INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
| 2026-10-09 10:44 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
iRhythm Holdings Inc., a publicly traded heart monitoring device manufacturer, has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident that was first identified on June 8, 2026. The company confirmed that unauthorized access to certain business applications hosted on a third-party platform had occurred, resulting in the exfiltration of sensitive data, including personal and protected health information from approximately 360,000 individuals in Texas and South Carolina alone, as well as hundreds of thousands more nationwide. iRhythm activated its cybersecurity incident response plan and launched an investigation to determine the nature and scope of the unauthorized activity, which was later confirmed by a threat actor who claimed to have exfiltrated proprietary data and patient information from its applications; however, at no point was there any impact on products or clinical systems, customer connections, or patient safety.
Technical Mitigations AI-generated
• Patch third-party hosted business applications to prevent social engineering attacks.
• Implement multi-factor authentication for access to sensitive data and applications.
• Regularly review and update software versions, including the Zio wearable ECG monitor, to ensure compatibility with patched systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
EUROPE
EUROPE
healthhealth
financefinance
manufacturingmanufacturing
technologytechnology
Incident Timeline
February 2026
Threat actors exfiltrated around 50 terabytes of data from Stryker in March, following similar incidents at UFP Technologies and Medtronic.
Click on any entity below to view its context and source!
tactic
Exfiltration
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
organisation
UFP Technologies
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
organisation
Stryker
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
organisation
Medtronic
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
data_breach
50 terabytes
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
data_breach
9 patient records
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
June 8, 2026
IRhythm Holdings Inc. disclosed a cybersecurity incident to the U.S. Securities and Exchange Commission on June 8, 2026.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Technology
General Document Context
industry
Finance
General Document Context
industry
Manufacturing
General Document Context
organisation
Data Breach
Heart Monitoring Device Manufacturer Discloses Cyberattack and Data Breach
iRhythm Holdings Inc., a publicly traded heart monitoring device manufacturer, has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident that was first identified on June 8, 2026.
organisation
iRhythm Holdings Inc.
Heart Monitoring Device Manufacturer Discloses Cyberattack and Data Breach
iRhythm Holdings Inc., a publicly traded heart monitoring device manufacturer, has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident that was first identified on June 8, 2026.
organisation
the U.S. Securities and Exchange Commission
Heart Monitoring Device Manufacturer Discloses Cyberattack and Data Breach
iRhythm Holdings Inc., a publicly traded heart monitoring device manufacturer, has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident that was first identified on June 8, 2026.
organisation
SEC
Heart Monitoring Device Manufacturer Discloses Cyberattack and Data Breach
iRhythm Holdings Inc., a publicly traded heart monitoring device manufacturer, has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident that was first identified on June 8, 2026.
June 9, 2026
Threat actors gained access to iRhythm's third-party hosted business applications through social engineering, exfiltrating sensitive data including personal and protected health information.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Technology
General Document Context
industry
Finance
General Document Context
industry
Manufacturing
General Document Context
organisation
CA
Company Background
San Francisco, CA-based iRhythm makes cardiac monitoring devices that are used by approximately 8 million patients in the United States and Europe, and cloud-based data analytics for diagnosing and tracking patients with heart arrhythmias.
organisation
Scope of the Breach
Scope of the Breach and Data Affected
The internal investigation confirmed that the threat actor had exfiltrated sensitive data, including personal and protected health information.
organisation
Data Affected
The
Scope of the Breach and Data Affected
The internal investigation confirmed that the threat actor had exfiltrated sensitive data, including personal and protected health information.
organisation
Unaffected Systems
Confirmed and Unaffected Systems
iRhythm has not identified any impact on its products, clinical or medical device systems, patient safety, manufacturing, distribution operations, financial reporting systems, or its ability to meet patient needs as a result of the incident.
organisation
Financial and Reputational Disclosure
The
Financial and Reputational Disclosure
The SEC filing does not state whether payment was made to the attacker or if the company is negotiating payment.
June 2026
IRhythm has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident.
Click on any entity below to view its context and source!
organisation
Hacking Incident
Posted
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
iRhythm
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
Zio
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
ECG
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
iRhythm Notifies Individuals Affected
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident.
organisation
the HHS’ Office for Civil Rights
Regulators have been notified about the incident, although it is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected in total; however, it is clear that the incident has affected hundreds of thousands of individuals, including more than 360,000 individuals in Texas and South Carolina alone.
June 18, 2026
IRhythm notified individuals affected by a June 2026 hacking incident, which involved multiple sectors including health, technology, finance, and manufacturing.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Technology
General Document Context
industry
Finance
General Document Context
industry
Manufacturing
General Document Context
Oct 9, 2026
IRhythm has issued notification letters to individuals affected by a June 2026 hacking incident involving its wearable cardiac monitoring devices.
Click on any entity below to view its context and source!
industry
Health
General Document Context
industry
Technology
General Document Context
industry
Finance
General Document Context
industry
Manufacturing
General Document Context
organisation
Hacking Incident
Posted
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
iRhythm
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
Zio
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
organisation
ECG
iRhythm Notifies Individuals Affected by June 2026 Hacking Incident
Posted By
Steve Alder
on Oct 9, 2026
iRhythm, a health technology company that specializes in wearable cardiac monitoring devices such as the Zio wearable ECG monitor, has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident, as reported below.
Tactical Metrics
Metrics
data_breach
50
Terabytes
Click for context!
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
Metrics
data_breach
9,000,000
Patient Records
…ector Incidents
Several cyberattacks have recently been reported by medical device manufacturers, including UFP Technologies in February 2026, which involved either the theft or destruction of company data; Stryker, which involved the exfiltration of around 50 terabytes of data in March; and Medtronic experienced a major data theft incident in March, involving around 9 million patient records.
Intelligence Sources
HIPAA Journal
2026-10-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:19
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
CA
entity
6x
timeline
Temporal Reference
Oct 9, 2026
date
4x
industry
Targeted Sector
Health
sector
3x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
6 METRICS
target region
Target Country
United States
country
target region
Target Region
EUROPE
region
general metric
Patients
8,000,000
patients
data breach
Terabytes
50
terabytes
data breach
Patient Records
9,000,000
patient records
general metric
Individuals
360,000
individuals
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.