← Medtronic

2026 Medtronic — ShinyHunters breach; 3.83M patients notified (Apr–Jul)

2026 3.8M records affected Share on X

Data compromised

Names, dates of birth, Social Security numbers, contact information, and health-related information per notification letters and Indiana AG filing

Technical writeup

Medtronic confirmed unauthorized access to certain corporate IT systems during April 13–19, 2026, after ShinyHunters listed the medical-device company on an extortion portal claiming theft of more than nine million PII-oriented records. Medtronic stated products, patient safety interfaces, hospital customer networks, manufacturing/distribution, and financial reporting systems were not characterized as impacted in the same way as segregated corporate IT. In July 2026 Medtronic began mailing customer notification letters offering 24 months of credit monitoring, dark-web monitoring, healthcare-plan ID monitoring, and identity-restoration services with up to $1 million reimbursement; letters cite names, contact information, dates of birth, Social Security numbers, and health-related information. Medtronic told the Indiana Attorney General's Office that 3,834,294 individuals were affected; earlier partial state filings had cited at least 369,509 across Texas, Massachusetts, and Vermont before the consolidated count was published. SecurityWeek and HIPAA Journal reported the July 2026 notification wave. Medtronic stated it had no evidence the stolen information was posted publicly. ShinyHunters removed Medtronic from its leak site after the incident, suggesting possible ransom negotiation. Treat the actor's original ~9M marketing figure as superseded by the company/regulator attested total unless HHS OCR publishes a different figure.

Root cause

Unauthorized access to corporate IT segment; ShinyHunters extortion listing

References