Breaches · 70 days ago
The breach is still being measured, and the public number has narrowed to a confirmed minimum. Medtronic has started notifying 3.8 million people, while ShinyHunters has removed its 9 million-record claim, which leaves open whether the gap reflects a negotiated resolution or a count that is still being reconciled.
Medtronic says the stolen data includes names, contact details, dates of birth, Social Security numbers, and health-related details. The company also says its products and manufacturing and distribution operations were not affected, and it has told regulators it saw no evidence the information was posted publicly.
For customers, the exposure is in identity fraud and scam leverage, not in a product compromise. For responders tracking healthcare extortion, the removal of the leak-site listing is a reminder that public evidence can disappear before the final victim count is settled.
4 sources covering this story
The Record from Recorded Future
Major medical device manufacturer notifies nearly 4 million of breach
Information like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.”
Medtronic Data Breach Impacts 3.8 Million People
In April, ShinyHunters accessed the company’s corporate IT systems and stole patients’ personal and medical information.
Pacemaker manufacturer Medtronic warns patients cybercrooks may have swiped health data
Company that also makes insulin pumps and other devices tells users what was exposed months after ShinyHunters attack
Medtronic notifies customers impacted by ShinyHunters data breach
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party.
Part of the PlainSec briefing for 2026-07-04