← BACK TO FEED
data breachMedtronicShinyHuntershealthcare securityransomware

ShinyHunters Breach Exposes Data of 3.8 Million Medtronic Patients

Medical technology company Medtronic suffered a data breach in April 2026 when the extortion group ShinyHunters accessed its corporate IT systems, compromising the personal and medical information of over 3.8 million individuals. Stolen data included names, contact details, dates of birth, Social Security numbers, and health-related information, though Medtronic states there is no evidence the data was publicly exposed. The company is offering affected individuals 24 months of free credit monitoring and identity theft protection services, and has implemented additional cybersecurity safeguards.

Medtronic is in the process of notifying nearly 3.84 million people that their personal and medical data was stolen in an April 2026 breach carried out by ShinyHunters, the prolific extortion crew responsible for a string of high-profile attacks.

The group claimed to have lifted over 9 million records along with terabytes of corporate data, posting Medtronic to its Tor-hosted leak site on April 17. Medtronic confirmed the intrusion shortly after, stressing that its medical devices, manufacturing lines, and distribution operations were untouched. Small mercies.

More telling is what happened next. ShinyHunters has since quietly removed Medtronic from the leak site. That kind of disappearing act rarely happens out of goodwill. It typically means someone paid up, though Medtronic has not confirmed or denied whether any ransom changed hands.

The stolen data is about as sensitive as it gets: names, addresses, dates of birth, Social Security numbers, and health-related information. According to the notification letter Medtronic filed with the California Attorney General's Office, the company says it has no evidence the data was publicly posted or exposed online. Whether that reassurance holds long-term depends entirely on the honesty of a criminal extortion gang, which is not a position any company wants to be in.

The figure submitted to Indiana's Attorney General puts the affected count at precisely 3,834,294 individuals.

Medtronic is offering two years of free credit monitoring, dark web monitoring, and identity theft restoration services to those caught up in the breach. The company says it has brought in third-party cybersecurity specialists, is cooperating with law enforcement, and has begun notifying relevant regulators.

Standard post-breach playbook, in other words. Whether any of the promised 'additional safeguards' amount to meaningful change, or just better PR, remains to be seen.

READ NEXT
Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April BreachNichirei Cyberattack Leaves Japan's Frozen Food Chain on IceSmall US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.