// AI threat desk · 10 Oct 2026
Home/LEAK · Data Leaks
Data LeaksMediumDATACVSS not assigned

iRhythm cyberattack breached data of at least 360,000 people

iRhythm said the data of at least 360,000 people was breached in a June cyberattack, and that the incident occurred on June 8 and involved unauthorized access to third-party systems.

AI-generated image of security analysts reviewing blurred healthcare system screens in a monitoring centre.
AI-generated image, not a photo of the event.
Key takeaways
  • iRhythm said the incident involved unauthorized access to third-party systems.
  • iRhythm said its clinical systems and medical devices were not affected.
  • iRhythm said a June cyberattack breached the data of at least 360,000 people.

iRhythm said the data of at least 360,000 people was breached in a June cyberattack, and that the incident occurred on June 8 and involved unauthorized access to third-party systems.

The Record reported that the affected information included names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth. iRhythm said cybercriminals accessed and downloaded the information.

On this page

Hackers accessed third-party business applications through social engineering

The Record said an investigation found that hackers had access to company systems between June 3 and June 8. They gained access to unidentified third-party-hosted business applications through a social engineering attack.

The Record said the information included iRhythm patient account numbers, device serial numbers and patient insurance numbers, along with personal and service details. iRhythm later confirmed that certain data had been exfiltrated from the applications.

iRhythm said the threat actor demanded payment

iRhythm said communications from the threat actor demanded payment in exchange for not publicly disclosing the information. The company said the cyberattack did not affect its products, devices, manufacturing process or distribution operations, and that its finances were not disturbed.

iRhythm said it responded promptly after detecting the unauthorized access and, once it verified the scope, notified affected individuals and applicable regulators.

FAQ

What happened in the iRhythm cyberattack?

iRhythm said a June 8 cyberattack involved unauthorized access to third-party systems and breached data affecting at least 360,000 people.

What information was accessed in the iRhythm breach?

The Record said the information included names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth.

Did the iRhythm attack affect medical devices or clinical systems?

iRhythm said the incident did not affect its clinical systems or medical devices and did not disrupt operations.

Sources

  1. Hundreds of thousands impacted by data breach at biosensor firm iRhythm, The Record
  2. Cardiac monitoring, Wikipedia
How we checked this story
ClaimSourceStatus
iRhythm said a June cyberattack breached the data of at least 360,000 people.iRhythm, via The RecordAttributed
iRhythm said 298,647 people in Texas and 69,526 in South Carolina had information stolen.iRhythm, via The RecordAttributed
iRhythm said it responded promptly, verified the scope, and notified affected individuals and regulators.iRhythm, via The RecordAttributed
iRhythm said the incident did not affect its clinical systems or medical devices and did not disrupt operations.iRhythm, via The RecordAttributed
The Record reported that hackers had access to company systems between June 3 and June 8 through a social engineering attack.The RecordAttributed
The Record said the stolen information included names, addresses, phone numbers, patient account numbers, device serial numbers, insurance numbers, dates of service, and dates of birth.The RecordAttributed
iRhythm said cybercriminals accessed and downloaded the information.iRhythm, via The RecordAttributed
iRhythm said it had no evidence that personal information had been or would be used for identity theft.iRhythm, via The RecordAttributed
The Record said no hacking group publicly took credit for the attack.The RecordAttributed
iRhythm said the cyberattack did not affect its products, devices, manufacturing, distribution operations, or finances.iRhythm, via The RecordAttributed
iRhythm reported $224.2 million in second-quarter revenue.iRhythm, via The RecordAttributed
iRhythm said the threat actor demanded payment to prevent public disclosure of the information.iRhythm, via The RecordAttributed
iRhythm said it confirmed that certain data had been exfiltrated from the applications.iRhythm, via The RecordAttributed
Cardiac monitoring generally refers to continuous or intermittent monitoring of heart activity to assess a patient’s condition relative to cardiac rhythm.WikipediaConfirmed
Ambulatory cardiac monitoring uses small wearable devices such as Holter monitors, wireless ambulatory ECGs, or implantable loop recorders.WikipediaConfirmed

Could not verify

  • Whether the full number of affected people is established
  • Whether the stolen information has been misused is not established
  • Whether a hacking group was responsible is not established
Explore with AI