Visualização de leitura

iRhythm Hit by Cyberattack, Patient Data Stolen and Ransom Demanded

iRhythm disclosed a cyberattack via third-party apps where patient and proprietary data was stolen, followed by a ransom demand.

iRhythm Technologies is a U.S.-based digital healthcare company specializing in remote cardiac monitoring and arrhythmia detection. Its best-known product is the Zio, a wearable patch that continuously records a patient’s heart rhythm for up to several weeks. The data is then analyzed using proprietary algorithms and reviewed by clinicians to help diagnose conditions such as Atrial Fibrillation and other heart rhythm disorders.

iRhythm disclosed a cyberattack in an SEC Form 8-K filed on June 10. Someone got into third-party-hosted business applications, grabbed data, and then asked to be paid to keep quiet about it.

“On June 8, 2026, iRhythm Holdings, Inc. identified unauthorized activity involving data maintained on certain third-party-hosted business applications.” reads the SEC Form 8-K report. “The Company promptly activated its cybersecurity response plan and launched an investigation with the support of external advisors and cybersecurity experts to assess and contain the threat.”

On June 9, 2026, iRhythm received an extortion demand from a threat actor claiming to have stolen proprietary data, protected health information, and other personal data. The company later confirmed the data breach from third-party-hosted business applications via a social engineering attack and deemed the incident material.

The digital healthcare firm stated that clinical and medical device systems, patient safety, operations, and customer connections were not affected, and no payment card or financial account data was involved.

The company did not reveal which specific application was compromised and did not disclose technical details about the attack.

“On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information.” continues the report. “The communications from the threat actor demanded payment in exchange for not publicly disclosing this information.”

The company is investigating the scope of the incident.

No ransomware group has publicly claimed the attack, and it’s not known whether iRhythm has engaged in negotiations with the attacker.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

Cardiac patients’ medical data stolen and held to ransom

Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt.

In a filing with the Securities and Exchange Commission (SEC), iRhythm revealed it was contacted by someone on June 9 who claimed to have stolen sensitive information, including proprietary data, patient PHI, and other personal information. That person demanded payment in exchange for not publishing the data.

iRhythm provides ambulatory cardiac monitoring and analysis (for example using the Zio patch) and has reportedly processed over two billion hours of heartbeat data from more than twelve million patients.

In the filing, the company said the data was obtained through social engineering and is from “certain third-party-hosted business applications”, without revealing any further details about the amount of data.

On its own website, iRhythm also doesn’t disclose much about the nature of the stolen data, but does seem to imply no financial data was affected:

“We have not identified any impact to our products, our clinical or medical device systems, our connections to customers, our manufacturing and distribution operations, patient safety, or our ability to meet patient needs. In addition, we do not store or retain individual financial account information or payment card information. 

 As we actively investigate, we will notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.“

However, the SEC filing adds that iRhythm determined that the incident is significant, “in light of the volume of the potentially affected data.” Together with the extortionist’s claims that they have patients’ medical data, that makes the breach one worth noting if you have used iRhythm’s services.

Even without payment data, healthcare breaches have serious downstream effects:

  • Attackers can craft highly convincing emails, texts, or calls that reference specific procedures or monitoring episodes (for example, “about your recent Zio patch recording”) to trick patients into sharing more data or paying fake bills.
  • The breached data can be used to create a fake identity, insurance fraud, or medical identity theft.
  • Exposure of cardiac and other health‑related information can be deeply sensitive and may have employment/insurance ramifications, especially if data is posted publicly or sold to data brokers.

Healthcare breach data tends to circulate for years, and victims may face sporadic fraud and phishing attempts long after the headlines fade.

How to stay safe

If you’ve used iRhythm’s services, keep an eye on your post, email, and patient portals for official breach notifications from iRhythm or your healthcare provider.

In the US, breaches of protected health information that meet certain criteria must be reported to patients and regulators. iRhythm has promised to “notify individuals affected by this incident in accordance with applicable law and take steps as needed to protect and remediate the impact to them.”

To stay out of the hands of phishers and scammers:

  • When you receive a communication about the data breach, verify through other channels that it really came from iRhythm. Go directly to iRhythm’s official website or patient portal, or call a known phone number to confirm the communication is genuine.
  • Be extra suspicious of emails or texts that claim to offer compensation, refunds, or other financial consequences related to this incident.
  • Change passwords for your iRhythm‑linked portals and your cardiology or hospital patient portals, especially if you reused those passwords elsewhere.
  • Log into your health insurer’s portal and check claims on a regular basis.
  • If you see anything suspicious, report it immediately to your insurer and provider and ask them to flag your account for possible identity theft.
  • Do not provide personal or financial information over the phone just because the caller knows details about you which they may have obtained from the stolen data.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

iRhythm Discloses Data Breach After Threat Actor Claims PHI Theft

iRhythm data breach

Cardiac monitoring company iRhythm Technologies has disclosed a cybersecurity incident involving unauthorized access to data stored within certain third-party-hosted business applications. The company revealed details of the iRhythm data breach in a recent SEC filing, stating that sensitive information, including protected health information (PHI), may have been accessed and exfiltrated by a threat actor.  According to the SEC filing, iRhythm identified suspicious activity on June 8 and immediately activated its cybersecurity response protocols. The company launched an investigation with assistance from external advisors and cybersecurity specialists to determine the scope of the incident and implement containment measures. 

Decoding the iRhythm Data Breach 

The company reported that on June 9, it received communications from a threat actor who claimed to have obtained "sensitive information" from the affected systems. According to iRhythm, the allegedly compromised data included proprietary company information, patient protected health information, and other forms of personal information.  The threat actor also demanded payment in exchange for withholding the information from public disclosure.  Following the communication, iRhythm conducted additional reviews and confirmed that certain data had indeed been exfiltrated from the impacted third-party-hosted applications. By June 10, the company determined that the incident was material due to the volume of potentially affected information.  The SEC filing noted that the company continues to investigate the full nature and scope of the iRhythm data breach. 

Company Says Core Operations Remain Unaffected 

Despite the seriousness of the incident, iRhythm stated that it has not identified any disruption to its products, patient services, or operational capabilities.  According to the SEC filing, the company has found no impact on: 
  • Products and services 
  • Clinical systems 
  • Medical device systems 
  • Patient safety 
  • Manufacturing operations 
  • Distribution activities 
  • Financial reporting systems 
  • The company's ability to continue serving patients 
iRhythm said the data breach at iRhythm stemmed from a social engineering attack targeting certain third-party-hosted business applications rather than its clinical infrastructure.  The company further emphasized that the incident did not affect its clinical or medical device systems, nor did it involve connections used by customers. Additionally, iRhythm stated that it does not store or retain individual financial account information or payment card information, reducing the likelihood that such data was compromised. 

Investigation Continues as Company Assesses Impact 

As of the latest SEC filing, iRhythm reported that it has found no evidence of ongoing unauthorized access within its systems.  The company stated that its investigation remains active and that it is continuing to evaluate the extent of the exposure and any potential consequences arising from the incident. At present, iRhythm believes the cybersecurity event is "not reasonably likely" to have a material effect on its financial condition or operating results.  The company also noted that it maintains cybersecurity insurance that could potentially offset certain losses related to the incident. However, iRhythm cautioned that there can be no assurance that insurance coverage would fully compensate for all losses associated with the breach. 
❌