The Containment Era is here. →Explore

Industry Category

Medical Equipment

Breach intelligence, attack campaigns, and threat reports targeting the Medical Equipment sector.

23 threat reports
Page 2 of 2

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Medical Equipment Threat Reports

Showing 1323 / 23 reports
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
Impact· HIGH

Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity

In March 2026, Stryker, a leading U.S. medical technology company, experienced a significant cyberattack attributed to the Iranian-linked hacking group Handala. The attackers claimed to have wiped over 200,000 systems and extracted 50 terabytes of critical data, leading to widespread operational disruptions across Stryker's global network. The attack was reportedly in retaliation for U.S. military actions in Iran. ([techradar.com](https://www.techradar.com/pro/security/an-unprecedented-blow-us-medtech-giant-stryker-suffers-global-outage-after-apparent-iranian-cyberattack?utm_source=openai)) This incident underscores the escalating cyber threats targeting critical healthcare infrastructure, highlighting the need for robust cybersecurity measures to protect sensitive data and ensure operational continuity in the face of nation-state-sponsored cyberattacks.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
Impact· CRITICAL

Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity

In March 2026, Stryker Corporation, a leading medical technology company, experienced a significant cyberattack attributed to the pro-Iranian hacktivist group Handala. The attackers claimed to have infiltrated Stryker's global network, exfiltrated 50 terabytes of sensitive data, and deployed wiper malware that erased data on over 200,000 systems, servers, and mobile devices. This attack led to widespread operational disruptions across Stryker's offices in 79 countries, severely impacting their ability to deliver medical products and services. ([investing.com](https://www.investing.com/news/stock-market-news/stryker-stock-falls-34-on-iranlinked-cyberattack-report-93CH-4554963?utm_source=openai)) This incident underscores the escalating threat posed by politically motivated cyberattacks targeting critical infrastructure sectors. Organizations in the healthcare and medical technology industries must enhance their cybersecurity measures to protect against such sophisticated and destructive attacks.

4 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
Impact· HIGH

Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity

In March 2026, Stryker Corporation, a leading U.S. medical technology company, experienced a significant cyberattack attributed to the pro-Palestinian hacktivist group Handala. The attackers reportedly utilized wiper malware to erase data from over 200,000 systems, including servers and mobile devices, leading to widespread operational disruptions across Stryker's global network. Employees in multiple countries, notably Ireland, were sent home as the company worked to contain the incident. Handala claimed the attack was retaliation for a missile strike that resulted in civilian casualties in Iran. This incident underscores the escalating trend of state-sponsored hacktivism targeting critical infrastructure and healthcare sectors. Organizations must enhance their cybersecurity measures to defend against sophisticated threats that aim not only to steal data but also to cause operational paralysis. The use of wiper malware highlights the need for robust data backup and recovery strategies to mitigate the impact of such destructive attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
UFP Technologies Cyberattack: A 2026 Data Theft Incident
Impact· MEDIUM

UFP Technologies Cyberattack: A 2026 Data Theft Incident

In February 2026, UFP Technologies, a leading medical device manufacturer, detected unauthorized access to its IT systems. The breach, identified on February 14, led to the theft and potential destruction of company data, impacting critical functions such as billing and label creation for customer deliveries. Immediate containment measures were implemented, and external cybersecurity experts were engaged to investigate and remediate the incident. The company has since restored access to the affected information and believes the threat actor has been removed from its systems. This incident underscores the escalating cyber threats targeting the healthcare sector, emphasizing the need for robust cybersecurity measures. Organizations must remain vigilant against sophisticated attacks that can disrupt operations and compromise sensitive data, highlighting the importance of proactive defense strategies and incident response planning.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Remote Hacking of WHILL Wheelchairs: Unsecured Bluetooth Puts Patient Safety at Risk
Impact· high

Remote Hacking of WHILL Wheelchairs: Unsecured Bluetooth Puts Patient Safety at Risk

In January 2026, cybersecurity researchers revealed significant security flaws in WHILL's electric wheelchairs, which allowed attackers within Bluetooth range to remotely pair with the device due to the absence of authentication controls. This flaw enabled malicious actors to take control of the wheelchair, manipulating its movement, speed settings, and configuration profiles without requiring any credentials or user interaction. CISA subsequently issued an advisory highlighting the risk, underscoring that such vulnerabilities could result in dangerous, unauthorized maneuvers or override critical safety restrictions, potentially jeopardizing user safety and privacy. This incident exemplifies the escalating risk represented by insecure IoT medical devices, especially those operating in public or semi-public settings. With threat actors increasingly targeting Bluetooth-enabled endpoints and the medical IoT landscape expanding rapidly, similar vulnerabilities are likely to be discovered in other transportation and assistive devices, putting regulatory and patient pressures on device manufacturers and healthcare providers.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Bluetooth Vulnerability Exposes WHILL Medical Wheelchairs
Impact· high

Critical Bluetooth Vulnerability Exposes WHILL Medical Wheelchairs

In December 2025, a critical IoT vulnerability (CVE-2025-14346) was disclosed in WHILL Model C2 Electric Wheelchairs and Model F Power Chairs, widely used in healthcare and public health sectors. Researchers discovered that these devices failed to enforce authentication for Bluetooth connections, enabling attackers within physical range to pair, take full control, issue movement commands, bypass safety restrictions, and alter configuration profiles with no user credentials required. The issue impacted all device versions, prompting emergency firmware mitigations from WHILL Inc. to restrict unauthorized access and manipulation. This incident underscores urgent risks associated with the growing attack surface in medical IoT and connected healthcare devices. Increasing reliance on wireless interfaces heightens exposure to exploitation, mandating stronger security and authentication measures as the threat landscape evolves.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Varex Imaging 2025: Privilege Escalation Vulnerability in Dental Imaging Software
Impact· medium

