Breach taxonomy
Summary
iRhythm identified unauthorized activity on June 8, 2026 involving data on certain third-party-hosted business applications. On June 9 a threat actor claiming to have proprietary data, patient PHI and other personal information demanded payment in exchange for not publicly disclosing it; the company confirmed data was exfiltrated and determined the incident material on June 10, 2026 given the volume of potentially affected data. Access was obtained through social engineering; no impact to products, clinical/medical device systems, or operations.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsData ExfilPhishing
Company 'confirmed that certain data was exfiltrated' and 'the affected data was obtained through social engineering' -> DATA-EXFIL + PHISHING.
AssetsPersonal DataIp Trade Secrets
Threat actor claims to have obtained 'proprietary data, patient protected health information and other personal information' -> PERSONAL-DATA + IP-TRADE-SECRETS.
EffectsCyber ExtortionInfo Privacy Loss
Threat actor 'demanded payment in exchange for not publicly disclosing this information' -> CYBER-EXTORTION, plus exposure of PHI -> INFO-PRIVACY-LOSS.
Business continuityNot Required
No impact identified to products, clinical or medical device systems, manufacturing/distribution, or ability to meet patient needs -> Not Required.
Impact
Material determination based on volume of exfiltrated PHI with an active extortion demand, but no operational disruption -> score 3.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. On June 8, 2026, iRhythm Holdings, Inc. (the "Company") identified unauthorized activity involving data maintained on certain third-party-hosted business applications. The Company promptly activated its cybersecurity response plan and launched an investigation with the support of external advisors and cybersecurity experts to assess and contain the threat. On June 9, 2026, the Company received communications from a threat actor claiming to have obtained sensitive information, including proprietary data, patient protected health information and other personal information. The communications from the threat actor demanded payment in exchange for not publicly disclosing this information. Since receipt of the communications, the Company has confirmed that certain data was exfiltrated from those applications. On June 10, 2026, the Company determined that the incident is material in light of the volume of the potentially affected data. Based on its investigation as of the date of this Current Report on Form 8-K, (1) the Company has not identified any impact to its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, financial reporting systems, or the Company's ability to meet patient needs and (2) the affected data was obtained through social engineering and is from certain third-party-hosted business applications.