Dive Brief:
- Cook Medical said Wednesday that an employee inadvertently gave an outside party access to some company systems in a July 2 cybersecurity incident.
- Contact information for U.S. and Canadian customers, records of communications with Cook employees in the Salesforce platform, some internal business files, employee names and company email addresses were involved in the incident.
- However, Cook Medical said there was no impact on its products, manufacturing or ability to serve patients and customers, and operations are running normally. “Based on our review to date, we have no evidence that sensitive or protected data was accessed,” the company said in a post on its website.
Dive Insight:
Medtech companies have been targeted in a string of cybersecurity incidents this year. Over the past several months, iRhythm, Stryker, Abbott, AdaptHealth, Medtronic and Intuitive have dealt with different threats. In Stryker’s case, the cyberattack caused a global network disruption that affected its electronic ordering systems and caused shipping delays.
Cook Medical, a privately held medical device maker whose products are used in vascular treatments, critical care, surgery and urology, said the employee involved in the cyber incident was deceived by a social engineering attack. The Bloomington, Indiana-based company said its information security infrastructure, reporting and response teams worked as they should.
“We identified the unauthorized access and contained it quickly on the same day it occurred,” the company said.
Cook said it was notifying customers and employees and providing guidance on how to watch for further scams.