Varex Imaging 2025: Privilege Escalation Vulnerability in Dental Imaging Software

In December 2025, Varex Imaging disclosed a critical privilege escalation vulnerability (CVE-2024-22774, CVSS v4 8.5) affecting its Panoramic Dental Imaging Software (versions prior to 6.6.1.490). The flaw, caused by an uncontrolled search path element (CWE-427) in the SDK, could enable a standard user to gain NT Authority/SYSTEM privileges through DLL hijacking. While the vulnerability cannot be exploited remotely and no active exploitation has been reported, successful compromise could give attackers unrestricted system access in affected healthcare environments, with the potential to disrupt or manipulate sensitive imaging processes. This incident underscores the persistent risks of local privilege escalation vulnerabilities in healthcare software, especially where operational technology and patient systems converge. With increasing regulatory requirements and a rising focus on vertical-specific threats, incidents like this highlight the urgent need for robust patch management, secure software development practices, and vigilant network segmentation in healthcare environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows
Impact· high

Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows

In December 2025, a significant vulnerability was disclosed in the Grassroots DICOM (GDCM) library, a critical open-source imaging component widely used in healthcare systems worldwide. Identified as CVE-2025-11266, this out-of-bounds write vulnerability could be triggered by simply opening a specially-crafted DICOM file, potentially crashing affected applications such as SimpleITK and medInria. The flaw, present in versions GDCM 3.0.24 and earlier, allows for denial-of-service and partial data and integrity impacts, increasing operational risk for healthcare environments that rely on medical imaging interoperability. This incident highlights the persistent risk posed by vulnerable third-party libraries in regulated industries like healthcare. The rise in supply chain threats and software dependencies magnifies the urgency for organizations to maintain rigorous patching practices and robust segmentation, as attackers increasingly target widely-deployed open-source components to disrupt critical services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Mirion Medical 2025: Critical Vulnerabilities in NMIS BioDose Software Threaten Healthcare Security
Impact· high

Mirion Medical 2025: Critical Vulnerabilities in NMIS BioDose Software Threaten Healthcare Security

In December 2025, Mirion Medical disclosed multiple high-severity vulnerabilities affecting its EC2 Software NMIS BioDose product, versions prior to 23.0. These flaws—incorrect permission assignments, use of hard-coded credentials, and client-side authentication weaknesses—could be exploited by attackers to gain unauthorized access, elevate privileges, manipulate executables, steal sensitive medical data, or execute arbitrary code. Impacting the healthcare and public health sectors globally, these vulnerabilities pose critical operational and patient-data risks, especially in environments with networked installations and exposed Microsoft SQL Server databases. No active exploitation has yet been reported, but CISA urges urgent mitigation measures due to the vulnerabilities’ remote exploitability and low attack complexity. This incident highlights intensifying regulatory scrutiny on medical device security as threat actors increasingly target healthcare systems for sensitive patient data and intellectual property. The vulnerabilities in Mirion’s product underscore persistent gaps in authentication and privilege controls—a growing concern amid adoption of connected medical technologies and regulatory frameworks such as HIPAA and NIST.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical DoS Flaw in NIHON KOHDEN CNS-6201 Exposes Legacy Healthcare Systems
Impact· high

Critical DoS Flaw in NIHON KOHDEN CNS-6201 Exposes Legacy Healthcare Systems

In October 2025, a critical security vulnerability (CVE-2025-59668) was disclosed in the NIHON KOHDEN Central Monitor CNS-6201—a medical device used globally in healthcare environments. The flaw, a NULL pointer dereference triggered by a specially crafted UDP packet, allows attackers to remotely cause a denial-of-service (DoS) condition, resulting in abnormal termination of the monitoring process. Exploitation requires no authentication as long as the device is network-accessible. Affected models are end-of-support, placing healthcare environments at heightened risk if legacy equipment remains unsegmented or exposed. This exposure highlights continuing challenges associated with legacy medical devices, the urgency of network segmentation, and the importance of proactive vulnerability management in healthcare. Similar technique trends surrounding unauthenticated DoS vulnerabilities in critical infrastructure increase regulatory, patient-safety, and operational risk considerations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SimonMed Data Breach Exposes Over 1.2 Million Patient Records in 2024
Impact· high

SimonMed Data Breach Exposes Over 1.2 Million Patient Records in 2024

In January 2024, SimonMed Imaging, a major U.S. provider of diagnostic medical imaging, disclosed a data breach impacting over 1.2 million patients. The incident involved unauthorized access to internal systems, which allowed attackers to exfiltrate sensitive health and personal information—including names, birthdates, contact information, health insurance and medical data. The breach was discovered during routine security monitoring, after which SimonMed implemented containment measures and engaged third-party forensics. Regulatory authorities and affected individuals were promptly notified, with the company offering support and identity protection services where relevant. This breach underscores the persistent targeting of healthcare organizations due to the high value of medical data, as well as regulatory scrutiny around the protection of patient information. It highlights the growing sophistication of data exfiltration tactics, emphasizing the critical need for robust east-west security controls, encrypted traffic, and rapid anomaly detection within healthcare IT environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports