Medtronic, the world's largest medical device manufacturer, has begun notifying 3,834,294 people that their personal and health information was exposed in an April 2026 intrusion into its corporate IT systems, an attack the company attributes to the extortion group ShinyHunters. The figure comes from Medtronic's own filing with the Indiana Attorney General's Office, as reported by Hexnode citing SecurityWeek, and matches the count carried in Breached.Company's tally. The unusual part is not the scale but the ending: ShinyHunters listed Medtronic on its Tor leak site claiming more than nine million records, set a ransom deadline, and then the listing simply disappeared with no data ever published. Every source in this set is secondary reporting or sector advisory material; Medtronic's own notification letter and SEC filing are quoted through those outlets rather than read directly here, and the company has never publicly named ShinyHunters in its own statements.
What Happened
The reconstructed timeline is broadly consistent across reporting, with one date in dispute. Medtronic detected unusual activity on its corporate IT environment on April 15, 2026, and a subsequent investigation placed the unauthorized access window at April 13 through April 19, roughly six days, according to InfoSources' reconstruction of Medtronic's public statements and the notification letter.
Mid-way through that window, ShinyHunters added Medtronic to its dark web leak site, claiming theft of more than nine million records of personal data plus terabytes of internal corporate files, and threatening publication unless a ransom was paid by April 21. Sources differ on the listing date: Breached.Company, InfoSources, and National Cyber Security (republishing HealthInfoSec reporting sourced to BleepingComputer) all put it at April 18, while Hexnode, citing SecurityWeek, says April 17. The one-day discrepancy does not change the picture, but it is worth noting that no source in this set resolves it.
Medtronic filed with the U.S. Securities and Exchange Commission on Friday, April 24, saying criminals had broken into its corporate IT systems but that it had identified no impact to patient safety, to its products, manufacturing or distribution operations, or to its electronic connections with customers. The company also told the SEC the incident was not expected to cause a material decrease in earnings. For context on the size of the target, National Cyber Security notes Medtronic operates in 150 countries, serves 79 million people annually, and reported $33.5 billion in revenue in fiscal 2025.
The ShinyHunters listing came down later in April without any data being posted. InfoSources characterises this as consistent with the group's established pattern of pulling entries once a payment arrangement is reached, but is explicit that Medtronic has not confirmed whether any payment was made. That is an inference, not a confirmed fact, and it should be read as one.
Individual notification letters did not go out until July 5, roughly two and a half months after the intrusion. The fuller picture became public on June 29, when the California Attorney General's office released a copy of the letter.
What Was Taken
The notification letters describe the exposed data as names, contact information, dates of birth, Social Security numbers, and health-related information. That is a high-value combination: identity-grade identifiers paired with medical context, the sort of dataset that supports long-tail identity fraud, targeted insurance and medical billing scams, and highly credible phishing against patients who may not understand why a device manufacturer holds their data at all.
On volume, the numbers diverge sharply depending on who is counting. Medtronic told the Indiana Attorney General that 3,834,294 individuals were affected, reported as "more than 3.8 million" by Hexnode via SecurityWeek and as 3.83 million by InfoSources. ShinyHunters claimed more than nine million records plus terabytes of internal corporate data. Kodo Systems and GEPLAC both build their coverage around the nine million figure, though both are clear it is the attacker's claim. These are not necessarily contradictory counts: a records total and an individuals-notified total measure different things, and attacker-claimed volumes are routinely inflated for leverage. But nothing in these sources reconciles the gap, and defenders should treat 3,834,294 as the only figure with a regulatory filing behind it and nine million as an unverified extortion claim.
Medtronic says it has found no evidence the stolen information has been publicly released or exposed online. InfoSources highlights what the letter does not say: it makes no mention of ShinyHunters, of the extortion demand, or of the leak-site listing at all. The company's own account and the criminal group's account have never been connected in a Medtronic document.
Why It Matters
The cleanest lesson here is the one Hexnode draws: operational resilience is not cyber resilience. Medtronic's segmentation worked exactly as designed. Products kept working, manufacturing kept running, distribution was untouched, patient safety was not implicated. And 3.8 million people still had their Social Security numbers and health data taken, because that data lives in corporate IT, identity infrastructure, HR systems and CRM platforms, not on the production network. GEPLAC makes a related point: segregation is sound in theory but frays at the edges, and a corporate-side compromise still raises hard questions about credential hygiene, access controls and response tempo.
The second issue is disclosure. Medtronic had an SEC filing out within about nine days of detection but took until July 5 to notify the individuals whose Social Security numbers were taken, with the letter's contents surfacing publicly through the California AG on June 29. For the affected person, the clock on credit monitoring and fraud watch started roughly eleven weeks late.
