MedTech Dive tallied the year's damage on August 21: nine device makers and suppliers have disclosed cyber incidents since January. The list runs from UFP Technologies on February 27 to Baylor Genetics on August 18, and it spans manufacturers, a genetic testing laboratory, and a home equipment supplier.

The operational hit landed hardest at Stryker. The March 11 attack on its Microsoft environment disrupted ordering, shipping, and manufacturing for weeks, and the company called the first quarter impact material. CEO Kevin Lobo described the company as working through a backlog of orders.

The data losses concentrated at Medtronic. Its April intrusion led to notifications for 3,834,294 people, according to a filing with the Oregon attorney general, with names, dates of birth, Social Security numbers, and health information taken. Abbott disclosed an attack on its cancer diagnostics business on July 17. iRhythm said on June 16 that data was stolen from third-party applications, with the thief demanding payment to withhold publication.

Social engineering did much of the work. Cook Medical said a scam on one employee opened its systems on July 2. AdaptHealth traced its material July incident to a compromised third-party contractor session. Intuitive Surgical's March 13 disclosure started with phishing that reached employee and customer data.

Every intrusion on the list started in corporate IT, at a contractor, or with a deceived person. The exposure that matters this year sits in ERP systems, cloud applications, and third parties holding manufacturer credentials.

For product security teams the lesson is budgetary. Boards that funded premarket cybersecurity to satisfy FDA reviewers are watching material losses arrive through the corporate network. Segmentation between enterprise IT and manufacturing, and real scrutiny of contractor access, would have blunted most of this year's list.