Contained High impact Data breach Checked 1d ago

Medtronic breach exposes millions of patients' data

Medtronic detected hackers inside its corporate IT systems around April 13, 2026, and later confirmed that patients' Social Security numbers and medical information were stolen. The company says about 3.8 million people are affected and has been sending notification letters. MiniMed Group filed its own notice for the same breach. No new activity against Medtronic has been reported, though ShinyHunters remained active in the healthcare sector in September.

Started
Apr 13, 2026
Latest activity
Sep 10, 2026
Attributed to
ShinyHuntersLikely
Where
United States
Sectors
Healthcare, Manufacturing
Scale
One company, Medtronic, including its MiniMed Group subsidiary, which filed its own breach notice for the same incident

Current status

On 2026-09-10, Health-ISAC warned that ShinyHunters was still targeting healthcare workers, but no new Medtronic activity was reported.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

ShinyHunters claimed responsibility, but Medtronic has not publicly confirmed the group as the attacker.

Impact

Hackers accessed Medtronic's corporate IT systems and stole personal and medical information, including Social Security numbers, for millions of patients who use Medtronic medical devices or services. There is no indication the medical devices themselves were affected or that patient safety was put at risk.

What to do

Affected patients who receive a notification letter from Medtronic should enroll in the free credit monitoring being offered and watch for phishing emails or calls that reference the breach.

Timeline

  1. Sep 10, 2026

    Health-ISAC warned healthcare providers that ShinyHunters was using phone calls to target employees and steal data. The warning did not report new activity against Medtronic.

    Containedhealthcareitnews.com
  2. Sep 9, 2026

    AdaptHealth confirmed that 4.1 million people were exposed in a July cyberattack attributed in reporting to ShinyHunters, adding to evidence that the group remained active after the Medtronic breach. No new activity against Medtronic was reported.

    Containedbleepingcomputer.com
  3. Aug 31, 2026

    McKesson confirmed a separate data theft that ShinyHunters claimed. McKesson did not name the attacker, and no new activity against Medtronic was reported.

    Containedhelpnetsecurity.com
  4. Aug 7, 2026

    ShinyHunters published data from Exact Sciences, a different healthcare victim, showing that the group remained active. No new activity against Medtronic was reported.

    Containedtheregister.com
  5. Jul 31, 2026

    A healthcare-sector information-sharing group, Health-ISAC, warned of a rise in ShinyHunters data-theft attacks on healthcare and medical technology companies, naming Medtronic among the group's earlier victims alongside iRhythm, One Medical, DentaQuest, AdaptHealth, and Hims and Hers. The advisory described no new activity against Medtronic itself.

    Containedhipaajournal.com
  6. Jul 27, 2026

    Reports noted hackers continued to claim over 9 million records were stolen even as Medtronic's own count remained lower.

    Containedmsn.com
  7. Jul 23, 2026

    A California attorney general breach-notice filing listed the date of the intrusion as April 13, 2026, and showed that Medtronic subsidiary MiniMed Group, Inc. filed its own separate notice referencing the same breach.

    Containedmorningoverview.com
  8. Jul 16, 2026

    Legal analysts noted Medtronic notifications were continuing as part of the breach response.

    Containedjdsupra.com
  9. Jul 2, 2026

    Medtronic disclosed in filings that the breach affected about 3.8 million people.

    Containedsecurityweek.com
  10. Jul 2, 2026

    Medtronic said 3.8 million people were being notified that their personal and medical information was compromised.

    Containedsecurityweek.com
  11. Jul 2, 2026

    State attorney general filings in Massachusetts and Vermont showed at least 72,000 residents in those two states had Social Security numbers and health records exposed.

    Containedbeckershospitalreview.com
  12. Jul 2, 2026

    Medtronic said the breach affects about 3.8 million people and began sending notification letters; reports named the ShinyHunters extortion group as responsible.

    Containedsecurityweek.com
  13. Jun 22, 2026

    Medtronic said it was still investigating the scope and impact of the breach with outside cybersecurity firms.

    Containedcybersecuritynews.com
  14. Jun 22, 2026

    Medtronic publicly confirmed the breach and said patient personal and health-related information may have been exposed.

    Emergingcybersecuritynews.com
  15. Apr 28, 2026

    Medtronic confirmed the data breach after the ShinyHunters group claimed responsibility for stealing millions of records.

    Activeinfosecurity-magazine.com
  16. Apr 27, 2026

    Medtronic confirmed a breach after ShinyHunters claimed it stole about 9 million records.

    Activebleepingcomputer.com
  17. Apr 24, 2026

    Medtronic publicly disclosed the breach and began notifying affected individuals.

    Activeinfosecurity-magazine.com
  18. Apr 15, 2026

    Medtronic detected unusual activity in its corporate IT systems.

    Emergingcybersecuritynews.com
  19. Apr 15, 2026

    Medtronic detected unusual activity in its corporate IT systems and launched an internal investigation with outside cybersecurity help.

    Emergingcybersecuritynews.com
  20. Apr 13, 2026

    Medtronic detected unauthorized access to certain corporate IT systems.

    Emergingmsn.com

Sources

Related reports