
Healthcare technology company Medtronic said it suffering a major cyber security incident after the ShinyHunters hacker group claimed that it breached its internal network and stole over 9 million records.
Medtronic is an American-Irish multinational healthcare technology and medical devices company. Among the world’s largest medical device manufacturers by revenue, it operates in more than 150 countries and develops innovative technologies to treat over 70 medical conditions. The company is particularly known for its cardiovascular innovations, including the invention of the first battery-powered pacemaker.
In April, the ShinyHunters hacker group claimed that it breached Medtronic’s internal network, stealing more than 9 million records containing personally identifiable information and terabytes of corporate data.
The group listed Medtronic on its data leak site on April 18 and threatened to release the data unless ransom negotiations began by April 21.
Acknowledging ShinyHunter’s claim, Medtronic said in a data security incident notice filed with the Office of California Attorney General that on April 15, it identified unauthorised access to its internal network.
The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. It also took steps to contain the incident, secure the affected network and notified relevant law enforcement authorities about the same.
“The investigation determined that from April 13 to April 19, 2026, an unauthorised actor accessed certain Medtronic corporate IT systems,” Medtronic said.
The compromised data included names, contact information, dates of birth, Social Security numbers, and health-related information. In a filing with Texas state regulators, Medtronic said it has identified at least 297,307 individuals who were impacted by the incident.
“As part of our ongoing commitment to the security of personal information in its care, Medtronic has implemented additional safeguards and continues to work with third-party cybersecurity experts to identify opportunities to further strengthen the security of its systems,” Medtronic added.
While the company found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through Epiq to all affected individuals.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543