Medtronic is notifying patients that their personal and health information may have been compromised in a cyberattack back in April.
The breach hit the medical device maker’s corporate network over nearly a week. Unauthorized access was detected on April 15, but the intruders had been in the system since April 13. They stayed until April 19.
What got taken? Names, contact details, dates of birth, Social Security numbers, and health information — data Medtronic collects for product updates and regulatory compliance. The company says there’s no evidence the data was publicly posted or exposed online. But it’s unclear if attackers exfiltrated copies.
Here’s the good news: the attack didn’t affect the functionality or safety of Medtronic’s medical devices. Manufacturing, distribution, and patient care weren’t impacted either.
The extortion group ShinyHunters claimed responsibility. They listed Medtronic on their dark web leak site, alleging theft of over nine million records. The listing was later removed. Medtronic hasn’t publicly attributed the attack or mentioned ransomware demands.
The company is offering affected individuals two years of credit monitoring and identity restoration services. They’ve also implemented additional security measures.
