Cook Medical disclosed that a recent cyberattack compromised customer information.
“On July 2, a Cook Medical employee was deceived by a social engineering attack and inadvertently gave an outside party access to certain company systems,” the company said in a news release today. “We identified the unauthorized access and contained it quickly on the same day it occurred.”
Customer contact information for U.S. and Canadian customers, records of customer communications with Cook employees in Salesforce, employee names and company email addresses and certain internal business files accessed via SharePoint were among the compromised data.
“Based on our review to date, we have no evidence that sensitive or protected data was accessed,” the Bloomington, Indiana–based company said.
The device developer is notifying customers and employees of the incident and issuing guidance on how to identify follow-on scams. Cook said its operations are running normally without impact to its products, manufacturing and ability to serve patients and customers.
“We take this seriously, and we will continue to update customers and employees as our investigation progresses,” Cook said.
In a similar incident in 2023 at Zoll Medical, protected health information of employees, dependants and beneficiaries was exposed in what the company described as a “sophisticated email phishing attack” that targeted a Zoll employee.
Cook Medical adds to growing list of medtech companies hit by cyber attacks this year
In June, cardiac monitor maker iRhythm identified unauthorized activity involving data maintained and exfiltrated from third-party-hosted business applications. Similarly, an unauthorized party accessed data in certain Medtronic corporate IT systems this April.
Earlier this year in March, an Iranian-backed “hacktivist” group managed a “wiper attack” against Stryker, targeting data on Stryker’s Microsoft-based IT system and effectively wiping it out so it couldn’t be retrieved.
Intuitive Surgical also experienced a cyberattack in April, when an unauthorized third party accessed certain internal IT business applications as a result of a phishing incident.
In 2023, protected health information of employees, dependants and beneficiaries of Zoll Medical was exposed in an email phishing cyberattack.
