Intuitive Surgical disclosed a phishing incident that let an unauthorized third party into customer business and contact information, plus employee and corporate data. The surgical robotics company did not attach numbers to the exposure.
Nothing in the disclosure touches the robots. The timing is what stands out, since it landed the same week Stryker was fighting a wiper, which put two of the biggest names in surgery into incident response at once. Phishing keeps working, including on companies with mature security programs.
Questions & Answers
What did the Intuitive Surgical phishing incident expose?
Customer business and contact information plus employee and corporate data, accessed by an unauthorized third party. The company did not attach numbers, and nothing in the disclosure touches the surgical robots.
What is notable about the timing of the Intuitive disclosure?
It landed the same week Stryker was fighting a wiper attack, putting two of the biggest names in surgery into incident response at once. Phishing keeps working against companies with mature programs.