Cyber Incident Victim: Medtronic
Timeline
Summary
Medtronic disclosed that an unauthorized party accessed its corporate IT systems, resulting in the compromise of personal and medical information for approximately 3.8 million individuals, including names, contact details, dates of birth, Social Security numbers and health-related data. The attacker, identified as the ShinyHunters group, claimed access to up to nine million records but the company found no evidence the data was publicly posted and reported no impact to product safety, patient safety or manufacturing operations, and is providing affected individuals with credit monitoring, dark web monitoring and identity theft restoration services while working with law enforcement and third‑party experts to strengthen security.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
In early March 2026 Stryker experienced a global cyberattack attributed to the pro‑Iran group Hawala Hack in response to U.S. and Israeli military strikes, which wiped data from employee electronic devices, disrupted manufacturing and shipping for weeks and forced the postponement of some surgeries. On April 24 2026 Medtronic filed an SEC Form 8‑K disclosing that an unauthorized party had accessed its corporate IT systems, a disclosure accompanied by a claim from the ShinyHunters ransomware group that up to nine million records had been exfiltrated. Medtronic emphasized that hospital networks supporting its devices remained separate from its corporate IT, manufacturing and distribution networks and were not exposed. On April 28 2026 Medtronic issued a statement saying it had contained the cyberattack on its IT systems, activated its incident response protocols, engaged leading cybersecurity experts to assist with investigation and remediation, and was working to determine whether any personal information had been accessed, while stating it did not expect the incident to affect its business or financial results.

On May 5 2026 a summary of April 2026 breaches noted that Medtronic had confirmed an unauthorized access incident with up to nine million records claimed by ShinyHunters, that hospital networks running its devices were not exposed, and that the attack was characterized as a ShinyHunters extortion effort with an undisclosed initial access vector. A May 7 2026 report described Medtronic’s ongoing investigation into the unauthorized system access, noting a possible link to a broader campaign targeting companies using the Salesforce Experience Cloud platform, referencing ShinyHunters’ use of social engineering and vishing tactics, and citing FBI indicators of compromise related to threat actors using API queries to exfiltrate data after gaining access to Salesforce environments, as well as UNC6040 actors requesting credentials and multi‑factor authentication codes to facilitate data exfiltration. Medtronic reiterated that it had seen no impact on its products, patient safety, connections to customers, manufacturing and distribution operations, financial reporting systems or ability to meet patient needs.
On July 2 2026 Medtronic began notifying individuals who may have been affected by the cyberattack disclosed more than two months earlier, stating it had no evidence that the accessed data had been posted to the public internet. The company offered 24 months of complimentary credit monitoring, dark web monitoring and identity theft restoration services, and established a dedicated call center for affected individuals, while reiterating that there was no identified impact on product security, patient safety, manufacturing, distribution or the ability to meet patient and customer needs. The same article referenced other medtech incidents in 2026, including a Stryker attack that halted manufacturing and shipping for weeks, an Intuitive Surgical phishing incident that compromised customer and employee data with no reported fraud or identity theft, and an iRhythm incident in which a threat actor claimed to have stolen sensitive data from third‑party‑hosted business applications and demanded payment to avoid public disclosure.
On July 3 2026 Medtronic announced it had begun sending written notification letters to 3,834,294 individuals whose personal and medical information—including names, contact details, dates of birth, Social Security numbers and health‑related details—had been compromised in the April 2026 breach. The company said it would provide 24 months of free credit monitoring, dark web monitoring and identity theft restoration services, and noted that it had informed the Indiana Attorney General’s Office of the number of affected individuals. Medtronic added that it had implemented additional safeguards, was continuing to work with third‑party cybersecurity experts, was cooperating with law enforcement and was notifying relevant regulatory authorities. The ShinyHunters group had previously placed Medtronic on its Tor‑based leak site on April 17 2026 and later removed the company from that site. No further speculative statements are included beyond the facts presented in the source materials.
