The Boston Scientific Hack
Two weeks ago, it became known that Boston Scientific, a major medical device manufacturer from the US that produces lab equipment and many devices used to treat heart conditions, was hacked. To this day, we do not know what happened at the company. Their press releases on the matter include no information whatsoever about what this âcybersecurity incidentâ actually was. The infamous US infosec services provider CrowdStrike is involved in investigating this attack, but hasnât given any details either. âCyber attackâ always sounds very sinister, but what this most often boils down to is an employee at the company getting duped into executing malware from somewhere in the cloud or brought in on a local storage device. In the more sophisticated attacks, the âsupply chainâ of some software they used is attacked, which often means some developer let his GitHub credentials get out and someone modified some software without anyone noticing.
Speaking of supply chains, this situation has apparently now led to hospitals desperately counting their catheters and stents because Boston Scientific doesnât know when they can ship more product. Arenât just-in-time supply chains great! đ„
But there are other serious consequences, as The Register reports:
Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. âNew remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,â the medtech firm said in a late Friday update.
This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patientsâ heart rhythms, the company added. Because of the cyberattack, ânew ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,â according to the update. The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the âinterrogateâ button, according to the company.
When will these people realise that our whole digital infrastructure is built on sand? Somebody executes some code or loses the credentials to a source code management system somewhere and, next thing you know, a whole company stops functioning, critical devices donât work anymore and hospitals are left without life-saving supplies. What happened to having emergency stocks of vital consumables? And why do we rely on software and protocols for critical medical devices that any sixteen-year-old with access to Claude Code can hack while theyâre in an Apex Legends match at the same time?
