Another serious cybersecurity incident highlights the risks facing large healthcare companies. Medtronic, one of the world's leading manufacturers of medical devices, is informing its customers that personal data may have been exposed following a breach of its information systems.

The company had already announced in April that it had detected suspicious activity on its corporate network , immediately launching an investigation with the assistance of specialized cybersecurity companies. Shortly afterwards, the notorious cybercriminal group ShinyHunters , known for large-scale attacks and extortion of organizations through the leakage of stolen data, claimed responsibility for the attack
Millions of files allegedly stolen
The attackers allegedly gained access to approximately 9 million records related to Medtronic, including personal customer information and internal company documents.
Medtronic says that suspicious activity was detected on April 15, 2026, while an internal investigation showed that the attackers maintained access to certain company systems from April 13 to April 19. During this time, the perpetrators gained unauthorized access to information related to some of the company's customers.
See also: DHS: HSIN breach – hackers targeted servers and SharePoint
Medtronic: What data may have been leaked
The company warns that the data that may have been exposed varies from case to case, but information that may have been obtained includes names, contact information, dates of birth, social security numbers, and health-related information.
This type of data is considered particularly sensitive, as it can be used for both financial fraud and social engineering attacks. Cybercriminals often exploit such information to create convincing phishing messages or attempt identity theft.
The ShinyHunters blackmail tactic
The ShinyHunters group is one of the most well-known cybercrime organizations, having been linked to attacks against large businesses and online services in recent years.

The group's usual practice is to steal large amounts of data and publish it on a special platform on the dark web if the victim refuses to pay a ransom. In the case of Medtronic, the perpetrators added the company to the blackmail list on April 18, demanding payment within a few days and threatening to publish approximately 9 million records.
However, the listing was later removed from the ShinyHunters website. While no further details have been released, Medtronic maintains that the stolen data was not made public online.
Devices remain secure
The company clarifies that the incident concerns exclusively the company's information systems and not the medical devices themselves used by patients and healthcare professionals.
See also: New data breach at Aflac – Attack on Japanese subsidiary
According to Medtronic, there is no indication that the operation of its products was affected or that there was a risk to patient safety. This assurance is considered particularly important, as the company operates in more than 150 countries, employs approximately 95,000 employees and has annual turnover exceeding $33 billion.
What should customers do?
Medtronic is calling on those affected by the incident to take advantage of its free credit monitoring and identity theft protection services for 24 months.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, cybersecurity experts recommend increased vigilance against suspicious emails, phone calls or messages that may use exposed personal information for fraud. Users are advised to closely monitor their banking and insurance transactions, activate two-factor authentication where available, and avoid sharing personal data without first verifying the sender's identity.
See also: Blackfield: Demands $2 million from Nidec after ransomware attack
The incident is yet another reminder that cyberattacks in the healthcare sector are constantly increasing, with personal and medical data now one of the most valuable targets for organized cybercriminal groups.
Source: www.bleepingcomputer.com
