Medtronic has confirmed a major cybersecurity breach occurring in April 2026 that exposed the sensitive personal and health-related information of nearly 3.8 million Americans across its corporate IT systems.
Key Points
- Medtronic reported that an unauthorized actor accessed corporate IT systems between April 13 and April 19, 2026.
- The Indiana Attorney General’s Office was notified that 3,834,294 individuals were impacted by the data theft.
- Compromised data includes names, contact information, dates of birth, Social Security numbers, and private health records.
- The company is providing affected individuals with 24 months of complimentary credit monitoring, dark web monitoring, and identity theft restoration services.
- Medtronic stated there is currently no evidence that the stolen data has been publicly posted or leaked on the internet.