Cybersecurity incidents are increasingly targeted toward medical device companies. Among others, Cook Medical was recently impacted.
Cook Medical is the latest medtech company to be impacted by a cyberattack.
The Bloomington, IN-based company said that on July 2, a Cook Medical employee was deceived by a social engineering attack and inadvertently gave an outside party access to certain company systems. The company said it identified the unauthorized access and contained it "quickly on the same day it occurred."
Cook said its investigation, conducted with the support of an outside cybersecurity firm, found that the information involved was primarily:
Business information for U.S. and Canadian customers
Records of communications with Cook employees within the company's Salesforce system
Employee names and company email addresses
Certain internal business files that were accessed via SharePoint
Based on the company's review to date, Cook said it has no evidence that sensitive or protected data was accessed.
"We are notifying customers and employees and providing guidance on how to watch for follow-on scams, which is the most likely real-world risk from this type of incident," the company said. "This incident has not affected our products, manufacturing, or our ability to serve patients and customers."
Earlier this year, Iran-linked hackers claimed responsibility for a global cyberattack that wiped Stryker devices and disrupted operations worldwide.
The group Handala claimed responsibility for the attack on social media, calling it retaliation "for the brutal attack on the Minab school and in response to ongoing cyber assaults against the infrastructure of the Axis of Resistance."
Less than a week after the Stryker incident, Intuitive Surgical reported it was the target of a phishing scheme.
"The information accessed was obtained from an employee's compromised access into Intuitive's internal business administrative network. It includes some customer business and information, as well as Intuitive employee and corporate data. It was not obtained from our da Vinci or Ion systems," Intuitive said.
Then, in April, Medtronic reported a cyberattack . The company said an unauthorized party accessed data from some of its corporate IT systems. The company said it had not identified any impact to its products, patient safety, connections to customers, manufacturing and distribution operations, financial reporting systems, or Medtronic's ability to meet patient needs.
Then, in June, cyberattackers targeted iRhythm . The company received a notice from a "threat actor" that it had obtained protected patient information, including proprietary data, patient protected health information, and other personal information.
The cyberterror organization demanded payment from iRhythm in exchange for not leaking the data. While the company confirmed that the cyberterror group did obtain sensitive information, it is unclear if the company paid or plans to pay the ransom.Last month, Abbott disclosed a cyberattack on Exact Sciences, its cancer diagnostics systems, and another attack on its LabCentral portal. The company acquired Exact Sciences in 2025.
"Upon learning this, we took immediate steps to address the situation," Abbott said. "We have engaged leading third-party cybersecurity experts and law enforcement and are working diligently to further investigate the information accessed and resolve this issue."
Abbott noted that it did not expect any material impact on the business or financial results.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
