Cook Medical confirms July employee-error breach, no patient data found

Cook Medical confirms a July intrusion began with an employee mistake and says no evidence shows patient data was accessed.

MedRisk Staff
By
2 Min Read

Cook Medical, the Indiana-based medical device maker, has confirmed that an employee inadvertently gave an outside party access to company systems during a July 2 incident. The disclosure, posted on the company’s website this week, is the device maker’s first official acknowledgment of the intrusion and arrived before an extortion gang later claimed the same episode.

The exposed material covers contact information for US and Canadian customers, records of communications with Cook employees held in the Salesforce platform, some internal business files, and employee names and company email addresses. Cook said its review found no evidence that sensitive or protected data was accessed, and that its products, manufacturing operations, and ability to serve patients were unaffected. The company said operations are running normally.

The statement preceded a ShinyHunters leak-site posting on August 14 that claimed 182 GB of customer, employee, and internal corporate data. Cook’s confirmation narrows the claimed haul to customer contact records and Salesforce communications rather than clinical information, a distinction that matters for the device maker’s hospital customers.

For health system security teams, the episode is a reminder that medical device vendors hold large customer relationship datasets that extortion gangs view as leverage. A single compromised employee account at a supplier can expose contracting details and account contacts that feed targeted phishing campaigns against provider organizations. Teams should ask device vendors what data their customer engagement platforms hold, whether Salesforce or similar SaaS instances are configured with restricted sharing, and what the vendor’s notification commitments are when those environments are touched.

Share This Article