Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Medtronic. Show all posts

Medtronic Alerts Customers After Data Breach Exposes Personal Information

 

Healthcare technology company Medtronic has started informing affected customers about a cybersecurity incident that resulted in unauthorized access to their personal information.

The company had earlier disclosed that its corporate IT infrastructure had been compromised by hackers. The cyber extortion group ShinyHunters later claimed responsibility for the attack, alleging it had obtained around 9 million records containing personally identifiable information (PII) and internal corporate data.

According to the notification shared by the company, “On April 15, 2026, Medtronic became aware of unusual activity on certain corporate IT systems.”

The notice further states, “Medtronic launched an investigation with the assistance of leading third-party cybersecurity experts to determine the impact and scope of the incident.”

Following the investigation, the company concluded that “The investigation determined that from April 13 to April 19, 2026, an unauthorized actor accessed certain Medtronic corporate IT systems.”

The information that may have been exposed includes:

  • Full name

  • Contact information

  • Date of birth

  • Social Security number

  • Health-related information

ShinyHunters is known for publishing stolen information when ransom demands are not met. The group reportedly added Medtronic to its dark web leak site on April 18, claiming it possessed more than 9 million records and warning that the data would be released if a ransom was not paid by April 21.

However, the listing disappeared from the group's portal later that month. In its customer notification, Medtronic clarified that the compromised data has not been made publicly available online.

Medtronic operates in over 150 countries and employs approximately 95,000 people, generating annual revenue of around $33.5 billion.

Despite the breach involving customer information, the company has reassured users that its medical devices continue to operate safely and were not impacted by the cybersecurity incident.

Customers receiving breach notifications are being encouraged to enroll in the company's complimentary 24-month credit monitoring and identity theft protection program to reduce potential risks.

The company has also advised affected individuals to stay alert for suspicious emails, messages, or calls that could exploit the exposed information for phishing, social engineering, or other fraudulent activities. Customers are also encouraged to regularly review their account activity for any signs of unauthorized access.

CDSCO Warns Users and Providers against Potentially Hack-able Insulin Pumps!





The wireless communication between Medtronic’s Minimed insulin pumps and other remote controlled related devices like blood glucose meters. These have a high risk of being hacked.

Central Drug Standard Control Organization (CDSCO), the apex drug regulator issued an alert about a few of Medtronic PLC’s insulin pumps being hack-able in response to US FDA flagging the theme.

No complaints of the sort have been received so far from the market, but nonetheless it happens to be an essential issue that needs looking into and hence CDSCO alerted the medical professionals.

Due to the aforementioned alleged cyber-security issues, (nevertheless potential in nature) few of the insulin pumps from the Medtronic Minimed have been recalled.

The US drug regulator recommends people to swap their insulin pumps for different models due to the potential risks related with the communication between these pumps and other devices like glucose meters and CareLink USB device used with them.





An insulin pump is a medical device specifically designed to help  diabetics control their glucose levels. The device pumps insulin in the user’s body in continuous doses.

Every insulin pump from Medtronic’s Minimed has a serial number which according to CDSCO should never be shared.

Per the CDSCO’s alert, the insulin pumps which are susceptible to potential hacking, namely are, MiniMed Paradigm 715, 712, 722 and 754 with software versions 2.6A or lower.

According to sources, Medtronic is pre-emptive about informing the users, regulators and medical professionals about the potential cyber-hazards of the insulin pumps.

They are also readily working with researchers to aid the patients, users, doctors and stakeholders, find answers to any questions they may have.

Medtronic alluded to it that with the evolution of technology will “continue to collaborate with industry researchers and regulators and develop high quality therapies that will positively impact lives”.

The company also remarked that over the years many models of these insulin pumps have been launched where their quality has been focused upon with utmost seriousness and concern.