Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible DexCom data breach. According to dark web monitoring sources, a hacker group calling itself Redact claimed responsibility for a cyberattack on DexCom in a post first observed in October 2026, alleging it had gained access to internal company systems. As of this writing, DexCom has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About DexCom
DexCom, Inc. is an American multinational medical device company founded in 1999 and headquartered in San Diego, California. The company designs, develops, and commercializes continuous glucose monitoring (CGM) systems used for diabetes management and metabolic health, including the Dexcom G7, G6, and ONE+ systems, as well as the Stelo glucose biosensor. DexCom is publicly traded on the Nasdaq under the ticker DXCM and employs approximately 11,100 people worldwide, with manufacturing facilities in Mesa, Arizona; Batu Kawan, Malaysia; and Athenry, Ireland.
What Happened?
On October 10th, 2026, Ransomware.live reported that the ransomware group Redact claimed DexCom as a victim on its dark web leak site. The Redact group alleges it exfiltrated 3.3 TB of data from DexCom’s systems. This is an attacker-side allegation only. DexCom has not publicly confirmed the incident, no regulatory filing has been identified, and no independent corroborating source confirms that the Redact claim resulted in an actual breach of DexCom systems. The specific types of data allegedly involved have not been disclosed.
Separately, around October 1st, 2026, a second ransomware group, ShinyHunters, also listed DexCom on its own dark web leak site and threatened to publish alleged corporate data. Breachsense recorded this ShinyHunters claim as of October 5th, 2026. DexCom has not publicly confirmed that claim either. The Redact group is described by WatchGuard as an emerging and active threat actor first seen in May 2026 that uses direct and double extortion tactics. On October 5th, 2026, law firm Migliaccio & Rathod LLP announced it was investigating the possible DexCom data breach based on dark web monitoring reports. DexCom also experienced a separate, unrelated incident in April 2026 in which its insurance broker Lockton inadvertently sent an Excel file containing employee personal information — including names, Social Security numbers, dates of birth, and limited benefits election information — to three vendors during a request for proposals. That was a third-party disclosure error, not a cyberattack, and is distinct from the October 2026 ransomware allegations.
Key Facts at a Glance
- Company or Organization: DexCom, Inc.
- Industry: Healthcare / Medical Devices (Continuous Glucose Monitoring)
- Location: San Diego, California
- Incident type: Ransomware leak-site allegation (attacker-side claim only; unconfirmed)
- Litigation status: Migliaccio & Rathod LLP announced an investigation on October 5th, 2026 into the possible breach. Dapeer Law, P.A. is separately investigating a potential class action related to the April 2026 Lockton disclosure incident. Unrelated ongoing litigation includes a consolidated consumer product-defect class action and a securities fraud class action, neither of which is connected to the October 2026 ransomware allegations.
- Source: Ransomware.live – DexCom (Redact claim); Cybernews – ShinyHunters claims O’Reilly and Dexcom breaches; Migliaccio & Rathod LLP – DexCom Investigation; WatchGuard – Redact Ransomware Tracker; Breachsense – DexCom Data Breach in 2026
What Should You Do?
If you believe your information may have been affected, consider placing a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — to help prevent unauthorized accounts from being opened in your name. You are entitled to free credit reports at AnnualCreditReport.com, and reviewing them regularly can help you spot suspicious activity early. If you notice signs of identity theft or fraud, visit IdentityTheft.gov for step-by-step guidance from the Federal Trade Commission. Because DexCom’s products are used in connection with health and medical monitoring, remain alert to any unexpected communications referencing your medical device use or health data, and report suspicious activity promptly.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.