Medical device maker iRhythm disclosed a cyberattack that exposed information belonging to at least 360,000 people. Attackers used social engineering to access third-party-hosted business applications between June 3 and June 8, 2026, and downloaded patient information, including identifying details, insurance numbers, account numbers, and device serial numbers. A threat actor demanded payment to prevent publication of allegedly stolen proprietary data, protected health information, and other personal information. iRhythm confirmed data exfiltration, but no hacking group has publicly claimed responsibility.
The company notified affected individuals and regulators, with a consumer notification letter published through South Carolina’s Department of Consumer Affairs on October 6. iRhythm reported no impact on clinical systems, medical devices, manufacturing, distribution, or service delivery, and said it had found no evidence of identity theft involving the stolen information. The incident underscores the exposure of sensitive healthcare data through third-party business applications even when clinical operations remain unaffected; security teams should review social-engineering defenses and access controls across those applications.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
After verifying the breach's scope, iRhythm notified affected individuals and applicable regulators, reporting 298,647 affected people in Texas and 69,526 in South Carolina. The company also filed notices in California but declined to provide the total number affected.
In a June Form 8-K filing, iRhythm disclosed the threat actor's communications and confirmed that data had been exfiltrated from affected applications. The company said the incident did not affect clinical systems, medical devices, or operations, including manufacturing and distribution.
A threat actor contacted iRhythm claiming to possess proprietary data, patient protected health information, and other personal information. The actor demanded payment in exchange for not publicly disclosing the information.
Attackers used social engineering to access third-party-hosted iRhythm business applications between June 3 and June 8 and downloaded patient information. The stolen data included identifying details, dates of service, patient account numbers, device serial numbers, and insurance numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.