Breach taxonomy
Summary
iRhythm identified unauthorized activity on June 8, 2026 involving data on certain third-party-hosted business applications. On June 9 a threat actor claiming to have proprietary data, patient PHI and other personal information demanded payment in exchange for not publicly disclosing it; the company confirmed data was exfiltrated and determined the incident material on June 10, 2026 given the volume of potentially affected data. Access was obtained through social engineering; no impact to products, clinical/medical device systems, or operations.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsData ExfilPhishing
Company 'confirmed that certain data was exfiltrated' and 'the affected data was obtained through social engineering' -> DATA-EXFIL + PHISHING.