---
title: "Brainjacking, Definition | MedTech Terms"
description: "Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/brainjacking#term",
        "name": "Brainjacking",
        "alternateName": [
          "Neural device hijacking",
          "DBS hijacking"
        ],
        "description": "Brainjacking is the term coined by Oxford researchers Pugh, Pycroft, Maslen, Aziz, and Savulescu (2017) for the malicious, unauthorized control of implanted neurostimulation devices - most notably deep brain stimulators (DBS) used to treat Parkinson's disease, essential tremor, dystonia, depression, and OCD. Modern DBS systems are programmed wirelessly through a clinician programmer or, increasingly, a patient remote and a smartphone app communicating over Bluetooth or proprietary RF. An attacker who can reach those programming interfaces could alter stimulation amplitude, frequency, pulse width, or contact configuration, or simply switch the device off. Documented research-level attacks against neurostimulator programming protocols (Marin et al., 2016; Halperin et al., 2008 on ICDs as a precedent) show that the underlying class of attack - eavesdropping and command injection on poorly authenticated implant telemetry - is well within reach of motivated adversaries. Because the targeted organ is the brain, the harm potential ranges from subtle behavioral and motor effects to seizures, severe pain, or cognitive change.",
        "url": "https://medtechterms.com/terms/brainjacking",
        "termCode": "brainjacking",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/brainjacking#article",
        "headline": "Brainjacking",
        "description": "Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.",
        "url": "https://medtechterms.com/terms/brainjacking",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/brainjacking"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/brainjacking#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "Brainjacking, Neural device hijacking, DBS hijacking, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "Pugh et al., 'Brainjacking in deep brain stimulation and autonomy' (Ethics and Information Technology, 2018)",
            "url": "https://link.springer.com/article/10.1007/s10676-018-9466-4",
            "publisher": {
              "@type": "Organization",
              "name": "Springer"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "Pycroft et al., 'Brainjacking: Implant Security Issues in Invasive Neuromodulation' (World Neurosurgery, 2016)",
            "url": "https://www.sciencedirect.com/science/article/pii/S1878875016304065",
            "publisher": {
              "@type": "Organization",
              "name": "World Neurosurgery"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "Marin et al., 'On the (in)security of the latest generation implantable cardiac defibrillators' (ACSAC 2016)",
            "url": "https://dl.acm.org/doi/10.1145/2991079.2991094",
            "publisher": {
              "@type": "Organization",
              "name": "ACM"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "ICSMA-19-080-01 Medtronic Conexus Telemetry Protocol",
            "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-080-01",
            "publisher": {
              "@type": "Organization",
              "name": "CISA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA Cybersecurity Guidance (Sept 2023)",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/medjacking#term",
            "name": "Medjacking",
            "url": "https://medtechterms.com/terms/medjacking"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/section-524b#term",
            "name": "Section 524B of the FD&C Act",
            "alternateName": "524B",
            "url": "https://medtechterms.com/terms/section-524b"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/threat-modeling#term",
            "name": "Threat Modeling",
            "url": "https://medtechterms.com/terms/threat-modeling"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/secure-boot#term",
            "name": "Secure Boot",
            "url": "https://medtechterms.com/terms/secure-boot"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hardcoded-credentials#term",
            "name": "Hardcoded Credentials",
            "url": "https://medtechterms.com/terms/hardcoded-credentials"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Brainjacking",
            "item": "https://medtechterms.com/terms/brainjacking"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/brainjacking#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "Has a real patient ever been brainjacked?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "There is no publicly confirmed case of a patient harmed by a brainjacking attack in the wild. The term describes a credible, well-characterized threat class demonstrated in academic security research against implant telemetry, not a documented clinical incident. Regulators treat it as a risk to be designed against, not a hypothetical to be ignored."
            }
          },
          {
            "@type": "Question",
            "name": "Is brainjacking different from medjacking?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes. Medjacking is the broader category - hijacking any medical device, often network-connected hospital equipment - while brainjacking specifically targets implanted neurostimulators where the attacked organ is the brain. The mitigations overlap (authenticated sessions, encrypted links, signed firmware), but the harm model and human-factors expectations are different."
            }
          },
          {
            "@type": "Question",
            "name": "Which standards apply to neurostimulator cybersecurity?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "FDA's 2023 cybersecurity guidance, Section 524B of the FD&C Act, AAMI TIR57, IEC 81001-5-1, and ISO 14971 for risk management. For the programming link itself, IEEE 11073 and Bluetooth SIG security mode requirements are commonly referenced."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  Brainjacking

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

# Brainjacking

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

Brainjacking is the term coined by Oxford researchers Pugh, Pycroft, Maslen, Aziz, and Savulescu (2017) for the malicious, unauthorized control of implanted neurostimulation devices - most notably deep brain stimulators (DBS) used to treat Parkinson's disease, essential tremor, dystonia, depression, and OCD. Modern DBS systems are programmed wirelessly through a clinician programmer or, increasingly, a patient remote and a smartphone app communicating over Bluetooth or proprietary RF. An attacker who can reach those programming interfaces could alter stimulation amplitude, frequency, pulse width, or contact configuration, or simply switch the device off. Documented research-level attacks against neurostimulator programming protocols (Marin et al., 2016; Halperin et al., 2008 on ICDs as a precedent) show that the underlying class of attack - eavesdropping and command injection on poorly authenticated implant telemetry - is well within reach of motivated adversaries. Because the targeted organ is the brain, the harm potential ranges from subtle behavioral and motor effects to seizures, severe pain, or cognitive change. 

