Were you recently affected by a data breach?

Cook Medical Data Breach

Cook Medical disclosed a July 2026 cybersecurity incident after an employee was deceived by a social engineering attack, giving an outside party access to certain company systems. Customer contact records and internal business files may have been exposed.

Cook Medical
Date of Breach: July 2, 2026 (disclosed August 12, 2026)
CAU logo

Who was affected:

Clients of Cook Medical

Impacted Data:

Business contact information, Salesforce communication records, employee names, company email addresses, certain internal business files

Cook Medical, a privately held medical device manufacturer, has disclosed a cybersecurity incident that gave an outside party access to certain company systems. Companies that maintain customer contact records and internal business communications have a responsibility to safeguard that information from unauthorized access.

Cook Medical’s Data Breach Investigation

Cook Medical, headquartered in Bloomington, Indiana, manufactures medical devices used in vascular treatments, critical care, surgery, and urology. According to a notice posted on the company’s own newsroom page on August 12, 2026, a Cook Medical employee was deceived by a social engineering attack on July 2, 2026, and inadvertently gave an outside party access to certain company systems. Cook Medical stated that it identified the unauthorized access and contained it quickly on the same day the incident occurred.

Cook Medical said its investigation, conducted with the support of an outside cybersecurity firm, found that the information involved was primarily business contact information for U.S. and Canadian customers, records of communications with Cook employees maintained within the company’s Salesforce system, employee names and company email addresses, and certain internal business files accessed via SharePoint. The company stated that, based on its review to date, it has no evidence that sensitive or protected data was accessed, and that the incident has not affected its products, manufacturing, or its ability to serve patients and customers.

Social engineering attacks, in which an employee is manipulated into granting access rather than a system being technically hacked, have become an increasingly common entry point for cybercriminals. Rather than exploiting a software vulnerability, attackers rely on deception, often posing as a trusted vendor, colleague, or IT representative, to convince an employee to hand over credentials or approve access. This method of attack has affected numerous companies in the medical device and healthcare sector over the past year, as the industry continues to be a frequent target for cybercriminals seeking valuable business and customer data.

Even when a company reports no evidence that sensitive personal data was taken, exposure of business contact information and internal communications can still create real risk. Threat actors who obtain this type of information sometimes use it to craft convincing follow-up phishing attempts, impersonating a company representative or vendor to extract further sensitive information from customers or employees.

When Did This Breach Occur?

According to Cook Medical’s own disclosure, the incident occurred on July 2, 2026, when an employee was deceived by a social engineering attack. The company stated that it identified and contained the unauthorized access the same day. Cook Medical publicly disclosed the incident on August 12, 2026, several weeks after it was first identified and contained.

What Information Was Breached?

According to Cook Medical’s notice, the information potentially involved included business contact information for U.S. and Canadian customers, records of communications with Cook employees maintained in the company’s Salesforce platform, employee names and company email addresses, and certain internal business files accessed through SharePoint. Cook Medical stated it has no evidence that sensitive or protected data, such as Social Security numbers or financial account information, was accessed.

What You Can Do

If you are a Cook Medical customer or employee, or have corresponded with Cook Medical, consider taking the following precautions:

  • Be cautious of unexpected emails or calls claiming to be from Cook Medical, its employees, or affiliated vendors
  • Verify the identity of anyone requesting sensitive information through a known, independently verified contact method
  • Monitor your business and personal accounts for unfamiliar activity
  • Keep records of any suspicious communications referencing Cook Medical
  • Watch for any official follow-up communication from Cook Medical and follow the guidance it provides

File a Data Breach Lawsuit Against Cook Medical

Companies that maintain customer contact information and internal business communications have a responsibility to protect that data from unauthorized access. If you believe your information may have been compromised in this incident, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: March 11, 2026 (unauthorized access occurred between September 22, 2025 and March 11, 2026)
Date of Breach: On or about November 21, 2024
Date of Breach: December 2, 2025 to December 18, 2025 (Aesto Health vendor incident; notified June 26, 2026)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.