Cybersecurity

A Series of Cyberattacks Hits Medical Device Companies Throughout 2026

The medical device sector experienced a series of cyberattacks throughout 2026 affecting Stryker, Medtronic, Abbott, Intuitive Surgical, and other companies. The effects ranged from disruptions to manufacturing and shipping to the exposure of patient and employee data, while some companies are still dealing with the aftermath of the incidents.

2026-08-21
4 min read
15 views
فريق تحرير certi.news
A Series of Cyberattacks Hits Medical Device Companies Throughout 2026

The medical device and technology sector experienced an escalating wave of cyberattacks throughout 2026, after several companies announced breaches that affected information technology systems and operational processes or exposed employee and patient data to unauthorized access. The companies include Stryker, Intuitive Surgical, Medtronic, Abbott, iRhythm, AdaptHealth, Cook Medical, Baylor Genetics, and UFP Technologies.

Stryker stands out as one of the cases with the greatest operational impact. The attack targeted the company’s global Microsoft environment on March 11, disrupting order-processing, manufacturing, and shipping systems for weeks. The company began restoring systems on March 17, then recovered most manufacturing operations on March 27, and announced on April 10 that it had returned to full operations, while warning of a material financial impact on first-quarter results. In May, CEO Kevin Lobo said the attack had had a significant effect on quarterly results, while the company maintained its full-year outlook. By July 31, Stryker was still working through a backlog of orders and dealing with a supply disruption linked to Inari Medical, while reporting in July that it continued to recover.

Data Exposure and Third-Party Breaches

Days after the Stryker incident, Intuitive Surgical announced that it had experienced a phishing incident that enabled an unauthorized party to access business information and customer communications, as well as employee and company data. Medtronic also reported on April 27 that its corporate information technology systems had experienced a data breach, then began notifying affected individuals on July 2, stating that it had no evidence that the accessed data had been posted online and did not expect a material impact on its business or financial results.

Abbott announced on July 17 that its cancer diagnostics business had experienced a cyberattack, following its $21 billion deal to acquire Exact Sciences, but it did not specify what type of information had been accessed. AdaptHealth said on July 7 that patient data had been stolen after an attacker accessed its systems through a social-engineering attack. On June 16, iRhythm disclosed that data had been stolen from third-party applications and said the attacker had demanded payment in exchange for not publishing the stolen data.

Latest Disclosures

Baylor Genetics and Cook Medical were the latest two companies to disclose incidents during August. Baylor Genetics said a third party may have accessed employee and patient information, including test results, Social Security numbers, and financial account details. In the case of Cook Medical, the incident resulted from a fraud scheme that enabled an outside entity to access some of the company’s systems, but the company said it had found no evidence that sensitive or protected data had been obtained and that its operations were functioning normally.

UFP Technologies also investigated an attack that affected company data in February, warning of short-term shipping delays while not expecting a material impact. These cases demonstrate that the impact is not limited to data confidentiality; in Stryker’s case, it extended to manufacturing, orders, and shipping, while other companies remained responsible for notifying affected individuals and assessing what data may have been exposed.

Why Does This Sequence Matter?

This wave does not provide evidence that all the incidents followed the same method, as the cases involved phishing, social engineering, breaches of corporate systems, and possible access through a third party. However, it illustrates the broadening range of risks in a sector whose companies rely on interconnected systems to manage manufacturing, distribution, and medical data. The effects of some incidents remain under assessment, meaning that the volume of affected information and the operational and financial impact vary from one company to another.

News source
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news