ShinyHunters Breach Exposes Data of 3.8 Million Medtronic Patients
Medtronic is in the process of notifying nearly 3.84 million people that their personal and medical data was stolen in an April 2026 breach carried out by ShinyHunters, the prolific extortion crew responsible for a string of high-profile attacks.
The group claimed to have lifted over 9 million records along with terabytes of corporate data, posting Medtronic to its Tor-hosted leak site on April 17. Medtronic confirmed the intrusion shortly after, stressing that its medical devices, manufacturing lines, and distribution operations were untouched. Small mercies.
More telling is what happened next. ShinyHunters has since quietly removed Medtronic from the leak site. That kind of disappearing act rarely happens out of goodwill. It typically means someone paid up, though Medtronic has not confirmed or denied whether any ransom changed hands.
The stolen data is about as sensitive as it gets: names, addresses, dates of birth, Social Security numbers, and health-related information. According to the notification letter Medtronic filed with the California Attorney General's Office, the company says it has no evidence the data was publicly posted or exposed online. Whether that reassurance holds long-term depends entirely on the honesty of a criminal extortion gang, which is not a position any company wants to be in.
The figure submitted to Indiana's Attorney General puts the affected count at precisely 3,834,294 individuals.
Medtronic is offering two years of free credit monitoring, dark web monitoring, and identity theft restoration services to those caught up in the breach. The company says it has brought in third-party cybersecurity specialists, is cooperating with law enforcement, and has begun notifying relevant regulators.
Standard post-breach playbook, in other words. Whether any of the promised 'additional safeguards' amount to meaningful change, or just better PR, remains to be seen.