Healthcare
,
Industry Specific
Cybercrime Gang ShinyHunters Claimed to Steal 9M Records
Medical device maker Medtronic told federal authorities that cybercriminals broke into its corporate IT system, but said the incident did not affect the company’s products, manufacturing or distribution operations. Cybercrime gang ShinyHunters claimed to have stolen 9 million of the manufacturer’s records.
See Also: Why Healthcare Faces Rising Risks From Shadow AI
Minneapolis-based Medtronic in a filing to the U.S. Securities and Exchange Commission on Friday said it has not identified any impact to patient safety or, the company’s electronic connections to customers. The incident will likely not put a material decrease in earnings, it also said.
Medtronic, which operates in 150 countries and serves 79 million people globally each year with its wide range of cardiac, neurologic to robotic-assisted surgical devices, reported revenue of $33.5 billion in fiscal 2025.
The company did not immediately respond to ISMG’s request for additional details about the cyber incident.
ShinyHunters claimed on its darkweb site on April 18 to have stolen 9 million Medtronic records containing personally identifiable information and internal corporate date, threatening to publish the data if a ransom was not paid by April 21, according to news site BleepingComputer.
ShinyHunters also claims to be behind a recent hack on home security firm ADT, stealing PII pertaining to 5.5 million customers (see: Home Security Firm ADT Breach: 5.5 Million Customers’ Data Exposed).
The hack on Medtronic is at least the fourth cyber incident disclosed in recent weeks involving a large U.S. based medtech manufacturer.
On March 11, medical gear maker Stryker was hit with a wiper attack claimed by Iranian hacktivist group Handala, which is widely suspected of being a front for Iran’s Ministry of Intelligence. Stryker said earlier this month that it expected the incident to have an impact on first quarter results, which will be released on Thursday (see: Stryker Hack Affects First Quarter Results).
Also, TriMed, a California maker of implantable orthopedic gear last month disclosed it was a victim of a recent cybersecurity incident, as did UFP Technologies, a Massachusetts-based maker of single-use medical devices and other healthcare supplies in late February.
The recent attacks on global medical device makers present a number of concerning issues, some experts said.
“Everyone involved in healthcare, from device manufacturers through to providers, needs to invest in threat modelling risks knowing that cybercriminals don’t seem to care about patient health,” said Tim Mackey, head of software supply-chain risk strategy at application security firm Black Duck.
Click Here For The Original Source.
