The medical technology company Medtronic is currently notifying nearly 3.8 million individuals whose personal and medical information was compromised in a cyberattack targeting the company’s IT systems.
According to a filing submitted by Medtronic to the California Attorney General’s Office, the stolen data included names, contact details, dates of birth, Social Security numbers, and patient health information. The company stated that there is currently no evidence that the data has been publicly exposed or distributed online.
In notifications to authorities in the U.S. state of Indiana, Medtronic specified that 3,834,294 individuals were affected. The company is now offering those impacted a range of free protection services for 24 months, including credit monitoring, dark web surveillance, and support in the event of identity theft.
Attack Took Place in April
The breach itself occurred several months ago. In April 2026, the group known as ShinyHunters reportedly gained access to Medtronic’s corporate IT environment. At the end of the month, the company publicly confirmed the incident but emphasized that its products, manufacturing operations, and distribution processes had not been affected.
As early as April 17, ShinyHunters had listed Medtronic on its own leak platform hosted on the Tor network. The group claimed at the time to have copied more than 9 million records and several terabytes of internal company data. The corresponding Medtronic entry has since disappeared from the platform. This is considered a possible indication that a ransom payment may have been made to prevent the release of the stolen information.
Company Announces Additional Security Measures
Medtronic says it has implemented additional security measures and continues to work with external cybersecurity experts to strengthen its systems. The company also confirmed that law enforcement agencies have been notified and that relevant regulatory authorities have been informed about the incident.
The ShinyHunters group has previously been linked to several major data breaches affecting international companies and is currently considered one of the most active actors in the field of cyber extortion.
(lb)