Cyber Incident Victim: iRhythm
Timeline
Summary
iRhythm disclosed that unauthorized activity was detected on certain third‑party‑hosted business applications, leading to a threat actor’s claim of having stolen proprietary data, patient protected health information and other personal information and demanding payment to prevent public release. The company confirmed that some data was exfiltrated from those applications but has not verified the actor’s description of the compromised data. It stated that its clinical or medical device systems, manufacturing and distribution operations, patient safety and financial reporting systems were not affected and that it does not store individual financial account or payment card information. The company is working with external cybersecurity experts to investigate the scope and volume of the data involved and the number of individuals impacted, and it believes the incident is unlikely to have a material financial impact.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On June 8, 2026, iRhythm detected unauthorized activity involving data maintained on certain third‑party‑hosted business applications, according to a securities filing with the SEC. The following day, June 9, the company received a message from a threat actor claiming to have stolen sensitive information, including proprietary data, patient protected health information and other personal information. The threat actor demanded payment in exchange for not publicly disclosing the alleged stolen data. iRhythm confirmed that certain data had been exfiltrated from those applications but stated it had not verified whether the threat actor’s description of the compromised data was accurate. The company emphasized that the incident did not involve its clinical or medical device systems or connections to customers. iRhythm also noted that it does not store or retain individual financial account information or payment card information.

iRhythm activated its cybersecurity response plan and began working with external cybersecurity experts to investigate the breach. As of the June 16 SEC filing, the company had not identified evidence of ongoing unauthorized access to its systems. The investigation aimed to determine the nature and scope of the incident, including the categories and volume of the data involved and the individuals affected, but the exact details remained under review. iRhythm stated that its products, manufacturing and distribution operations, patient safety and financial reporting systems were not impacted by the attack. The company disclosed that it holds cybersecurity insurance that may cover certain losses related to the incident. iRhythm also said it believed the incident was not likely to have a material impact on its financial condition or results of operations as of the filing date.
The iRhythm breach was disclosed in the same period that other medtech companies reported cyber incidents, including Stryker’s manufacturing‑shutdown attack in March and Intuitive Surgical’s phishing incident that week. Medtronic had previously disclosed in April that an unauthorized party accessed data in certain corporate IT systems. No known ransomware or extortion group has claimed responsibility for the iRhythm attack, and it remains unclear whether the company engaged with the threat actor or made any payment. iRhythm has not posted an update to the attack on its website beyond the SEC filing.
