← BACK TO FEED
data breachMedtronicShinyHuntershealthcare securityransomware

Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach

Medtronic is notifying patients that their personal and health data — including names, Social Security numbers, and medical information — may have been stolen during a cyberattack in which unauthorised actors accessed its corporate systems for nearly a week in April. The extortion group ShinyHunters claimed responsibility, alleging it stole over nine million records and demanding a ransom, though Medtronic has not publicly attributed the attack or confirmed whether data was actually exfiltrated. The company states that no medical devices were affected and is offering impacted individuals two years of complimentary credit and identity monitoring services.

Pacemaker maker Medtronic is notifying patients that their personal and medical data may have been compromised after attackers spent nearly a week roaming parts of its corporate network in April.

Breed notification letters sent to affected individuals confirm that unusual activity was detected on April 15, with the company later establishing that an unauthorised party had accessed certain internal systems between April 13 and April 19. That's a six-day window. Not ideal.

The exposed data is exactly what you'd expect a medical device company to hold: names, contact information, dates of birth, Social Security numbers, and health information. Medtronic collects this data for product updates and regulatory compliance purposes.

The company has stated there is no evidence the stolen data has been published online or made publicly available. Whether it was copied and is sitting on someone's hard drive somewhere is a rather different question, and one Medtronic hasn't answered.

For patients understandably worried about their implanted devices, Medtronic is clear that the incident had no impact on any device's ability to operate or deliver therapy. Its corporate IT systems are apparently segregated from the networks that actually run its products, and hospital customer networks are managed separately. So the breach was corporate, not clinical.

What Medtronic's carefully worded notification does not mention is ShinyHunters. The ransomware and extortion crew listed Medtronic on its dark web leak site shortly after the intrusion began, claiming to have lifted more than nine million records and threatening to publish them unless a ransom was paid by April 21. The listing quietly disappeared later that month without any data being released. ShinyHunters typically removes victims from its site after some form of agreement is reached. Draw your own conclusions.

Medtronic's notification makes no reference to any ransom demand, extortion attempt, or the identity of the attackers. The company has not publicly attributed the incident to anyone.

Several obvious questions remain unanswered. How many patients were affected? How did the attackers get in? And why has it taken more than two months to start telling people?

On the remediation side, Medtronic says it has tightened security, engaged law enforcement, and notified relevant regulators. Affected individuals are being offered two years of complimentary credit monitoring, dark web monitoring, and identity restoration services. The standard breach response package, essentially.

READ NEXT
ShinyHunters Breach Exposes Data of 3.8 Million Medtronic PatientsNichirei Cyberattack Leaves Japan's Frozen Food Chain on IceSmall US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.