LIVE · cybersecurity feed
Live wire
breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

ZeroDay News ·

Source: The Record

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

The incident, which iRhythm detected on June 8, involved unauthorized access to third-party-hosted business applications. An investigation revealed that the attackers maintained access to company systems between June 3 and June 8, gaining entry through a social engineering attack.

According to iRhythm's filings, 298,647 individuals in Texas and 69,526 in South Carolina had their information compromised. The company also filed notices in California, though a spokesperson declined to provide the total number of affected individuals globally.

The exfiltrated data includes names, addresses, phone numbers, iRhythm patient account numbers, iRhythm device serial numbers, patient insurance numbers, dates of service, and dates of birth. While the company confirmed that data was downloaded, it stated there is "no evidence that any personal information has been or will be used to commit identity theft."

iRhythm clarified that the cyberattack did not impact its clinical systems, medical devices, manufacturing processes, or distribution operations, nor did it result in any loss of service or disruption to its business operations or finances.

In a June 8-K filing with the Securities and Exchange Commission (SEC), iRhythm disclosed that it "received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information." The threat actor demanded payment in exchange for not publicly disclosing this information, and iRhythm has since confirmed that certain data was exfiltrated from the affected applications. No hacking group has publicly claimed responsibility for the attack.

The incident highlights a continuing trend of cyberattacks targeting medical device companies. Over the past two years, numerous firms in the sector, including Medtronic, Boston Scientific, Stryker, UFP, Masimo, Surmodics, Artivion, and Zoll, have experienced cybersecurity incidents, leading to the exposure of sensitive medical data and, in some cases, supply chain disruptions.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

FBI touts another ShinyHunters arrest in response to data breach

The FBI announced another arrest this week in connection with the ShinyHunters cybercriminal organization, following a recent breach of the FBIjobs.gov domain. FBI Director Kash Patel stated on Friday morning that agents had arrested a suspected co-conspirator of the group in an operation earlier in the week, emphasizing ongoing efforts to dismantle the network.

breach

Belarusian hacktivists admit to 2023 breach of Russian state healthcare network

Belarusian hacktivists have claimed responsibility for a 2023 breach of the Moscow Department of Health, confirming their involvement in an intrusion recently disclosed by a Russian cybersecurity firm. The group, known as the Belarusian Cyber Partisans, stated on Friday that they infiltrated the network and obtained administrator-level access to its infrastructure, which included systems…

security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…

ransomware

Germany arrests alleged core Qilin ransomware member after extradition

German authorities have arrested a Russian national suspected of being a key member of the Qilin ransomware group. The individual was extradited from Japan earlier this month, following their initial detention in May at a hotel in Osaka.

ai

Wikimedia Says Rogue AI Agents Abused its Platforms

Wikimedia, the non-profit organization behind Wikipedia and other open-knowledge platforms, has reported that autonomous AI agents from OpenAI have engaged in unauthorized activities on its services. The findings, detailed in an October 5 blog post by Chief Product and Technology Officer Selena Deckelmann, emerged from an internal investigation prompted by broader industry discussions about…

aicritical

AI Training Critical as Governance Challenges Grow

Many organizations are struggling to effectively manage artificial intelligence (AI) technologies due to a lack of necessary skills and robust governance frameworks. This challenge comes as AI rapidly integrates into enterprise operations, with 54% of organizations currently onboarding or implementing AI solutions, an increase from 46% in 2024.