2026 iRhythm Holdings — patient PHI stolen from third-party-hosted apps (SEC disclosure)
Data compromised
Patient protected health information and personal data per SEC filing; payment cards and clinical device systems not involved per company
Technical writeup
Digital cardiac-monitoring vendor iRhythm Holdings disclosed in a June 10, 2026 SEC filing that it received extortion communications on June 9 from a threat actor claiming possession of proprietary data, patient protected health information, and other personal information stored on third-party-hosted business applications. The company confirmed exfiltration from those applications on June 10, classified the incident as material given data volume, and stated attackers gained access through social engineering. iRhythm said clinical/medical device systems, manufacturing, financial reporting, and payment card data were not affected; Reuters and MassDevice reported no impact on device systems or patient safety. BleepingComputer reported the disclosure on June 16; no public victim count had been published at catalog time.
Root cause
Social engineering enabling access to third-party-hosted business applications; extortion demand June 9
References
- https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/
- https://www.sec.gov/Archives/edgar/data/1388658/000138865826000055/irtc-20260610.htm
- https://www.reuters.com/legal/litigation/irhythm-discloses-cyber-incident-says-no-impact-device-systems-patient-safety-2026-06-15/
- https://www.massdevice.com/irhythm-reports-cybersecurity-breach-health-data/