ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

iRhythm discloses data breach after hackers steal patient health information and demand ransom

iRhythm Holdings, Inc., a digital healthcare company specializing in remote cardiac monitoring, disclosed a data breach on June 10, 2026, after unauthorized actors infiltrated third-party-hosted business applications and exfiltrated patient health information, proprietary data, and other personal information, then demanded payment to suppress its release.


The company identified the unauthorized activity on June 8. One day later, a threat actor sent communications claiming to have stolen the data and demanding payment in exchange for not publicly disclosing it. iRhythm confirmed the exfiltration and, on June 10, determined the incident was material given the volume of potentially affected data.


"On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information," iRhythm stated in a filing with the U.S. Securities and Exchange Commission. "The communications from the threat actor demanded payment in exchange for not publicly disclosing this information."


The company disclosed that the breach was carried out through a social engineering attack targeting third-party-hosted business applications. iRhythm did not identify the specific applications involved or provide technical details about the intrusion method.


iRhythm said its clinical and medical device systems, patient safety infrastructure, manufacturing and distribution operations, and financial reporting systems were not affected. The company also stated it does not store patients’ payment card or financial account information, and confirmed that no such data was part of the breach.


The company activated its cybersecurity response plan and engaged external cybersecurity experts following discovery of the incident. An investigation into the scope of the breach remains ongoing.


No ransomware group has publicly claimed responsibility for the attack, and it is not known whether iRhythm has entered into negotiations with the threat actor.


iRhythm’s cardiac monitoring service has analyzed more than 2 billion hours of heartbeat data gathered from over 12 million patients. Its flagship product, the Zio, is a wearable patch that records a patient’s heart rhythm continuously for up to several weeks. Clinicians use data from the device, processed through proprietary algorithms, to diagnose conditions including atrial fibrillation and other cardiac arrhythmias.


The breach at iRhythm follows a separate incident disclosed last week by Danish pharmaceutical company Novo Nordisk, the world’s largest producer of insulin, which reported that patient information from certain clinical trials was stolen after attackers compromised internal IT systems.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543