Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Medical Device Maker UFP Technologies Hit by Cyberattack

UFP Technologies appears to have been targeted in a ransomware attack that involved data theft and file-encrypting malware.

UFP data breach

Medical device manufacturer UFP Technologies on Tuesday disclosed a cybersecurity incident that involved the theft of files and the disruption of some IT systems.

UFP Technologies is a Massachusetts-based contract manufacturer and designer of custom-engineered solutions, specializing in medical devices, sterile packaging, and highly specialized components for healthcare and other industries.

The company revealed in an 8-K filing with the SEC that it detected an IT systems intrusion on February 14. 

The incident has disrupted many systems, including those used for billing and the creation of customer delivery labels.

“Certain Company or Company-related data appear to have been stolen or destroyed,” UFP said. “As a result of the Company’s contingency plans and data backup systems, the Company implemented planned solutions for the issues posed by the incident. The Company’s operations have continued since the detection of the cybersecurity incident in all material respects.”

Its investigation found that attackers exfiltrated files, but UFP is still working to determine what types of information have been compromised and whether it includes personal information.

Advertisement. Scroll to continue reading.

The company said the cyberattack has not had a material impact and expects many of the costs for containing and investigating the incident to be covered by insurance.

UFP’s brief description of the incident indicates that the company has been targeted in a ransomware attack that involved both data theft and the deployment of file-encrypting malware.

However, at the time of writing no known ransomware group appears to have taken credit for an attack on UFP. 

Related: US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

Related: Mississippi Hospital System Closes All Clinics After Ransomware Attack

Related: Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.