iRhythm breach exposes data of at least 360,000 cardiac monitoring patients

Wearable heart monitor maker iRhythm says a social engineering attack in June let hackers download patient data, with at least 360,000 people affected, The Record reports.

iRhythm breach exposes data of at least 360,000 cardiac monitoring patients

At a glance

  • Attackers accessed iRhythm systems between June 3 and June 8 via a social engineering attack, according to breach notices.
  • Filings show 298,647 people affected in Texas and 69,526 in South Carolina; the company declined to give a total.
  • Exposed data includes names, dates of birth, insurance numbers, patient account numbers and device serial numbers.
  • A threat actor demanded payment not to publish the data; no group has claimed the attack.

iRhythm, the medical device maker behind the Zio wearable heart monitor, is notifying at least 360,000 people that their personal information was stolen in a cyberattack earlier this year, according to The Record. Breach notices filed with several U.S. states this week say hackers reached third-party-hosted business applications through social engineering and downloaded patient data, after which a threat actor demanded payment to keep it private.

What happened

According to The Record, attackers had unauthorized access to company systems from June 3 to June 8, and the breach notices list June 8 as the incident date. The intruders used a social engineering attack to get into unidentified business applications hosted by a third party, then accessed and downloaded data. The report does not say when iRhythm detected the intrusion.

The company disclosed the incident in a June 8-K filing with the U.S. Securities and Exchange Commission. That filing said iRhythm had received communications from a threat actor claiming to hold sensitive data and later confirmed that certain data had been exfiltrated. The Record says the attacker demanded payment in exchange for not publicly disclosing the information. No group has publicly claimed responsibility.

Who is affected

The Record reports that iRhythm filed notices showing 298,647 affected people in Texas and 69,526 in South Carolina, and also submitted a notice in California. That brings the confirmed figure to at least 360,000, but the company declined to provide a full victim count, so the real total may be higher.

The stolen information includes names, addresses, phone numbers, iRhythm patient account numbers, device serial numbers, insurance numbers, dates of service and dates of birth.

Company response

iRhythm said it "responded promptly after detecting the unauthorized access" and that the incident did not affect clinical systems or medical devices, nor cause any loss of service or operational disruption, according to The Record. The company also said it has no evidence that any personal information has been or will be used to commit identity theft, and that its finances were not affected.

What to do

Patients who have used Zio monitors should watch for notification letters and take up any identity protection services offered. Because the exposed data combines insurance numbers, dates of birth and service dates, affected people should review insurance statements for unfamiliar claims and be wary of calls or emails that cite their medical device or treatment details, which could be used in targeted phishing. For organizations, the case is another example of attackers using social engineering to reach third-party SaaS platforms, underlining the need for phishing-resistant authentication and close monitoring of access to externally hosted business applications.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.