
Cardiac monitoring device manufacturer iRhythm suffered a significant data security incident that involved threat actors gaining unauthorised access to data stored within a third-party-hosted business application.
iRhythm, a cardiac monitoring device manufacturer, reported a major data security breach after threat actors accessed data held on select third-party-hosted business applications.
iRhythm Technologies is a healthcare technology company that develops wearable cardiac monitoring devices and data analytics solutions for detecting heart rhythm disorders. Its flagship product, the Zio patch, provides continuous ambulatory monitoring outside clinical settings, helping physicians diagnose arrhythmias more efficiently and accurately.
In a filing with the U.S. Securities and Exchange Commission (SEC), iRhythm said that on June 8, it detected unauthorised activity involving data stored in certain third-party-hosted business applications. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the scope of the incident.
On June 9, 2026, iRhythm received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information, and other personal data, and demanding payment in exchange for not disclosing it publicly. Following these communications, the company confirmed that certain data had been exfiltrated from the affected applications.
By June 10, iRhythm determined the incident to be material due to the volume of potentially impacted data.
“Based on its investigation as of the date of this Current Report on Form 8-K, (1) the Company has not identified any impact to its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems, or the Company’s ability to meet patient needs and (2) the affected data was obtained through social engineering and is from certain third-party-hosted business applications.
“The incident does not involve the Company’s clinical or medical device systems or connections to customers and the Company does not store or retain individual financial account information or payment card information,” iRhythm said in its SEC filing.
While the company has not found evidence of ongoing unauthorised access to its systems, it continues to investigate the nature and scope of the incident, including the categories and volume of data involved and the individuals affected.
iRhythm stated that the incident is not expected to have a material impact on its financial condition or results of operations. The company also noted that it carries cybersecurity insurance, which may cover some of the associated losses, though it cannot guarantee that the coverage will be sufficient to fully offset all costs.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on iRhythm. The company also did not share details on who was behind the attack, how much data was compromised, or whether it had received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543