iRhythm (Nasdaq:IRTC) today disclosed that it identified unauthorized activity involving data maintained on certain third-party-hosted business applications.
The long-term cardiac monitor maker said in an SEC filing that it identified the unauthorized activity on June 8. It promptly activated its cybersecurity response plan and launched an investigation. The investigation included support from external advisors and cybersecurity experts to assess and contain the threat.
On June 9, iRhythm received communications from a threat actor claiming to have obtained “sensitive information.” That included proprietary data, patient protected health information and other personal information. The threat actor demanded payment in exchange for not publicly disclosing the information.
iRhythm said that, after receiving contact from the actor, it confirmed that certain data was exfiltrated from those applications. On June 10, the company said it determined that the incident is material in light of the volume of potentially affected data.
To date, the company has not identified any impact on products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems or its ability to meet patient needs. It says the data was obtained through social engineering and is from certain third-party-hosted business applications.
The incident does not involve iRhythm’s clinical or medical device systems or connections to customers. It said it does not store or retain individual financial account information or payment card information.
As of today’s filing, iRhythm reports no evidence of ongoing unauthorized access to its systems. It continues to investigate the nature and scope of the incident. The company believes, as of today, that the incident remains not reasonably likely to have a material impact on its financial condition or results of operations. It maintains cybersecurity insurance that may cover certain losses, with no assurances that such coverage can cover all losses.
iRhythm becomes the latest medtech company hit by cyber attack
This isn’t the first cybersecurity issue in medtech of late. In March, Iranian-backed “hacktivist” group managed a “wiper attack” against Stryker, targeting data on Stryker’s Microsoft-based IT system and effectively wiping it out so it can’t be retrieved. The group said it undertook the cyberattack in response to U.S. and Israeli attacks on Iran, beginning on Feb. 28, 2026.
Days later, Intuitive Surgical said an unauthorized third party accessed certain internal IT business applications in a cybersecurity incident. The surgical robotics leader said the breach came as a result of a cybersecurity phishing incident.
In April, Medtronic issued a statement saying that it determined that an unauthorized party accessed data in certain corporate IT systems. Upon identifying the access, Medtronic said it took immediate steps to contain the incident.
There is no indication at this time that the breaches across the large medtech firms are related or were executed for similar reasons.
