2026 Intuitive Surgical — intrusion via credential compromise (employee + customer business data)
Data compromised
Employee information, customer contact data, business records (per disclosure)
Technical writeup
Intuitive Surgical disclosed a cybersecurity incident on March 12, 2026. Attackers conducted a targeted phishing campaign to steal an employee's credentials, then used those credentials for unauthorized access to internal IT business applications—consistent with a broader intrusion into corporate systems rather than a single mailbox event. Exposed: customer business and contact information, employee and corporate records. Total number of affected individuals not publicly quantified. Da Vinci and Ion robotic surgical platforms were unaffected; hospital customer networks remained separate. No operational disruption or patient safety risk. Company activated incident response, secured affected applications, and notified regulators.
Root cause
Phishing / credential compromise leading to unauthorized system access