Find notable cyber news and cases, enriched with sources, timelines, and signals.

IRhythm patient data exfiltration from third-party business applications

Data Leak
First reported
Last updated
Happening score
H score 34
2 unique sources, 2 articles

Summary

Hide ▲

iRhythm Holdings disclosed a data breach involving third-party-hosted business applications after a threat actor used social engineering to access data and demanded payment on June 9, 2026. The company said it detected unauthorized activity on June 8, confirmed that some data was stolen, and is still determining the full scope. The exposed material includes proprietary data and patients’ protected health information, while products, clinical or medical device systems, and financial reporting systems were not impacted.

Related Happenings

Aflac Japan impacted files data exposure

Data Leak
H score66 First: 30.06.2026 14:12 Last: 30.06.2026 14:12 Sources 1

About this happening: Aflac Japan disclosed that certain impacted files exposed policy and coverage details, personal information, and bank account information after unauthorized access...

IRhythm Holdings hit by cyberattack

Incident
H score31 First: 16.06.2026 09:31 Last: 16.06.2026 09:31 Sources 1

How related: The company said it detected “unauthorized activity involving data maintained on certain third-party-hosted business applications” on June 8.

About this happening: iRhythm Holdings disclosed a data breach after attackers used social engineering against third-party-hosted business applications and stole patients' personal an...

Latest development: 16.06.2026 18:06

iRhythm detected unauthorized activity involving data maintained on certain third-party-hosted business applications on June 8 after social engineering was used against the applications; the targeted application was not named.

West Pharmaceutical Services Inc. hit by data theft breach

Incident
H score19 First: 14.05.2026 01:23 Last: 14.05.2026 01:23 Sources 1

About this happening: West Pharmaceutical Services disclosed a cyberattack that exfiltrated data and encrypted systems, disrupting global operations and increasing recovery risk. The co...

LexisNexis Legal & Professional data leak after AWS intrusion

Data Leak
H score41 First: 03.03.2026 17:40 Last: 03.03.2026 17:40 Sources 1

About this happening: FulcrumSec leaked 2GB of files tied to LexisNexis Legal & Professional, exposing customer and business information that could be used for follow-on abuse. The company...

UFP Technologies hit by network compromise

Incident
H score15 First: 26.02.2026 01:02 Last: 26.02.2026 01:02 Sources 1

About this happening: UFP Technologies disclosed a cybersecurity incident that affected many but not all IT systems, disrupting billing and label making for customer deliveries. The com...

Timeline

  1. 16.06.2026 09:31 1 articles · 29d ago

    Threat actor demands payment to suppress iRhythm patient data

    Exploitation Observed

    On June 9, 2026, a threat actor told iRhythm Holdings it had obtained sensitive information, including proprietary data, patient protected health information and other personal information, and demanded payment in exchange for not publicly disclosing it; the access path involved social engineering.

    Show sources
  2. 16.06.2026 09:31 3 articles · 29d ago

    iRhythm confirms exfiltration of patient health information

    Victim Impact Update

    On June 10, 2026, iRhythm Holdings determined the incident was material in light of the volume of the potentially affected data and confirmed that certain data had been exfiltrated from third-party-hosted business applications.

    Show sources
  3. 16.06.2026 09:31 1 articles · 29d ago

    iRhythm Holdings discloses a data breach in SEC filing

    Initial Disclosure

    iRhythm Holdings disclosed the breach in an SEC filing, saying it discovered the incident one day earlier, launched an investigation with external cybersecurity experts and activated its cybersecurity response plan to contain the breach.

    Show sources