Cook Medical disclosed on August 13 that an outside party reached its systems on July 2, after an employee was deceived into granting access. The company says it spotted and contained the access the same day it happened.

The material involved: contact information for U.S. and Canadian customers, employee names and company email addresses, Salesforce records of communications involving Cook staff, and internal business files. Cook says it has no evidence that sensitive or protected data was accessed, and that products, manufacturing, and its ability to serve patients were unaffected. It has not said how many people the notification covers.

What went out the door is a target list. Customer contacts paired with real internal email threads are the raw material for the next round of social engineering, and the six weeks between containment and disclosure are six weeks the recipients spent unaware. The CRM has become production infrastructure at device makers, and it is being attacked that way.