Intuitive Surgical
(Nasdaq: ISRG)
today said an unauthorized third party accessed certain internal IT business applications in a cybersecurity incident.
The surgical robotics leader said the breach came as a result of a cybersecurity phishing incident. It says it quickly activated its incident response protocols and secured all affected applications.
“We are providing this web update to be transparent about this issue beyond any required notifications,” the company said in a statement.
Shares of ISRG fell 1.3% to $472.95 apiece in afternoon trading today.
Intuitive’s cybersecurity incident comes just days after an Iranian-backed “hacktivist” group managed a “wiper attack” against Stryker, targeting data on Stryker’s Microsoft-based IT system and effectively wiping it out so it can’t be retrieved. The group said it undertook the cyberattack in response to U.S. and Israeli attacks on Iran, beginning on Feb. 28, 2026. (Read the thoughts of cybersecurity experts on the impact of this attack on medtech here.)
There is no indication at this time that the breach at Intuitive is related to the Stryker cyberattack or was executed for similar reasons. Intuitive said the incident has no impact on operations at this time and its robotic systems have their own security protocols, operating independently of its internal business network.
More about the cybersecurity incident at Intuitive
Intuitive said that the information accessed was obtained from an employee’s compromised access into its internal business administrative network. It includes some customer business and contact information, plus Intuitive employee and corporate data.
The company said that data was not obtained from its leading da Vinci surgical robotic system or the Ion endoluminal system. Those devices remain safe and operational.
Intuitive said that it has a segmented network infrastructure. Networks and infrastructure that support internal IT business applications, manufacturing operations and the da Vinci, Ion and other digital systems, are separate.
Hospital customer networks also remain separate from Intuitive networks, secured and managed by customers’ IT teams. As a result, Intuitive said those networks also remain unaffected.
The company said it took immediate action to assess and contain the incident, begin an investigation and review security protocols. It also reminded employees of online security training and processes. The company said it continues to communicate with customers and appropriate data privacy regulators.
“We take our responsibility to our employees, customers and the patients they serve seriously,” Intuitive said. “The privacy and security of all data with which we are entrusted is a vital part of that. We are committed to resolving and improving from this incident.”
Intuitive’s warning to surgeons and hospitals
In an email obtained by MassDevice, Intuitive warned surgeons and hospitals of the breach but said the data “does not include highly sensitive information such as bank account information, identifiable patient health information, or any customer or employee passwords.”
Intuitive said the data involved included names, titles and specialties of healthcare providers and administrators, plus emails, phone numbers and hospital facility addresses.
Intuitive said the exposed data also included da Vinci and Ion procedure type and length; Intuitive learning course completion; complaints reported to Intuitive’s Field Service Engineers; HCP engagement activities such as event attendance, mentoring or proctoring; and reimbursement Program impact documents (also known as Quantify the Impact).
Finally, for healthcare institutions, data exposed in the breach included commercial contract data extracts, automated business alignment meeting (ABAM) reports, and service work orders as of Jan. 18, 2026.
Intuitive has notified “law enforcement and other authorities,” the company told its customers in the email.
Medical Design & Outsourcing: Intuitive discloses executive pay with new leader at the helm
— Managing Editor Jim Hammerand contributed to this report.
