HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICHighActive
Medtronic, Inc.
bd_e21cf390157138ff · schema v1 · pii pii-v1
Full breach record for Medtronic, Inc. →Medtronic Inc. disclosed a cybersecurity incident affecting Rhode Island residents. Unauthorized actors accessed corporate IT systems between April 13 and 19, 2026. Impacted data included names, contact info, DOB, SSN, and health-related information. Medtronic engaged third-party cybersecurity experts, worked with law enforcement, and offered 24 months of credit monitoring and identity theft restoration via Epiq. The incident did not affect device safety.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_16376e0868310d02California State AGfiled 2026-06-29Verified
- bd_31da13fbfc3e2878New Hampshire State AGfiled 2026-06-29Verified
- bd_6536e51ee9376565Washington State AGfiled 2026-06-29Verified
- bd_9ded8c745ef6d801Indiana State AGfiled 2026-06-29Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_d19f45be73d3ef0eOregon State AGfiled 2026-06-29Verified
- bd_628268b6629e42a1Texas State AGfiled 2026-06-30(1d gap)Candidate
- bd_6feae201289b3817Vermont State AGfiled 2026-06-28(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2026/06/Consumer-Letter-Exhibit-A.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2026
- Raw hash
- 35a52453a600f65195866db97648fecec6d51fca02bd371b0784f9f4655dfa3b
Reporting entity
- Name
- Medtronic, Inc.norm: medtronic
Victim entity
- Name
- Medtronic, Inc.norm: medtronic
Incident
- Discovered
- Apr 15, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 12,054
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Notifying relevant regulatory authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.