunters claimed responsibility for the attack and subsequently published data allegedly obtained from Exact Sciences.

On August 5, Abbott confirmed that some of the affected files contained personal information and/or personal health information. Abbott said it was continuing to analyze the affected data and would make required notifications to impacted individuals once its review was complete. Approximately 10.9 million unique email addresses were included in the exposed information. Other compromised information includes names, physical addresses, phone numbers, dates of birth, gender and personal health information.

Why this breach matters

A data breach does not necessarily mean someone has broken into your personal email, bank account, or other accounts. But exposed personal information can give scammers something extremely valuable to leverage in scam attempts. Names, email addresses, phone numbers, dates of birth, addresses and health-related information can potentially be combined to create highly convincing scams. A criminal may know enough to appear to be calling or messaging from a healthcare provider, insurance company, financial institution or other trusted organization.

That makes unexpected communications following a breach particularly important to scrutinize.

Cybercriminals also routinely use information obtained through breaches to create phishing messages or attempt to gain access to other accounts. That is why Carefull alerts our members to these occurrences and recommends taking action when your email address or other information is discovered on the dark web.

What should you do if your information was exposed?

If Carefull alerted you that your information appeared in the Exact Sciences breach, or another data breach, there are several steps you can take right away:

  1. Change your password. If the exposed email address is associated with a password that you still use, update it. More importantly, if you have reused the same password on banking, shopping, social media or other accounts, change those passwords too.
  2. Turn on two-factor authentication. Enable two-factor or multi-factor authentication (2FA/MFA) on your email, financial accounts and other important services whenever it is available. This adds an additional barrier even if someone obtains your password.
  3. Use a unique password for every account. A reputable password manager can generate and securely store strong, unique passwords so that one compromised password cannot easily be used to access multiple accounts.
  4. Be especially alert for phishing calls, texts and emails. Be suspicious of unexpected communications asking you to provide personal information, verify account details, click a link, download something or send money. Information exposed in a breach can be used to make a scam seem much more authentic.
  5. Don't assume a caller is legitimate because they know something about you. A caller knowing your name, date of birth, address, healthcare provider or other personal detail is no longer proof that they are who they claim to be. If you're contacted unexpectedly, end the communication and contact the organization independently using a phone number or website you know is legitimate.
  6. Pay closer attention to your financial accounts. Watch for transactions or account activity you don't recognize, and investigate unexpected changes quickly. The sooner unusual activity is identified, the more options you may have to address it.

A Carefull alert is an early warning

Seeing that your information has appeared on the dark web can be alarming. But this is why Carefull includes dark-web monitoring in our complete protection platform. Follow the steps provided in your Carefull alert and contact the Carefull Care Team for any needed assistance. 

Carefull's role is to help you become aware of potential exposure and respond to it. When Carefull identifies information associated with you in known breached data, an alert can give you an opportunity to strengthen your security, watch for suspicious activity and be more prepared for scams that may follow.

And remember: receiving an alert that your email address appeared on the dark web does not automatically mean your email account itself has been hacked. It means your information may have been included in data exposed somewhere else, and it's a signal to take additional precautions.

Stay alert after a data breach

Data stolen today can be used in scams weeks, months, or even years later. And the more information criminals know, the easier it can be to create a message that feels personal, urgent and believable.

Treat unexpected requests for money, passwords, verification codes, or sensitive information with caution, even when the person contacting you seems to know a surprising amount about you.

Carefull helps you stay aware of risks like data breaches so you can take action before exposed information turns into a bigger problem.

Becky Ross

Becky Ross

3 Steps to Safer Money,
Try it Free for 30 Days

Step 1

Start your free,
no-risk trial

Step 2

Connect the accounts and cards you want protected

Step 3

Stay alerted to any
unusual activity

Disclaimer: The information and resources above and within the articles are provided for your convenience through Carefull and should not be considered an endorsement of products, services or information provided, or an assurance of security or privacy provided at the linked site. Bristol County Savings Bank does not own or operate these sites and does not guarantee the accuracy, completeness or timeliness of the information contained therein. We encourage you to review their privacy and security policies which may differ from Bristol County Savings Bank. Bristol County Savings Bank assumes no liability for any loss or damage resulting from any reliance on the material provided.