Medtronic Initiates Notification Process for Individuals Affected by Cyberattack Incident
Medtronic issued a statement on Monday, beginning to notify individuals who may have been affected by a previous cyberattack. The company is offering 24 months of free credit monitoring, dark web monitoring, and identity theft recovery services, and has established a dedicated call center. Medtronic stated that there is currently no evidence that accessed data has been made public or leaked, and no impact on product safety, patient safety, or manufacturing operations has been identified.

Medtronic has begun notifying individuals potentially affected by the cyberattack disclosed two months ago. The company posted a statement on its website this Monday, providing an update on the incident.
According to the statement, Medtronic currently has no evidence that the accessed data has been made public or leaked on the internet. The company will offer affected individuals 24 months of free credit monitoring, dark web monitoring, and identity theft recovery services, and has set up a dedicated call center to address related questions.
Medtronic stated in the announcement: "We have not identified any impact on product safety or patient safety, including the ability of any Medtronic device to operate safely and deliver its intended therapy. Additionally, we have not identified any impact on manufacturing and distribution operations, or on our ability to meet patient and customer needs."
In April, Medtronic disclosed that an unauthorized third party had accessed data stored in some of its corporate IT systems, but did not specify the types of data accessed. At that time, Medtronic stated in a filing with the U.S. Securities and Exchange Commission (SEC) that it expected the incident would not have a material impact on its business or financial results.
Multiple cyberattacks this year
Medtronic is one of many medical device companies that have suffered cyberattacks this year.
Stryker disclosed a cyberattack in March that disrupted its manufacturing and shipping operations for several weeks. Stryker CEO Kevin Lobo told investors on a May earnings call that the cyberattack "had a significant impact on our results, with varying impacts across our business segments due to their different go-to-market models and revenue recognition processes." Stryker did not disclose the specific financial loss from the first quarter, but despite the impact, the company maintained its full-year outlook.
In the same week as the Stryker attack, Intuitive Surgical reported a phishing incident that led to the exposure of customer and employee data. In a June update, the surgical robotics company said the incident had not resulted in any reports of fraud or identity theft, and there was no indication that the accessed data had been misused.
Additionally, iRhythm said last month that some data in its third-party hosted business applications had been stolen. The cardiac monitoring device maker received a message from a threat actor claiming to have stolen sensitive information, including proprietary data, patient protected health information, and other personal information. According to the SEC filing, the threat actor demanded payment in exchange for not publicly disclosing the information. The company has not yet posted an update about the attack on its website.