Robotic Surgery Giant Intuitive Discloses Cyberattack After Phishing Incident

Related

Iranian Cyber Group Handala Claims Cal Water Hack

What happened Iran-linked threat actor Handala claimed it hacked California...

British High School Sends Students Home After Cyberattack

What happened Great Marlow School in Buckinghamshire, England, sent the...

IBM and AT&T Accused of Covering Up Foreign Hacks

What happened IBM and AT&T were accused in a whistleblower...

Cyberattack Shuts Down Major Australian Sugar Mills

What happened A cyberattack disrupted sugar production in one of...

ServiceNow Discloses Security Incident Exposing Customer Data

What happened ServiceNow disclosed a security incident after attackers exploited...

Share

What happened

Medical device company Intuitive disclosed a cyberattack after a targeted phishing incident led to unauthorized access to certain internal business applications. The attackers leveraged an employee’s compromised credentials to access the company’s internal administrative network, exposing customer business and contact information, employee data, and corporate information. Intuitive said it activated incident response procedures upon discovery and secured the affected systems. The company emphasized that the breach did not impact its operations, and that its da Vinci surgical systems, Ion platforms, and manufacturing networks were not affected, as they operate on separate infrastructure from internal IT systems. 

Who is affected

Customers, employees, and business contacts whose information was stored in Intuitive’s internal systems are affected, while hospitals and systems using its surgical platforms were not impacted. 

Why CISOs should care

The incident highlights how phishing attacks targeting employee credentials can lead to unauthorized access to sensitive business systems, even when critical operational and product environments remain isolated. 

3 practical actions

  1. Strengthen phishing resistance. Monitor and prevent credential compromise through targeted phishing campaigns. 
  2. Segment critical systems. Maintain separation between business IT systems and operational or product environments. 
  3. Audit internal application access. Review access controls and monitor for unauthorized activity in administrative systems. 

For more coverage of major incidents and threat activity, explore our reporting on Cyberattacks.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.