Summary:
- Cybersecurity incidents are increasingly targeted towards organizations in the healthcare sector. Among other leading companies in medical devices, Cook Medical was recently impacted.
- On July 2, a Cook Medical employee was deceived by a social engineering attack and inadvertently gave an outside party access to certain company systems.
- Customer contact information was involved, along with records of customer communications with Cook employees in Salesforce, employee names and company email addresses, and certain internal business files accessed via SharePoint.
- Our information security infrastructure, reporting, and response teams were swift and worked exactly as they should.
- Cook operations are running normally, with no impact to our products, manufacturing, or our ability to serve patients and customers.
Cybercriminals have increasingly targeted organizations across the healthcare sector. Cook Medical was recently affected, along with other leading medical device companies.
On July 2, a Cook Medical employee was deceived by a social engineering attack and inadvertently gave an outside party access to certain company systems. We identified the unauthorized access and contained it quickly on the same day it occurred.
Our investigation, conducted with the support of an outside cybersecurity firm, found that the information involved was primarily:
- Business contact information for US and Canadian customers
- Records of communications with Cook employees within our Salesforce system
- Employee names and company email addresses
- Certain internal business files that were accessed via SharePoint
Based on our review to date, we have no evidence that sensitive or protected data was accessed.
We are notifying customers and employees and providing guidance on how to watch for follow-on scams, which is the most likely real-world risk from this type of incident.
This incident has not affected our products, manufacturing, or our ability to serve patients and customers.
We take this seriously, and we will continue to update customers and employees as our investigation progresses.