Cybersecurity

Medtronic Initiates Notification Process for Individuals Affected by Cyberattack Incident
Medtronic issued a statement on Monday, beginning to notify individuals who may have been affected by a previous cyberattack. The company is offering 24 months of free credit monitoring, dark web monitoring, and identity theft recovery services, and has established a dedicated call center. Medtronic stated that there is currently no evidence that accessed data has been made public or leaked, and no impact on product safety, patient safety, or manufacturing operations has been identified.

iRhythm discloses data theft from third-party applications in cyberattack
iRhythm disclosed in a securities filing that it discovered a cyberattack on June 8 and the next day received a ransom message from a threat actor claiming to have stolen sensitive data, including proprietary data, patient protected health information, and other personal information. The company confirmed that some data was exfiltrated from third-party hosted business applications but stated that the incident did not affect clinical or medical device systems, nor did it impact manufacturing and distribution capabilities.

Stryker cyberattack has 'material' impact on first-quarter results
Stryker's first-quarter sales growth was only 2.6%, well below prior-year levels, due to a March cyberattack that disrupted orders, shipping, and manufacturing for several weeks. The CEO called the impact 'material,' but the company maintained its full-year organic growth guidance of 8%-9.5%, and analysts generally view its long-term prospects favorably.

Medtronic Discloses Unauthorized Access to Corporate IT Systems
Medtronic filed an 8-K with the U.S. Securities and Exchange Commission on Friday (April 27, 2026), disclosing unauthorized access to its corporate IT systems. The company emphasized that its products, manufacturing, distribution, and customer networks are separate and unaffected, with no risk to patient safety. The incident has triggered an emergency response, and the company is assessing the risk of personal information exposure, expecting no material financial impact.