ShinyHunters Breach Hits Medtronic: 3.8 Million Patients' Medical Records Stolen

The extortion group ShinyHunters broke into the medical device maker's systems in April 2026, walking away with names, Social Security numbers, and sensitive health details belonging to nearly four million people.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A vast, dimly lit server room filled with towering racks of blinking blue and white lights
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • ShinyHunters broke into Medtronic's corporate systems in April 2026, stealing data on 3,834,294 individuals.
  • Stolen records include names, dates of birth, Social Security numbers, and health-related details.
  • ShinyHunters initially claimed theft of more than 9 million records before quietly removing Medtronic from its leak site, a common sign a ransom was paid.
  • Medtronic told California regulators it has "no evidence" the stolen data was posted publicly.
  • Affected individuals are being offered 24 months of free credit monitoring and identity theft support.

Medtronic, the Minnesota-based medical device maker, is notifying nearly 3.8 million people that criminals stole their personal and medical information in a breach that happened this past April.

The group responsible is ShinyHunters, a well-known extortion crew tracked by security vendors under that same name, with a history of large-scale data theft going back to at least 2020. Their model skips ransomware entirely: steal sensitive data, post it to a Tor-based leak site (a hidden network designed to mask identities), and threaten public release unless the victim pays. As we reported on 3 July, the group rifled through Medtronic's corporate systems for nearly a week before the company confirmed the intrusion.

On April 17, ShinyHunters listed Medtronic on that site, claiming more than nine million records and terabytes of internal data. The listing has since disappeared, which almost always means one thing.

Medtronic has not confirmed or denied paying. The company told the Indiana Attorney General's Office that exactly 3,834,294 people were affected. Stolen records include names, contact information, dates of birth, Social Security numbers, and health-related details, the combination that makes identity theft straightforward and medical fraud genuinely dangerous.

What should affected patients do right now?

Medtronic is mailing written notification letters and offering two years of free credit monitoring, dark web monitoring (services that watch for your personal information in criminal marketplaces), and identity theft restoration help. Accept that offer and enroll promptly; sign-up windows are typically limited.

Beyond that, consider placing a free credit freeze with all three major bureaus, which stops anyone from opening new credit accounts in your name. A freeze costs nothing and lifts any time you need it.

Medtronic says its medical devices and manufacturing operations were not affected. Your pacemaker or insulin pump is fine.

Should you worry about how they got in?

From an attribution standpoint, ShinyHunters' TTPs (tactics and procedures, meaning the specific methods the group habitually uses) overlap with prior large-scale database theft operations. Medium confidence only: the group has historically used stolen credentials obtained through phishing to access cloud-stored corporate databases. Whether that was the entry point here, Medtronic has not said. The company confirms it is working with law enforcement and outside cybersecurity experts to review its defences.

The quiet removal of Medtronic from the leak site is the detail worth watching. If a ransom was paid, that buys silence, not safety: ShinyHunters has no verified track record of deleting what it steals.

© 2026 Threat Vectr