INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

iRhythm Notifies Individuals Affected by June 2026 Hacking Incident

| 2026-10-09 10:44 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
iRhythm Holdings Inc., a publicly traded heart monitoring device manufacturer, has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident that was first identified on June 8, 2026. The company confirmed that unauthorized access to certain business applications hosted on a third-party platform had occurred, resulting in the exfiltration of sensitive data, including personal and protected health information from approximately 360,000 individuals in Texas and South Carolina alone, as well as hundreds of thousands more nationwide. iRhythm activated its cybersecurity incident response plan and launched an investigation to determine the nature and scope of the unauthorized activity, which was later confirmed by a threat actor who claimed to have exfiltrated proprietary data and patient information from its applications; however, at no point was there any impact on products or clinical systems, customer connections, or patient safety.
Technical Mitigations AI-generated
• Patch third-party hosted business applications to prevent social engineering attacks. • Implement multi-factor authentication for access to sensitive data and applications. • Regularly review and update software versions, including the Zio wearable ECG monitor, to ensure compatibility with patched systems.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE healthhealth financefinance manufacturingmanufacturing technologytechnology
Incident Timeline
‎February 2026
Threat actors exfiltrated around 50 terabytes of data from Stryker in March, following similar incidents at UFP Technologies and Medtronic.
tactic Exfiltration
organisation UFP Technologies
organisation Stryker
organisation Medtronic
data_breach 50 terabytes
data_breach 9 patient records
‎June 8, 2026
IRhythm Holdings Inc. disclosed a cybersecurity incident to the U.S. Securities and Exchange Commission on June 8, 2026.
industry Health
industry Technology
industry Finance
industry Manufacturing
organisation Data Breach
organisation iRhythm Holdings Inc.
organisation the U.S. Securities and Exchange Commission
organisation SEC
‎June 9, 2026
Threat actors gained access to iRhythm's third-party hosted business applications through social engineering, exfiltrating sensitive data including personal and protected health information.
industry Health
industry Technology
industry Finance
industry Manufacturing
organisation CA
organisation Scope of the Breach
organisation Data Affected The
organisation Unaffected Systems
organisation Financial and Reputational Disclosure The
‎June 2026
IRhythm has started issuing notification letters to individuals affected by a June 2026 hacking and data theft incident.
organisation Hacking Incident Posted
organisation iRhythm
organisation Zio
organisation ECG
organisation iRhythm Notifies Individuals Affected
organisation the HHS’ Office for Civil Rights
‎June 18, 2026
IRhythm notified individuals affected by a June 2026 hacking incident, which involved multiple sectors including health, technology, finance, and manufacturing.
industry Health
industry Technology
industry Finance
industry Manufacturing
‎Oct 9, 2026
IRhythm has issued notification letters to individuals affected by a June 2026 hacking incident involving its wearable cardiac monitoring devices.
industry Health
industry Technology
industry Finance
industry Manufacturing
organisation Hacking Incident Posted
organisation iRhythm
organisation Zio
organisation ECG
Tactical Metrics
Metrics
data_breach
50
Terabytes
Metrics
data_breach
9,000,000
Patient Records
Intelligence Sources