HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighActive
Medtronic, Inc.
bd_31da13fbfc3e2878 · schema v1 · pii pii-v1
Full breach record for Medtronic, Inc. →Medtronic Inc. notified the New Hampshire Attorney General on June 29, 2026, of a cybersecurity incident occurring between April 13 and 19, 2026. An unauthorized actor accessed corporate IT systems, potentially exposing personal information of 12,215 New Hampshire residents, including names, contact info, DOB, SSN, and health-related data. Medtronic engaged third-party cybersecurity experts, notified law enforcement and consumer reporting agencies, and offered 24 months of credit monitoring and identity theft restoration services. Device safety was not impacted.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_16376e0868310d02California State AGfiled 2026-06-29Verified
- bd_6536e51ee9376565Washington State AGfiled 2026-06-29Verified
- bd_9ded8c745ef6d801Indiana State AGfiled 2026-06-29Verified
- bd_d19f45be73d3ef0eOregon State AGfiled 2026-06-29Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_e21cf390157138ffDelaware State AGfiled 2026-06-29Verified
- bd_628268b6629e42a1Texas State AGfiled 2026-06-30(1d gap)Candidate
- bd_6feae201289b3817Vermont State AGfiled 2026-06-28(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/medtronic-20260629.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2026
- Raw hash
- af6b1f2fbbcf1a7e3e3f855c70791d173358d3d8b784501f5bf9fb4806ff18a8
Reporting entity
- Name
- Medtronic, Inc.norm: medtronic
Victim entity
- Name
- Medtronic, Inc.norm: medtronic
Incident
- Discovered
- Apr 15, 2026
- Materiality determined
- —
- Notification sent
- Jun 29, 2026
- Affected individuals
- 12,215
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.