Medtronic disclosed in an 8-K filing and official statement submitted to the U.S. Securities and Exchange Commission (SEC) on Friday (April 27, 2026) that an unauthorized third party accessed data in some of its corporate IT systems.

The company stated that it has not yet found any impact from the incident on products, customer connectivity, manufacturing, and distribution operations, nor any impact on patient safety or the company's ability to meet patient needs.

Medtronic emphasized in its statement: "The networks supporting corporate IT systems, products, and manufacturing and distribution operations are separated. Hospital customer networks remain independent from Medtronic's IT network and are secured and managed by customers' own IT teams."

The company is working to confirm whether any personal information may have been accessed. According to the filing submitted to the SEC, Medtronic currently expects that the incident will not have a material impact on its business or financial results.

Upon discovering the cybersecurity breach, Medtronic immediately took measures to contain the situation, activated its incident response protocol, and engaged cybersecurity experts to assist with the investigation and remediation efforts.

This data breach is the latest cybersecurity incident in the medical device industry. In March, Stryker's Microsoft environment suffered a cyberattack that disrupted its order, shipping, and manufacturing systems, and operations took several weeks to return to normal.

In the same week as the cyberattack on Stryker, Intuitive Surgical reported a phishing incident. The company stated that an unauthorized third party accessed information including customer business and contact information as well as employee and corporate data. The surgical robotics company said during its earnings call in the most recent week that the incident has been contained and did not have a material impact on its first-quarter financial results.