All Breaches
June 8, 2026 Verified Sensitive Record Medical Technology

iRhythm 2026 Data Breach

The iRhythm 2026 data breach is an incident in which the cardiac-monitoring technology company reported to the U.S. Securities and Exchange Commission that data had been exfiltrated from certain third-party-hosted business applications. iRhythm identified the attack on June 8, 2026, activated its incident-response plan, and the next day received a message from a threat actor claiming theft and demanding payment. The company subsequently confirmed that certain data was in fact taken from the applications.

The Form 8-K filed on June 15 is the primary source. iRhythm's own cybersecurity statement and MedTech Dive's review corroborate that the event did not affect clinical or medical-device systems, products, customer connections, manufacturing and distribution, or patient safety. Because the company was still investigating the data categories and affected individuals, LeakData records the person count as unknown.

Confirmed Data Scope

The core scope confirmed by the company is that “certain data” was exfiltrated from specified third-party-hosted business applications. iRhythm did not name those applications, quantify the files, or enumerate the fields present in each record. The data class is therefore limited to the broad category of third-party business-application data, without inferring undisclosed names, email addresses, identifiers, or medical fields.

iRhythm stated that it does not store or retain individual financial-account or payment-card information. Clinical systems, medical-device systems, and connections to customers were outside the incident. Credit cards, bank accounts, device telemetry, and clinical-system data are not listed as compromised classes. The company said it would notify affected individuals as required by applicable law.

Attacker Claims and Evidentiary Limit

The threat actor claimed to have stolen proprietary company data, patient protected health information, and other personal information, and demanded payment in return for not publishing it. iRhythm confirmed exfiltration from the applications but did not separately validate the categories named by the actor. LeakData describes those allegations as context and does not present PHI, personal information, or proprietary data as settled data classes.

An actor's list of categories cannot by itself prove the contents or freshness of an archive. The company's continuing investigation was still determining categories, volume, and affected individuals. pwnCount, totalRecords, and dataClasses are consequently not derived from the actor's statement. Verified fields can be added later if individual notices or a regulatory update provides stronger evidence.

Incident Timeline

iRhythm identified the event on June 8, 2026 and activated its cybersecurity response plan. On June 9 the threat actor sent a message alleging theft of sensitive data and demanding payment. The company then confirmed that certain data had been exfiltrated from third-party applications, and filed the Form 8-K on June 15. The June 8 date in LeakData represents the verified detection day.

The exact initial-access date, duration, transfer time, and affected third-party applications were not publicly disclosed. As of June 15, the company had not identified evidence of continuing unauthorized access. That does not mean no earlier access occurred; it describes the observation at the filing date. The timeline avoids turning undisclosed details into certainty.

Attack Method and System Separation

The SEC filing says the data was obtained through social engineering and came from third-party-hosted business applications. iRhythm did not identify the person or organization deceived, how a session or credential was compromised, or the communication channel used. The event is not classified as a software vulnerability across the entire company network or as an attack on medical devices.

Confirmation that clinical and device systems were not involved is an important patient-safety boundary. iRhythm found no impact to products, manufacturing or distribution, financial-reporting systems, or its ability to meet patient needs. Theft of business-application data nevertheless creates privacy and extortion risk; operational continuity and data confidentiality are different measures.

iRhythm's Response and User Actions

iRhythm activated its incident-response plan, opened an investigation with cybersecurity specialists and external advisers, and looked for evidence of continuing access. It did not say whether it paid the demand. In its website statement, the company said it would notify affected individuals under applicable law and take steps to protect and remediate impacts. Undisclosed payment or technical measures are not added to this record.

Recipients of a notice should act according to the actual fields listed and independently verify unexpected health-information checks, invoices, portal logins, or payment requests sent in iRhythm's name. Password reuse is generally risky, although the company did not confirm password theft. The absence of stored financial-account and payment-card data does not remove possible phishing or privacy risks.

How to Interpret This LeakData Record

The zero-person value does not mean nobody was affected; it means iRhythm has not published a verified total. The company's patient population, device users, and customer organizations are not breach scope. The data class represents the confirmed third-party business-application data and does not convert the actor's PHI and personal-information allegations into established fields.

The verified conclusion is that social engineering resulted in exfiltration of certain data from iRhythm's third-party-hosted business applications and that the actor demanded payment not to publish it. Clinical and medical-device systems were unaffected and no continuing access was identified, while the categories, volume, and person count remained open. LeakData documents the real breach within those evidentiary limits.

0
Affected Accounts
1
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

1
Third-party-hosted business application data

Additional Information

Added DateJuly 26, 2026
Breach DateJune 8, 2026
Domainirhythmtech.com
SourceSocial engineering
Last Content UpdateJuly 26, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information