GoFirm
Back to Blog
Case Studies·4 min read

The MFA approval ShinyHunters claims handed over 9 million Medtronic patient records

By GoFirm

On 15 April 2026, Medtronic plc, the medical device manufacturer with $33.5 billion in annual revenue and roughly 95,000 employees across 150 countries, detected unusual activity on its corporate IT systems. The company's subsequent investigation found that an unauthorised party had been inside those systems since 13 April. Within days, the data extortion group ShinyHunters had listed Medtronic on its dark web leak site and set a ransom deadline, claiming to hold more than nine million records of personally identifiable information alongside terabytes of internal corporate data.

Medtronic has not confirmed the precise method of entry. The timing, technique, and target profile place it squarely inside a documented ShinyHunters playbook, the same one the group used days earlier against the security firm ADT in the same week: an AI-generated voice call, built on commercial platforms such as Bland AI or Vapi, phones an employee, impersonates IT helpdesk staff, and walks the target through what looks like a routine multi-factor authentication reset. The employee approves a single Okta push notification. That approval produces a fully authenticated session, indistinguishable to every downstream system from the real employee logging in.

From there the attacker pivots into Salesforce. ShinyHunters has weaponised a modified version of AuraInspector, a legitimate open-source Salesforce auditing tool, to bundle up to 250 API requests into a single call against the platform's Aura endpoint, extracting records in bulk while staying under standard rate limits. It is the same mechanism the group has used against more than 400 organisations in 2026, and the same one it used to pull nine million records out of Medtronic and 5.5 million out of ADT within the same seven-day window. Medtronic was listed for extortion on 18 April, given a three-day deadline, and removed from the leak site later that month, an outcome consistent with a ransom having been paid, though Medtronic has not confirmed this.

The scale of the loss is still coming into view. Medtronic's own notification letters, sent starting in July, nearly three months after the intrusion, confirm that names, contact details, dates of birth, Social Security numbers, and health-related information were exposed. State breach filings already put the confirmed toll above 369,000 people across Texas, Massachusetts, and Vermont alone, a fraction of the nine million records ShinyHunters claims to hold. Several class action lawsuits have already been filed, and Medtronic is offering affected individuals 24 months of credit monitoring alongside identity theft insurance of up to $1 million.

The defences that failed here were not weak by conventional standards. Medtronic segments its corporate IT environment from the networks that run its medical devices, its manufacturing lines, and its hospital customer connections, which is precisely why the company can state with confidence that no pacemaker, insulin pump, or surgical robot was put at risk. That segmentation held. What sat outside it was the single decision point every one of these ShinyHunters intrusions shares: an employee, on a phone call, approving a credential action that carried the authority to open a Salesforce environment holding patient data at a scale most hospitals will never hold in their own systems. Push-based MFA confirmed only that a button had been pressed. It confirmed nothing about who pressed it, or why.

A Salesforce bulk export of patient records is an execution event. Under GoFirm, before that kind of export can run, a confirmation request goes to the named authority for that system, not the employee mid-call with an unverified caller, on their own registered device, through a separate channel the attacker never touches. The vishing call can be flawless. It can know the employee's name, their manager, their ticket history. None of that matters, because the confirmation does not depend on what the employee believes about the caller. It depends on whether the actual named authority, on the device GoFirm already knows is theirs, approves the specific action being requested.

That is the distinction a push notification cannot make and an execution boundary can. ShinyHunters did not need to break Medtronic's encryption, bypass its segmentation, or find a zero-day. It needed one employee to approve one prompt. A vishing call, however convincing, cannot produce a biometric confirmation from the named authority on a separate, registered channel. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Bill Toulas, "Medtronic notifies customers impacted by ShinyHunters data breach," BleepingComputer, 2 July 2026

2. Steve Alder, "Medtronic Starts Notifying Individuals Affected by April 2026 Cyberattack," The HIPAA Journal, 1 July 2026

3. Eric Bang, "ShinyHunters Hit Medtronic and ADT: 14.5M Records Stolen via AI Vishing and Salesforce," Decryption Digest, 29 April 2026 (updated 1 July 2026)

4. "Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak," SecurityWeek

Share this article