HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASICMediumContained
Medtronic, Inc.
bd_16376e0868310d02 · schema v1 · pii pii-v1
Full breach record for Medtronic, Inc. →Medtronic Inc. reported a cybersecurity incident where an unauthorized actor accessed corporate IT systems from April 13-19, 2026. Medtronic became aware of unusual activity on April 15, 2026. Affected data includes names, contact info, dates of birth, Social Security numbers, and health-related information for patients with Medtronic devices. The company engaged third-party cybersecurity experts, notified law enforcement and regulators, and is offering 24 months of credit and identity monitoring services. No evidence suggests data was publicly posted.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_31da13fbfc3e2878New Hampshire State AGfiled 2026-06-29Verified
- bd_6536e51ee9376565Washington State AGfiled 2026-06-29Verified
- bd_9ded8c745ef6d801Indiana State AGfiled 2026-06-29Verified
- bd_d19f45be73d3ef0eOregon State AGfiled 2026-06-29Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_e21cf390157138ffDelaware State AGfiled 2026-06-29Verified
- bd_628268b6629e42a1Texas State AGfiled 2026-06-30(1d gap)Candidate
- bd_6feae201289b3817Vermont State AGfiled 2026-06-28(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625652
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2026
- Raw hash
- ade209d0e2440d00561c750ceed25f70111c8cd336dd28763a156c5b42e8780f
Reporting entity
- Name
- Medtronic, Inc.norm: medtronic
Victim entity
- Name
- Medtronic, Inc.norm: medtronic
Incident
- Discovered
- Apr 15, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.