iRhythm Technologies, Inc.
Incident posture
Linked entities
- Victim
- iRhythm Technologies, Inc.
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
iRhythm detected unauthorized activity involving data stored on certain third‑party‑hosted business applications and identified the breach through social engineering tactics. A threat actor contacted the company claiming to have exfiltrated proprietary information, patient protected health data and other personal details and demanded payment to prevent public disclosure. The company confirmed that some data had been removed from the applications but has not verified the threat actor’s description of the stolen information. It stated that its clinical or medical device systems, manufacturing, distribution, patient safety and financial reporting were unaffected and that there is no evidence of ongoing unauthorized access. iRhythm believes the incident is unlikely to have a material impact on its financial condition and is working with external cybersecurity experts while maintaining cybersecurity insurance coverage.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 8, iRhythm detected unauthorized activity involving data maintained on certain third-party-hosted business applications. On June 9, a threat actor contacted the company claiming to have stolen sensitive information, including proprietary data, patient protected health information and other personal information. The threat actor demanded payment in exchange for not publicly disclosing the information. After receiving the communication, iRhythm confirmed that certain data had been exfiltrated from those applications. The company disclosed the breach in an SEC filing on Monday (June 16). The attack involved social engineering, though the specific application targeted was not named.
iRhythm stated that the incident did not involve its clinical or medical device systems, connections to customers, manufacturing and distribution operations, patient safety, or ability to meet patient needs. The company noted it does not store or retain individual financial account information or payment card information. iRhythm said it has not identified evidence of ongoing unauthorized access to its systems and there has been no impact on its ability to manufacture or distribute products. The company believes the incident is not likely to have a material impact on its financial condition or results of operations. iRhythm activated its cybersecurity response plan and launched an investigation with external cybersecurity experts and external advisers. The investigation aims to determine the nature and scope of the incident, including the categories and volume of data involved and the individuals affected. The company has cybersecurity insurance that may cover certain losses. No known ransomware or extortion group has taken credit for the attack, and it remains unclear whether iRhythm agreed to pay a ransom or engaged with the hackers.
iRhythm is the latest medtech company to be hit by a cyberattack in 2026. In March, Stryker suffered an attack that shut down ordering, shipping and manufacturing for weeks and cut into its first-quarter results. The same week Stryker disclosed its attack, Intuitive Surgical reported a phishing incident where an unauthorized third party accessed information including customer business and contact information as well as employee and corporate data. Meanwhile, Medtronic reported in April that an unauthorized party accessed data in certain corporate IT systems.
Sources
Sources available to members: 3 sources.