惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
宝玉的分享
宝玉的分享
C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
T
Tailwind CSS Blog
IT之家
IT之家
The Cloudflare Blog
V
V2EX
雷峰网
雷峰网
www.infosecurity-magazine.com
www.infosecurity-magazine.com
P
Proofpoint News Feed
I
Intezer
C
Cybersecurity and Infrastructure Security Agency CISA
美团技术团队
P
Privacy International News Feed
Apple Machine Learning Research
Apple Machine Learning Research
G
GRAHAM CLULEY
C
CXSECURITY Database RSS Feed - CXSecurity.com
C
Cisco Blogs
Simon Willison's Weblog
Simon Willison's Weblog
T
The Exploit Database - CXSecurity.com
TaoSecurity Blog
TaoSecurity Blog
O
OpenAI News
Security Latest
Security Latest
V2EX - 技术
V2EX - 技术
S
SegmentFault 最新的问题
博客园_首页
H
Hacker News: Front Page
有赞技术团队
有赞技术团队
博客园 - 聂微东
AWS News Blog
AWS News Blog
博客园 - 司徒正美
T
Threat Research - Cisco Blogs
K
Kaspersky official blog
N
News and Events Feed by Topic
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
T
Threatpost
The Last Watchdog
The Last Watchdog
S
Security Affairs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Schneier on Security
Schneier on Security
S
Secure Thoughts
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
PCI Perspectives
PCI Perspectives
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Heimdal Security Blog
博客园 - 叶小钗
罗磊的独立博客

GovInfoSecurity.com RSS Syndication

On Demand | Regulation Didn’t Change, Your Identity Landscape Did On Demand | Weaving Agentic AI into the SOC: A Practical Playbook for Operationalizing and Scaling Autonomy Why Periodic Pentesting Can’t Keep Up And What Security Leaders Are Doing Instead Claude Mythos 5 Can Build Exploits But Can't Power Campaigns AI Is Reshaping Cybersecurity Training Priorities Health Cyberthreat Sharing Is Advancing But Gaps Persist Are Small Models Closing the Gap on Frontier AI Cyber Tools? Government info security news, training, education Government info security news, training, education Government info security news, training, education Government info security news, training, education Beyond the Inbox: Defending Against AI-Enabled Social Engineering Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security How AI Governance Protects Patient Care and Sensitive Data Why Hospitals Must Rethink Cyber Resilience The Privacy Risks of Embedded, Shadow AI in Healthcare Why Election Systems Are Now a Persistent Cyber Target Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight AI Agents Are the New Insiders Demystifying Claude: Signal vs. Speculation German Court: Google Liable for AI Summaries DOJ, FBI Seize 13 Domains in Chinese Recruitment Op A Security Gets $37M to Thwart Weaponized AI With Automation Breach Roundup: CISA Says Agencies Should 'Patch Smarter' Google Sues Chinese Phishing Service Over Gemini Abuse Policy as Code: From Documents to Machine Intelligence Anthropic Limits on OT Access to Mythos Draw Criticism Ozempic Drug Maker Loses Clinical Trial Data in Hack ISMG Editors: Anthropic Unleashes Claude Mythos 5 ISACA Survey: AI Adoption Is Rising, Visibility Is Not Webinar | Frontier AI and Identity Security in Financial Services US Pulls the Plug on Anthropic's Top AI Models US Anthropic Export Controls Sparks Sharp EU Reaction 1Password Buys Apono to Expand AI Access Governance Why Banks Must Align Stakeholders Before Scaling AI Geopolitics Is Now a Cybersecurity Problem Why AI Defenses Fail Without Data and Identity Fundamentals Labcorp Agrees to Pay $35M to Settle AMCA Data Breach NewCore Launches With $66M to Rebuild Identity for AI Agents GovSec Summit USA 2026: Cyber Resilience Amid Fiscal Reality How FDA Mythos Shutdown Contains a Message: Don ShinyHunters Hits Universities Via Oracle Zero-Day How FDA US FCC Eases Router Ban for Cable ISPs Chinese Hacking Firm Upgrades With New Windows Backdoor South Korea Fines Coupang $409M Over Massive Data Breach Cyber Resilience Summit Dallas Prioritizes Risk Management Hacker: Restore Fable and Mythos Access, Cybersecurity Leaders Urge Live Webinar | Behind Dell’s AI Infrastructure Performance Rokarolla Android Banking Trojan Enables Device Takeover Ent Raises $100M to Reinvent Endpoint Security for AI Era The AI Accountability Gap CIOs Can Chinese Espionage Actor Abuses Email Rules to Steal Research Data AWS Unveils Continuum to Fight Vulnerability Backlog Quantum-Safe Cryptography Isn SpaceX Bets Big on AI Coding With $60B Cursor Deal Mastra AI Framework Poisoned in npm Supply-Chain Attack
Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data
Marianne Kolbasuk McGee · 2026-06-18 · via GovInfoSecurity.com RSS Syndication