Third, this is not an isolated event in medtech. National Cyber Security notes the Medtronic hack was at least the fourth cyber incident disclosed in a short span involving a large US-based medical technology manufacturer, including a March 11 wiper attack on Stryker claimed by the Iranian-linked hacktivist group Handala. Breached.Company, citing TechWalrus, notes Health-ISAC has named Medtronic among ShinyHunters victims alongside iRhythm, One Medical, DentaQuest, AdaptHealth and Hims and Hers. The same actor is working the healthcare sector methodically.
Finally, the vanished listing. Absence of a leak is not absence of exposure. The data was taken, it sits somewhere, and the most benign explanation for a quiet delisting is one nobody wants to say out loud.
The Attack Technique
None of these sources state how ShinyHunters got into Medtronic specifically. What is documented is the group's prevailing tradecraft against the health sector during the same period, and it is worth treating as the working hypothesis rather than as confirmed attribution of this intrusion's initial access.
Health-ISAC issued an urgent threat alert on the group's vishing operations, describing voice phishing campaigns that trick enterprise staff into entering credentials on medical-themed impersonation domains, then bypass MFA to pivot from single sign-on platforms into connected SaaS applications for large-scale exfiltration and extortion. The alert flags a distinctive naming convention: domains registered as company-claims[.]com or company[.]claims impersonating the target. Operators are reaching employees directly on personal mobile devices via calls and voicemails, and emailing users en masse from multiple random accounts.
The AHA-published Health-ISAC report on the August 22, 2026 ReliaQuest incident shows the playbook end to end, and shows where it breaks. The actor registered a typosquatted domain behind a CDN mirroring the corporate SSO portal, posed as a named internal security staff member, and called several employees with an urgency pretext. One employee entered credentials and approved an MFA push. That got the attacker an authenticated session limited to the identity provider dashboard, where they could see only the top-level application tiles. Because the session originated from an unmanaged external device, device-trust controls blocked lateral movement, and the attacker could not establish persistence or alter account configuration before automated detection engaged. Net result: zero unauthorized access to internal applications, enterprise systems, customer environments or telemetry.
That contrast is the actionable part. Same actor, same technique, one victim notifying millions and one victim with a contained incident and a clean after-action report. The difference was not the phishing filter. It was what happened after the credential was already lost.
What Organizations Should Do
- Enforce device trust at the identity provider, not just MFA. The ReliaQuest containment turned entirely on the session originating from an unmanaged device. Require managed, attested devices for IdP and SaaS access so a harvested credential plus an approved push still yields nothing.
- Move off push-approval MFA for privileged and IdP access. These campaigns are built around MFA fatigue and push approval. Phishing-resistant factors (FIDO2 or passkeys) break the attack at the point where vishing currently succeeds.
- Hunt for the documented domain pattern now. Health-ISAC calls out
company-claims[.]comandcompany[.]claimsimpersonation domains. Run brand-monitoring and certificate-transparency searches against your own name in that format, and pre-block newly registered lookalikes. - Brief staff on the specific pretext, not generic phishing. The lure is a phone call or voicemail to a personal mobile from someone claiming to be a named internal security employee, driving urgency toward a login page. Give people a hard rule: no credentials after an inbound call, ever, and a no-blame channel to report it.
- Treat corporate IT as in-scope for regulated data. Segmentation protected Medtronic's products and protected nothing else. Inventory where SSNs, dates of birth and health data actually live outside production, and apply production-grade controls, logging and access review there.
- Pre-build the notification path. Ten weeks between intrusion and individual notification is a regulatory and reputational exposure of its own. Have counsel, the data-mapping and the letter-generation pipeline ready before you need them.
- Do not read a deleted leak listing as resolution. Assume exfiltrated data remains in circulation regardless of whether it is published, and plan credit monitoring, fraud watch and executive-targeting defenses accordingly.
Sources: Medtronic Breach: 3.8M Notified, ShinyHunters Listing Gone Breache... | Medtronic Data Breach: 3.8 Million Affected After ShinyHunters Attack | What Medtronic's Own Notice Leaves Unsaid: A Breach, an Extortion C... | Medical Device Maker Medtronic Says It's Been Hacked #hacker - Nat... | Medtronic Breach Explained: 9 Million Records Stolen? What We Know... | Medtronic's Massive Data Breach: 9 Million Records at Risk (2026) | Cyber Incidents TLP WHITE: ShinyHunters-Linked Social Engineering a... | Urgent Threat Alert: ShinyHunters Vishing Campaigns and Domain Impe...