Data Breach · Lawsuits Filed

Dexcom Sued Over Data Breach Claimed by ShinyHunters That Dexcom Has Not Confirmed

Published October 8, 2026

Dexcom glucose monitor users may be covered by proposed class actions alleging DexCom, Inc. failed to protect personal and health information that the extortion group ShinyHunters claimed in October 2026 to have taken. Dexcom has not confirmed a breach, no class has been certified and there is nothing to file yet.

Medical data breach lawsuits filed against Dexcom over a ShinyHunters claim
▼ Hacker Claim · Not Confirmed by Dexcom · No Settlement

This page describes class action complaints and an extortion group's public claim. Dexcom has not confirmed that a breach occurred, the statements below are unproven allegations, and DexCom, Inc. has not been found liable. There is no certified class and nothing to claim at this time. This page is informational and is not legal advice.

What Happened at Dexcom?

Around the start of October 2026, the extortion group ShinyHunters added DexCom, Inc., the San Diego maker of continuous glucose monitors, to its data-leak website and claimed to have taken company data. The group listed O'Reilly Automotive at the same time and threatened to publish files from both companies if they did not contact it. Cybernews, which reported on the listings, said the group posted no sample files and that Dexcom did not respond to a request for comment.

Dexcom has not confirmed or denied the claim. OCA found no breach notice or state attorney general filing from Dexcom, and the company has made no public statement about the listing. That means there is no official account of whether anything was taken, what it was, or how many people it involved.

Three proposed class actions were filed anyway, all in the U.S. District Court for the Southern District of California, where Dexcom is headquartered: one on October 2, one on October 5 and one on October 6, 2026. No court has ruled on any of the allegations.

Status Three Complaints Filed · Breach Not Confirmed October 2–6, 2026 · S.D. Cal. · no class certified
Basis of the Claim ShinyHunters leak-site listing No sample files posted, per Cybernews · no breach notice from Dexcom
Can I Claim? No — nothing to claim yet No settlement, no claim form and no deadline

What the Lawsuits Allege

The two complaints available on the public docket say Dexcom collected sensitive personal and health information from people who use its glucose monitors, apps and support services, and failed to protect it. Both cite the Cybernews report as the source of the breach claim, and both acknowledge that the details are not yet known. One says the number of people affected is unclear and that Dexcom had not disclosed the breach as of filing; the other says the specific records and fields involved would have to be established through Dexcom's own records in the case.

The complaints describe the data differently. One alleges, on information and belief, that it included names, dates of birth, driver's license numbers, financial information, medical records and health insurance information. The other describes account and demographic information linked to glucose readings, device use, technical-support requests and sensor replacements. Neither list comes from Dexcom.

The plaintiffs are Dexcom users from Indiana and Oregon. The Oregon plaintiff says he has used Dexcom's monitors since about 2013, currently uses a G7, shares his readings with his doctors through Dexcom Clarity and with the Tidepool app, and has repeatedly given Dexcom personal and medical information when asking for technical help and replacement sensors. The complaint for the first case, filed October 2, is not yet on the public docket.

Legal Claims and What the Lawsuits Seek

The Indiana plaintiff's complaint brings claims for negligence, negligence per se, unjust enrichment, breach of implied contract and breach of confidence. The Oregon plaintiff's complaint pleads negligence, breach of implied contract and unjust enrichment alongside state-law claims under California's Confidentiality of Medical Information Act, the privacy clause of the California Constitution, Oregon's Unlawful Trade Practices Act and Oregon's law of breach of confidence, with a proposed Oregon subclass.

Both propose a nationwide class of people whose information was compromised in the alleged breach. They ask for damages, statutory damages where available, restitution, and court orders requiring Dexcom to improve how it protects the information it holds. Those are requests, not amounts anyone has been awarded.

Why the Breach Claim Matters

Lawsuits filed off an attacker's listing, before any company notice, face a specific problem. A data breach complaint normally relies on the company's own notification letter to show that a particular person's information was taken. Without one, the plaintiffs have to persuade the court that their own data was involved, which is harder when the attacker has posted nothing.

ShinyHunters' record cuts both ways. Some of its listings have been confirmed by the companies involved, while others have proved smaller than claimed. OCA's coverage of the Carhartt data breach shows how a ShinyHunters dataset can turn out to be padded with synthetic records, and the DentaQuest data breach lawsuits show the opposite path, a listing followed by a company-confirmed count.

If Dexcom's data were taken, the stakes would be high. Glucose readings, device records and support histories are health information, and a continuous glucose monitor account ties that information to a named person over years of use.

What Happens Next

The next significant fact is likely to come from Dexcom or from ShinyHunters, not from the court. A company statement or breach notices would establish whether data was taken and whose, and a publication of files by the group would show what it holds. Either would reshape the complaints.

On the court side, the two later complaints have told the court the cases are related, and three overlapping suits in the same district are commonly consolidated before one judge. Dexcom would then respond, often with a motion to dismiss. There is nothing to file in these cases now. This page will be updated if Dexcom confirms or denies the claim, or if the cases are consolidated.

Questions

Has Dexcom confirmed a data breach?

No. As of October 8, 2026, Dexcom had not publicly confirmed or denied the claim made by the extortion group ShinyHunters, and the complaints themselves say the company had not disclosed a breach. The lawsuits rest on the group's leak-site listing and news reports about it.

Is there a Dexcom data breach settlement or claim form?

No. Three proposed class actions have been filed in the U.S. District Court for the Southern District of California, but all are at the complaint stage. No class has been certified, there is no settlement, and there is nothing to claim.

What Dexcom data do the lawsuits say was taken?

One complaint alleges, on information and belief, that the data included names, dates of birth, driver's license numbers, financial information, medical records and health insurance information. Another describes account and demographic information linked to glucose readings, device use and technical-support records. Neither list comes from Dexcom, and ShinyHunters did not post sample files.

Who is ShinyHunters?

ShinyHunters is an extortion group that steals data from companies and threatens to publish it unless it is paid. Its listings have sometimes been confirmed and sometimes overstated, so a listing on its leak site is a claim, not proof of what was taken.

Why are there several Dexcom lawsuits?

Different law firms filed separate complaints within days of the leak-site listing. Two of them have told the court the cases are related. Overlapping cases in the same federal district are commonly consolidated before one judge and proceed as a single case.

Sources

• Brigando v. Dexcom, Inc., No. 3:26-cv-05668 (S.D. Cal., filed October 2, 2026) — CourtListener docket
• Lovell v. Dexcom, Inc., No. 3:26-cv-05699 (S.D. Cal., filed October 5, 2026) — CourtListener docket
• Hunter v. Dexcom, Inc., No. 3:26-cv-05727 (S.D. Cal., filed October 6, 2026) — CourtListener docket
• Cybernews — "ShinyHunters resurfaces with O’Reilly Auto Parts, Dexcom breach claims after FBI hack showdown"


For more class actions keep scrolling below.
Status Complaints Filed — No Class Certified · Breach Not Confirmed by Dexcom
Cases Brigando v. Dexcom, Inc. · Lovell v. Dexcom, Inc. · Hunter v. Dexcom, Inc.
Case Numbers 3:26-cv-05668 · 3:26-cv-05699 · 3:26-cv-05727
Court U.S. District Court, Southern District of California
Date Filed October 2–6, 2026

More Data Breach Lawsuits