
Medtronic, the world's largest medical device company by revenue, disclosed on April 24, 2026, that an unauthorized party accessed data in certain corporate IT systems. The total number of individuals affected by the breach was determined to be 3,834,294, including 297,307 Texas residents, 90,889 Indiana residents, 64,035 Washington residents, 63,534 Massachusetts residents, 12,215 New Hampshire residents and 8,668 Vermont residents were impacted.
On April 17, 2026, a threat actor known as ShinyHunters posted a claim on the dark web's Tor network alleging they had breached Medtronic's database. The threat actor claimed to have obtained over 9 million records containing personally identifiable information (PII), along with additional terabytes of internal corporate data.
One week later, on April 24, 2026, Medtronic publicly confirmed that an unauthorized party had accessed data within certain corporate IT systems through a notice on its website. The company filed disclosures with the U.S. Securities and Exchange Commission and with the California Attorney General.
The company emphasized that the networks supporting its corporate IT systems are separate from those supporting its medical device products and its manufacturing and distribution operations.
The specific types of personal information that may have been exposed include names, dates of birth, Social Security numbers, medical information and health records.
Medtronic has not publicly verified the claims made by ShinyHunters regarding the volume or nature of the compromised data. The investigation into the full scope of the breach remains ongoing.
Upon identifying the unauthorized access, Medtronic stated that it took steps to contain the incident. The company activated its incident response protocols and engaged leading cybersecurity experts to support its investigation and remediation actions.
The company is working to identify any personal information that may have been accessed during the breach.
Medtronic stated it will provide notifications and support services as needed to individuals whose data may have been affected. It also said it will continue to provide updates to impacted individuals as it learns more about the scope of the incident.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)