Medtronic tells customers their personal data was stolen in ShinyHunters raid

The medical device giant confirms hackers rifled through its corporate systems for nearly a week in April, exposing names, Social Security numbers and health details.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration for the story: Medtronic tells customers their personal data was stolen in ShinyHunters raid
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Medtronic says an unauthorised intruder was inside its corporate IT systems from April 13 to April 19, 2026.
  • The extortion crew ShinyHunters claimed to hold 9 million Medtronic records and demanded payment by April 21.
  • Stolen data may include names, contact details, dates of birth and Social Security numbers, along with health information.
  • Medtronic insists its medical devices are unaffected and safe to use.
  • Affected customers are being offered 24 months of free credit monitoring and identity theft protection.

Medtronic, one of the world's biggest makers of pacemakers and surgical kit, has started writing to customers to tell them their personal information was stolen in a data breach earlier this year.

The company first spotted something odd on April 15, 2026, and called in outside cybersecurity investigators. Those investigators determined an intruder had been quietly rummaging through Medtronic's corporate IT systems for almost a week, from April 13 to April 19. What they took is the sort of data identity thieves love: full names, contact details, dates of birth, Social Security numbers, health-related information.

No one is claiming a pacemaker got hacked. Medtronic is clear that its medical devices were not touched and remain safe to use. The break-in was on the corporate side of the house, not the hospital equipment.

Who stole the data?

ShinyHunters claimed the attack. The group specialises in stealing large databases and demanding a ransom, a payment to keep the files from being dumped online. Threat Vectr has been following ShinyHunters since May 2026; in June we reported how the group rode an Oracle PeopleSoft zero-day into university networks before a patch even existed.

ShinyHunters listed Medtronic on its dark web leak site, a hidden page the group uses to name and shame victims, on April 18 and said it held more than 9 million records. It set a deadline of April 21 to pay up.

The listing quietly vanished later that month, as first reported by BleepingComputer. Medtronic will not say whether it paid, but tells customers the stolen data was not exposed online. Whether that means the ransom was settled, or the crooks simply moved on, is anyone's guess.

ShinyHunters is less a shadowy hacker collective than a repeat shoplifter with a very large getaway van. Its preferred tactic is scraping data from poorly secured cloud storage, then squeezing owners for cash.

Should you worry?

If you received a notification letter, yes, take it seriously. Medtronic is offering 24 months of credit monitoring and identity theft protection, which watches for someone trying to open loans or accounts in your name. Sign up.

Be wary of calls or messages that seem to know a suspicious amount about you. That's social engineering, where scammers use real personal details to sound convincing before asking for money or passwords. Medtronic will not ring you out of the blue asking for your Social Security number.

Check your bank and health insurance statements more often than usual for the next year. Flag anything odd early.

For context on the scale: Medtronic operates in 150 countries, employs 95,000 people and reported annual revenue of $33.5 billion. A breach at a company that size, holding health data on millions of people, is not a footnote. It is exactly the kind of target ShinyHunters and its imitators will keep hunting until the economics change.

© 2026 Threat Vectr