Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach
Pacemaker maker Medtronic is notifying patients that their personal and medical data may have been compromised after attackers spent nearly a week roaming parts of its corporate network in April.
Breed notification letters sent to affected individuals confirm that unusual activity was detected on April 15, with the company later establishing that an unauthorised party had accessed certain internal systems between April 13 and April 19. That's a six-day window. Not ideal.
The exposed data is exactly what you'd expect a medical device company to hold: names, contact information, dates of birth, Social Security numbers, and health information. Medtronic collects this data for product updates and regulatory compliance purposes.
The company has stated there is no evidence the stolen data has been published online or made publicly available. Whether it was copied and is sitting on someone's hard drive somewhere is a rather different question, and one Medtronic hasn't answered.
For patients understandably worried about their implanted devices, Medtronic is clear that the incident had no impact on any device's ability to operate or deliver therapy. Its corporate IT systems are apparently segregated from the networks that actually run its products, and hospital customer networks are managed separately. So the breach was corporate, not clinical.
What Medtronic's carefully worded notification does not mention is ShinyHunters. The ransomware and extortion crew listed Medtronic on its dark web leak site shortly after the intrusion began, claiming to have lifted more than nine million records and threatening to publish them unless a ransom was paid by April 21. The listing quietly disappeared later that month without any data being released. ShinyHunters typically removes victims from its site after some form of agreement is reached. Draw your own conclusions.
Medtronic's notification makes no reference to any ransom demand, extortion attempt, or the identity of the attackers. The company has not publicly attributed the incident to anyone.
Several obvious questions remain unanswered. How many patients were affected? How did the attackers get in? And why has it taken more than two months to start telling people?
On the remediation side, Medtronic says it has tightened security, engaged law enforcement, and notified relevant regulators. Affected individuals are being offered two years of complimentary credit monitoring, dark web monitoring, and identity restoration services. The standard breach response package, essentially.