IRhythm patient data exfiltration from third-party business applications
Data Leak
Summary
Hide ▲
Show ▼
iRhythm Holdings disclosed a data breach involving third-party-hosted business applications after a threat actor used social engineering to access data and demanded payment on June 9, 2026. The company said it detected unauthorized activity on June 8, confirmed that some data was stolen, and is still determining the full scope. The exposed material includes proprietary data and patients’ protected health information, while products, clinical or medical device systems, and financial reporting systems were not impacted.
Related Happenings
Aflac Japan impacted files data exposure
Data Leak
H score66
First: 30.06.2026 14:12
Last: 30.06.2026 14:12
Sources 1
About this happening:
Aflac Japan disclosed that certain impacted files exposed policy and coverage details, personal information, and bank account information after unauthorized access...
Aflac Japan impacted files data exposure
Data LeakAbout this happening: Aflac Japan disclosed that certain impacted files exposed policy and coverage details, personal information, and bank account information after unauthorized access...
IRhythm Holdings hit by cyberattack
Incident
H score31
First: 16.06.2026 09:31
Last: 16.06.2026 09:31
Sources 1
How related:
The company said it detected “unauthorized activity involving data maintained on certain third-party-hosted business applications” on June 8.
About this happening:
iRhythm Holdings disclosed a data breach after attackers used social engineering against third-party-hosted business applications and stole patients' personal an...
IRhythm Holdings hit by cyberattack
IncidentHow related: The company said it detected “unauthorized activity involving data maintained on certain third-party-hosted business applications” on June 8.
About this happening: iRhythm Holdings disclosed a data breach after attackers used social engineering against third-party-hosted business applications and stole patients' personal an...
Latest development: 16.06.2026 18:06
iRhythm detected unauthorized activity involving data maintained on certain third-party-hosted business applications on June 8 after social engineering was used against the applications; the targeted application was not named.
West Pharmaceutical Services Inc. hit by data theft breach
Incident
H score19
First: 14.05.2026 01:23
Last: 14.05.2026 01:23
Sources 1
About this happening:
West Pharmaceutical Services disclosed a cyberattack that exfiltrated data and encrypted systems, disrupting global operations and increasing recovery risk. The co...
West Pharmaceutical Services Inc. hit by data theft breach
IncidentAbout this happening: West Pharmaceutical Services disclosed a cyberattack that exfiltrated data and encrypted systems, disrupting global operations and increasing recovery risk. The co...
LexisNexis Legal & Professional data leak after AWS intrusion
Data Leak
H score41
First: 03.03.2026 17:40
Last: 03.03.2026 17:40
Sources 1
About this happening:
FulcrumSec leaked 2GB of files tied to LexisNexis Legal & Professional, exposing customer and business information that could be used for follow-on abuse. The company...
LexisNexis Legal & Professional data leak after AWS intrusion
Data LeakAbout this happening: FulcrumSec leaked 2GB of files tied to LexisNexis Legal & Professional, exposing customer and business information that could be used for follow-on abuse. The company...
UFP Technologies hit by network compromise
Incident
H score15
First: 26.02.2026 01:02
Last: 26.02.2026 01:02
Sources 1
About this happening:
UFP Technologies disclosed a cybersecurity incident that affected many but not all IT systems, disrupting billing and label making for customer deliveries. The com...
UFP Technologies hit by network compromise
IncidentAbout this happening: UFP Technologies disclosed a cybersecurity incident that affected many but not all IT systems, disrupting billing and label making for customer deliveries. The com...
Timeline
-
16.06.2026 09:31 1 articles · 29d ago
Threat actor demands payment to suppress iRhythm patient data
Exploitation ObservedOn June 9, 2026, a threat actor told iRhythm Holdings it had obtained sensitive information, including proprietary data, patient protected health information and other personal information, and demanded payment in exchange for not publicly disclosing it; the access path involved social engineering.
Show sources
- iRhythm discloses data breach, says hackers stole patient info — www.bleepingcomputer.com — 16.06.2026 09:31
-
16.06.2026 09:31 3 articles · 29d ago
iRhythm confirms exfiltration of patient health information
Victim Impact UpdateOn June 10, 2026, iRhythm Holdings determined the incident was material in light of the volume of the potentially affected data and confirmed that certain data had been exfiltrated from third-party-hosted business applications.
Show sources
- iRhythm discloses data breach, says hackers stole patient info — www.bleepingcomputer.com — 16.06.2026 09:31
- iRhythm discloses data breach, says hackers stole patient info — www.bleepingcomputer.com — 16.06.2026 09:31
- iRhythm Confirms Data Stolen in Hack — www.securityweek.com — 16.06.2026 18:06
-
16.06.2026 09:31 1 articles · 29d ago
iRhythm Holdings discloses a data breach in SEC filing
Initial DisclosureiRhythm Holdings disclosed the breach in an SEC filing, saying it discovered the incident one day earlier, launched an investigation with external cybersecurity experts and activated its cybersecurity response plan to contain the breach.
Show sources
- iRhythm discloses data breach, says hackers stole patient info — www.bleepingcomputer.com — 16.06.2026 09:31