iRhythm notifies patients of June breach affecting hundreds of thousands
TLDR
- Cardiac-monitoring device maker iRhythm has begun notifying patients and state regulators of a breach that occurred on 8 June 2026, more than four months after the incident.1
- At least 360,000 people are confirmed affected so far, including 298,647 in Texas and 69,526 in South Carolina, with notices also filed in California; the company declined to give a total victim count.1
- Hackers used social engineering to access third-party-hosted business applications between 3 and 8 June, stealing names, addresses, phone numbers, device serial numbers, insurance numbers and dates of birth.12
- A threat actor contacted iRhythm the day after gaining access demanding payment to prevent public disclosure of the data; no group has publicly claimed credit, and iRhythm says it has no evidence of identity theft resulting from the incident.1
iRhythm, maker of the Zio Patch wearable cardiac monitor used for long-term arrhythmia detection, said the data of at least 360,000 people was exposed in a breach that occurred on 8 June 2026.1 The company began filing breach notices with regulators and victims this week, more than four months after the incident, telling Recorded Future News it "responded promptly after detecting the unauthorized access and, once the scope was verified, notified affected individuals and applicable regulators."1
An investigation found hackers had access to company systems between 3 and 8 June, gaining entry to unidentified third-party-hosted business applications through a social-engineering attack.1 The stolen information includes names, addresses, phone numbers, iRhythm patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth.12 In a June 8-K filing with the US Securities and Exchange Commission, iRhythm said it "received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information," and that the threat actor "demanded payment in exchange for not publicly disclosing this information."1 The company said it has since confirmed data was exfiltrated from the affected applications, but says it did not affect clinical systems, medical devices or cause any disruption to operations.12
iRhythm's cardiac monitors are used by roughly 8 million patients across the US and Europe.2 The company said it is unaware of any misuse of the stolen data and does not expect the incident to materially affect its finances; it reported $224.2 million in second-quarter revenue.1 As of this week, the breach had not yet appeared on the US Department of Health and Human Services' Office for Civil Rights breach portal, so the full scale beyond the confirmed Texas and South Carolina figures remains unclear.2
Why it matters: a four-month gap between a confirmed data-theft extortion attempt and the first patient notifications leaves hundreds of thousands of people unaware for months that their health data, insurance numbers and device identifiers were in a stranger's hands, and the lack of a published victim total still leaves regulators and patients unable to judge the breach's true scope.