What the regulation says

FDA's 2023 premarket cybersecurity guidance and  [Section 524B of the FD&C Act](/terms/section-524b) apply directly to neurostimulators that meet the cyber-device definition - they have software, can connect (Bluetooth/RF/programmer link), and have technological characteristics vulnerable to threats. FDA expects a documented threat model that explicitly considers unauthorized modification of therapy parameters, authenticated and encrypted programming sessions, and a postmarket vulnerability monitoring plan. ICS-CERT/CISA medical-device advisories have addressed comparable implant telemetry weaknesses (e.g., Medtronic CareLink/Conexus advisories,  [ICSMA](/terms/ics-medical-advisory)\-19-080-01) and set the regulatory expectation that implant programming links be cryptographically authenticated. 

## What this means in practice

In practice, brainjacking risk is mitigated by treating the implant-to-programmer link as untrusted by default: mutual authentication using device-unique keys provisioned at manufacture, encrypted sessions, replay protection, bounded parameter ranges enforced in firmware, and clinician-confirmed parameter changes with audible/visible feedback. Patient remotes and companion apps should hold no fleet-wide secrets and should mediate, not replace, clinician authority over therapy boundaries. 

Common pitfalls

-   • Relying on the obscurity of a proprietary RF protocol instead of cryptographic authentication. 
-   • Allowing the patient remote or companion app to set stimulation parameters outside clinician-defined safe ranges. 
-   • Leaving the inductive or Bluetooth programming interface open whenever the device is in range, rather than requiring an explicit clinician-initiated session. 
-   • Treating brainjacking as a purely theoretical risk and omitting it from the device threat model. 

## Frequently asked questions

Has a real patient ever been brainjacked? 

There is no publicly confirmed case of a patient harmed by a brainjacking attack in the wild. The term describes a credible, well-characterized threat class demonstrated in academic security research against implant telemetry, not a documented clinical incident. Regulators treat it as a risk to be designed against, not a hypothetical to be ignored. 

Is brainjacking different from medjacking? 

Which standards apply to neurostimulator cybersecurity? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Hardcoded Credentials

Secrets - passwords, API keys, certificates - embedded in firmware or source code shipped on every device.





](/terms/hardcoded-credentials)[

Cybersecurity

Medjacking

Compromise of a networked medical device to use it as a foothold inside a hospital network or to manipulate clinical function.





](/terms/medjacking)[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)[

Cybersecurity

Section 524B of the FD&C Act(524B) 

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.





](/terms/section-524b)

### More in Cybersecurity

· Same category 

[

Cybersecurity

Secure Boot

A chain-of-trust mechanism that ensures only cryptographically signed firmware and software can run on a device.





](/terms/secure-boot)[

Cybersecurity

Threat Modeling

A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.





](/terms/threat-modeling)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

5 sources 

Link health:  5 verified · last checked 2026-06-20 

Springer· 1 World Neurosurgery· 1 ACM· 1 CISA· 1 FDA· 1 

1.  [1 
    
    Pugh et al., 'Brainjacking in deep brain stimulation and autonomy' (Ethics and Information Technology, 2018)
    
    Verified 
    
    Springer · link.springer.com 
    
    
    
    ](https://link.springer.com/article/10.1007/s10676-018-9466-4)
2.  [2 
    
    Pycroft et al., 'Brainjacking: Implant Security Issues in Invasive Neuromodulation' (World Neurosurgery, 2016)
    
    Verified 
    
    World Neurosurgery · sciencedirect.com 
    
    
    
    ](https://www.sciencedirect.com/science/article/pii/S1878875016304065)
3.  [3 
    
    Marin et al., 'On the (in)security of the latest generation implantable cardiac defibrillators' (ACSAC 2016)
    
    Verified 
    
    ACM · dl.acm.org 
    
    
    
    ](https://dl.acm.org/doi/10.1145/2991079.2991094)
4.  [4 
    
    ICSMA-19-080-01 Medtronic Conexus Telemetry Protocol
    
    Verified 
    
    CISA · cisa.gov 
    
    
    
    ](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-19-080-01)
5.  [5 
    
    FDA Cybersecurity Guidance (Sept 2023)
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Sources

5

Updated

5/5/2026

[Compare with another term](/compare?a=brainjacking)

Learn in 60 seconds

Card Lesson Quiz

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.

-   · Patient remotes and companion apps should hold no fleet-wide secrets and should mediate, not replace, clinician authority over therapy boundaries. 
-   · Modern DBS systems are programmed wirelessly through a clinician programmer or, increasingly, a patient remote and a smartphone app communicating over Bluetooth or proprietary RF. 
-   · An attacker who can reach those programming interfaces could alter stimulation amplitude, frequency, pulse width, or contact configuration, or simply switch the device off. 

Remember this

Watch out: Relying on the obscurity of a proprietary RF protocol instead of cryptographic authentication.

Related terms

-   [Medjacking ](/terms/medjacking)
-   [Section 524B of the FD&C Act(524B) ](/terms/section-524b)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Threat Modeling ](/terms/threat-modeling)
-   [Secure Boot ](/terms/secure-boot)
-   [Hardcoded Credentials ](/terms/hardcoded-credentials)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [Neuromodulation ](/terms/neuromodulation)
-   [Medhacking ](/terms/medhacking)
-   [Cardiac Rhythm Management(CRM) ](/terms/cardiac-rhythm-management)
-   [MITRE ATT&CK(ATT&CK) ](/terms/mitre-attack)
-   [Software Safety Case ](/terms/software-safety-case)
-   [Remote Patient Monitoring(RPM) ](/terms/remote-patient-monitoring)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)