TL;DR: Medtronic, the $107 billion medical device manufacturer that makes pacemakers, insulin pumps, and surgical robots used in hospitals worldwide, confirmed on April 24 that an unauthorized party accessed its corporate IT systems. The ShinyHunters extortion group claimed the breach on April 17, saying they stole over 9 million records containing names, Social Security numbers, dates of birth, medical information, and government IDs. They gave Medtronic until April 21 to pay a ransom. Medtronic didn’t pay. The company insists patient devices and hospital networks weren’t compromised. But if ShinyHunters’ track record is any guide (and we’ve covered dozens of their operations this year) the stolen data is real, and it’s probably already being sold.
What Happened
On April 17, 2026, ShinyHunters posted Medtronic on their Tor-based leak site, claiming they’d broken into the company’s systems and grabbed more than 9 million records [1]. They threatened to publish everything if Medtronic didn’t negotiate by April 21.
Medtronic didn’t budge. A week later, on April 24, the company quietly posted a notice on its website confirming “an unauthorized party accessed data within certain Medtronic corporate IT systems” [2]. The same day, they filed an 8-K with the SEC, the kind of filing companies make when something is serious enough to affect investors [2].
By April 27, Medtronic’s listing had disappeared from ShinyHunters’ leak site. That could mean a lot of things. Payment. Private sale. Or the group simply moved on to their next target. It does not mean the data is safe.
What Was Stolen
ShinyHunters claimed the haul includes [1][3]:
- Names
- Social Security numbers
- Dates of birth
- Home addresses
- Government-issued IDs
- Medical information
- Financial information
- Terabytes of internal corporate data
Medtronic hasn’t confirmed what specific data was taken. Their official statement says they’re still “working to identify any personal information that may have been accessed” and will “provide notifications and support services as needed” [2]. That’s corporate for “we don’t know how bad this is yet.”
If those categories are accurate, 9 million people are now exposed to identity theft, medical fraud, insurance scams, and targeted phishing. SSN plus date of birth plus medical records is the identity theft trifecta.
Who’s at Risk
Medtronic employs over 95,000 people worldwide. But 9 million records is far beyond its employee base. That number likely includes:
- Current and former employees
- Healthcare providers and hospital contacts
- Business partners and contractors
- Possibly patients registered through Medtronic’s device monitoring platforms
Medtronic makes some of the most intimate medical devices on the planet: pacemakers, insulin pumps, spinal stimulators, surgical navigation systems. If patient data from device registrations or remote monitoring platforms was in those corporate systems, the exposure is far worse than a typical corporate breach.
Medtronic Says Devices Weren’t Hit. Here’s the Asterisk.
The company was emphatic that medical devices are safe. “This incident did not impact its products, patient safety, connections to our customers, our manufacturing and distribution operations, our financial reporting systems, or our ability to meet patient needs,” Medtronic stated [2].
They also stressed that “corporate IT network remains separate from the product, manufacturing, distribution, and hospital-customer networks” and that “hospital customer networks are secured and managed by customers’ IT teams” [2].
Medtronic’s MiniMed subsidiary, which makes insulin pumps, also confirmed its systems weren’t compromised [4].
That’s all good. But here’s the asterisk: network segmentation doesn’t protect the data that was already in the corporate systems. If those corporate databases contained patient registration data, device serial numbers, physician contacts, or health information from support interactions, it doesn’t matter that the pacemaker itself wasn’t hacked. The information about the patient was.
ShinyHunters: The Group Behind 30+ Breaches This Year
If you’ve been reading State of Surveillance, you know ShinyHunters. We’ve covered their attacks on ADT, Telus Digital, Infinite Campus, Carnival Corporation, Panera Bread, and dozens more. This group has been on an absolute tear in 2026.
Their playbook is well-documented at this point: breach a company through compromised SSO credentials, phishing, or supply chain attacks. Post the victim on their leak site. Set a short deadline, usually 3 to 5 days. If the company doesn’t pay, dump or sell the data.
The Medtronic attack follows a broader pattern of ShinyHunters targeting healthcare and critical infrastructure. In March, the group hit Hims & Hers telehealth. The medical technology company Stryker was also breached in March by Iran-aligned attackers, showing that medtech is increasingly in the crosshairs [5].
What You Should Do Right Now
If you’ve ever interacted with Medtronic (as a patient, employee, healthcare provider, or business partner) assume your data may be compromised. Here’s what to do:
- Freeze your credit with all three bureaus (Equifax, Experian, TransUnion). This is free and prevents anyone from opening new accounts in your name.
- Monitor your health insurance statements. Medical identity fraud is one of the hardest types to detect and fix. If you see claims for services you didn’t receive, report them immediately.
- Watch for targeted phishing. If attackers have your name, employer, and medical details, they can craft extremely convincing phishing emails pretending to be from your doctor, insurer, or Medtronic itself.
- Set up IRS identity protection. With SSNs exposed, file for an IRS Identity Protection PIN to prevent fraudulent tax returns.
- Enable multi-factor authentication on all healthcare-related accounts: patient portals, insurance logins, pharmacy accounts.
- Wait for Medtronic’s notification. The company said it will notify affected individuals and offer support services. Don’t wait for that letter to start protecting yourself.
The Medical Device Industry’s Security Problem
Medtronic is a $107 billion company. They make devices that keep people’s hearts beating. And ShinyHunters, a criminal group that’s been running a public extortion campaign for months, walked into their corporate network and took 9 million records.
This isn’t an isolated incident. The healthcare sector reported more data breaches than any other industry in 2025, and 2026 is tracking worse. The Department of Health and Human Services breach portal shows a steady drumbeat of hospital systems, insurers, and medical device companies losing patient data.
The FDA has pushed for stronger medical device cybersecurity requirements. Medtronic itself was hit by a different breach in 2023 involving its patient portal. The company clearly invested in network segmentation, separating corporate IT from device networks. That likely prevented a far worse outcome here. But segmentation doesn’t help if the corporate side is swimming in sensitive personal data that attackers can reach.
Until companies treat corporate databases holding PII with the same urgency as operational technology, breaches like this will keep happening. The pacemaker didn’t get hacked. The data about who has one did.
Sources
- Security Affairs: Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records
- Cyber Insider: Medical device giant Medtronic confirms data breach incident
- ClaimDepot: Medtronic Data Breach Exposes Millions of Records in 2026
- UnderCode News: Medtronic Cyberattack Confirmed: 9 Million Records Allegedly Stolen
- The Register: Medical, utility tech companies hit by intruders
Published: April 28, 2026