
Intuitive Surgical disclosed a cybersecurity incident in which hackers used a phishing attack to gain unauthorized access to the company’s internal administrative network and obtain customer and employee data.
The surgical robotics developer confirmed that attackers obtained an employee’s credentials through a phishing campaign and used the compromised access to enter the company’s internal business administrative systems. The unauthorized party accessed customer business and contact information as well as employee and corporate records.
The company published a statement about the incident on March 12. Once the breach was discovered, Intuitive activated its incident response procedures and secured the affected applications.
The company said it took immediate steps to assess and contain the intrusion, initiate an investigation, review security protocols and remind employees about cybersecurity training and online security practices. Intuitive did not disclose when the intrusion was first detected.
The company stated that its surgical robotics platforms were not impacted. The da Vinci Surgical System, the Ion Endoluminal System and related digital platforms remain operational and secure.
Intuitive explained that its network infrastructure is segmented. Systems supporting internal IT business applications operate on separate networks from those used for manufacturing operations and the da Vinci and Ion robotic platforms.
Hospital customer networks were also unaffected. Those systems remain separate from Intuitive’s networks and are managed by hospitals’ own IT teams.
The company said the incident did not disrupt operations or the support it provides to healthcare providers. Intuitive added that its robotic surgical systems operate independently from its internal business network and rely on their own security protocols.
The disclosure comes shortly after a cybersecurity incident involving Stryker Corporation, a global medical device manufacturer. The company experienced a cyberattack that disrupted its Microsoft network environment and affected order processing, shipping and manufacturing activities.
Security researchers linked the Stryker incident to an Iran-connected threat actor known as Handala. The group claimed responsibility for wiping thousands of servers and mobile devices and for extracting approximately 50 terabytes of data. The extent of any customer data exposure in that incident remains unclear.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543