Data Breach Notification , Data Privacy , Data Security

iRhythm: Patient Information and 'Proprietary' Data Breached, Held for Ransom (HealthInfoSec) • June 17, 2026    
Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data
Cardiac monitoring firm iRhythm told US federal regulators that sensitive patient information and "proprietary" data was stolen in a recent hack. (Image: iRhythm)

A cardiac monitoring firm that helps millions of patients diagnose and track cardiac arrhythmias says hackers stole proprietary data and patient health information and demanded a ransom. The company didn't say whether it paid.

See Also: Know Thy Enemy: Threats to Cyber Resilience

San Francisco-based iRhythm Technologies told the U.S. Securities and Exchange Commission that hackers stole the data from "certain" third-party-hosted business applications. An SEC filing on Monday said the company discovered "unauthorized activity" on the hosted systems on June 8.

The following day, iRhythm received demands from a threat actor for an undisclosed payment in exchange for not publicly releasing the stolen data, including proprietary data, patient protected health information and other personal information, the company said.

"On June 10, the company determined that the incident is material in light of the volume of the potentially affected data," iRhythm told the SEC.

The company in a public statement about the incident posted on its website said it has not identified "any impact" to its products, clinical or medical device systems, connections to customers, manufacturing and distribution operations, or patient safety.

"We do not store or retain individual financial account information or payment card information," iRhythm said.

iRhythm did not immediately respond to ISMG's request for additional details about the incident, including whether the company paid a ransom demand, the number of people affected by the data breach and clarification about the type of third-party hosted applications compromised.

iRhythm, which reported revenue of $747.1 million in 2025, offers wearable biosensors, remote monitoring and cloud-based data analytics "with powerful proprietary artificial intelligence algorithms" to help diagnose and track patients with cardiac arrhythmias. The company says it serves more than 8 million patients in the U.S. and Europe.

In a year-end filing last year with the SEC, iRhythm admitted that it had been subject to cyber incidents and data compromises in the past, "and expect that we will be subject to additional cyberattacks in the future and may experience future data breaches and other security incidents."

"Such incidents may impact the integrity, availability or confidentiality of the data we maintain or disrupt our information systems, devices or business, including our ability to deliver our services," the company told the SEC.

"As cyberthreats continue to evolve, we may be required to expend significant additional resources to continue to modify or enhance our protective measures or to investigate and remediate any cybersecurity vulnerabilities," the company said.

iRhythm also told the SEC that its Zio brand cardiac monitoring devices "are subject to cybersecurity vulnerabilities leading to potential harm to patients or compromises data security and confidentiality."

In case of an incident affecting those Zio products, "we may be required to initiate field actions, including device recalls, or subject to government inspections, investigations or enforcement actions," the company told the SEC.

The company also said a breach could "cause significant harm to our brand reputation and consumer trust in our devices."

iRhythm is among several other medical device companies hit with hacks in recent months, most notably a March 11 wiper attack on medical technology manufacturer Stryker, which was claimed by Iranian hacktivists Handala. The group, which widely suspected of being a front for Iran's Ministry of Intelligence, boasted of exfiltrating 50 terabytes of "critical data" for Stryker. The attack also disrupted Stryker ordering, distribution and manufacturing operations for several weeks (see: Stryker Hack Affects First Quarter Results).

In April, ransomware gang ShinyHunters posted a claim on a Tor network site alleging it had hacked into a database of medical device maker Medtronic, stealing 9 million records containing patient information as well as additional terabytes of internal corporate data (see: Medtronic Already Facing Federal Lawsuits in Recent Hack).

Also, in February, UFP Technologies, a Massachusetts-based maker of single-use medical devices and other healthcare supplies, also notified the SEC about a cyber incident discovered on Valentine's Day that involved the theft or destruction of some company data (see: Medical Device Maker Reports Data Theft Hack to SEC).