Data Breaches

Medical Device Maker UFP Technologies Hit by Cyberattack

UFP Technologies appears to have been targeted in a ransomware attack that involved data theft and file-encrypting malware.

UFP data breach

Medical device manufacturer UFP Technologies on Tuesday disclosed a cybersecurity incident that involved the theft of files and the disruption of some IT systems.

UFP Technologies is a Massachusetts-based contract manufacturer and designer of custom-engineered solutions, specializing in medical devices, sterile packaging, and highly specialized components for healthcare and other industries.

The company revealed in an 8-K filing with the SEC that it detected an IT systems intrusion on February 14. 

The incident has disrupted many systems, including those used for billing and the creation of customer delivery labels.

“Certain Company or Company-related data appear to have been stolen or destroyed,” UFP said. “As a result of the Company’s contingency plans and data backup systems, the Company implemented planned solutions for the issues posed by the incident. The Company’s operations have continued since the detection of the cybersecurity incident in all material respects.”

Its investigation found that attackers exfiltrated files, but UFP is still working to determine what types of information have been compromised and whether it includes personal information.

Advertisement. Scroll to continue reading.

The company said the cyberattack has not had a material impact and expects many of the costs for containing and investigating the incident to be covered by insurance.

UFP’s brief description of the incident indicates that the company has been targeted in a ransomware attack that involved both data theft and the deployment of file-encrypting malware.

However, at the time of writing no known ransomware group appears to have taken credit for an attack on UFP. 

Related: US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

Related: Mississippi Hospital System Closes All Clinics After Ransomware Attack

Related: Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site

Related Content

Data Breaches

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.

Data Breaches

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

Data Breaches

Using social engineering, hackers compromised employee accounts with access to personal and health information.

Data Breaches

Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.

Data Breaches

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.

Data Breaches

Targeting production infrastructure, the attack compromised internal datasets and service credentials.

Ransomware

The company has yet to determine the full scope, nature, and impact of the incident.

Cybercrime

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version