iRhythm Holdings, Inc.
Jun 2026 · Graded Verified · Healthcare and Life Sciences · Government record
Incident summary
iRhythm Holdings, Inc.Jun 2026
$700K
Spent responding & recovering
Direct expense
Unauthorized activity struck iRhythm Holdings' data inside 'certain third-party-hosted business applications' on June 8, 2026, a phrase that names no vendor, no entry point, and no data type. The filing quantifies the damage at $700K before it quantifies what was actually taken. Outsourcing the application does not outsource the exposure; the perimeter is wherever the vendor's login page sits. A breach description this vague is not discretion; it is a structural admission that nobody yet knows the shape of the failure.
Verified: the linked document states this figure.
SEC 8-K, Item 1.05
Initial attack type third-party or supply chain inferred · Impact data theft inferred + financial theft or fraud
Quantified 52 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.