Medjacking
Compromise of a networked medical device to use it as a foothold inside a hospital network or to manipulate clinical function.
Definition
Medjacking - short for medical device hijacking - was popularized by the security firm TrapX in its 2015 'MEDJACK' report and the 2016 'MEDJACK.2' and 2017 'MEDJACK.3' follow-ups, which documented attackers using out-of-date, unmanaged medical devices (blood gas analyzers, PACS workstations, infusion pumps, imaging consoles) as long-lived footholds inside hospital networks. Because medical devices often run unsupported operating systems, are exempt from routine IT patching, and live on flat clinical networks, they make ideal pivot points: an attacker who lands on a CT console can move laterally to EHRs, billing systems, or other devices while evading the endpoint detection tools deployed on standard IT assets. Medjacking can also describe direct manipulation of the device's clinical function - changing infusion pump flow rates, ventilator settings, or imaging parameters.What this means in practice
Mitigation is shared between the manufacturer and the healthcare delivery organization. Manufacturers reduce the attack surface (no default credentials, signed updates, least-privilege services, current OS, MDS2 disclosure, SBOM + VEX). Hospitals isolate clinical networks, maintain a real-time medical-device asset inventory, monitor for anomalous behavior, and follow the MITRE/FDA response playbook when devices are suspected of compromise.- •Shipping devices on long-out-of-support operating systems with no patching pathway.
- •Assuming the hospital network is a trusted environment - it is not.
- •Omitting an MDS2 form and SBOM, leaving hospital security teams unable to assess exposure.
- •Treating medjacking as an IT problem rather than a joint manufacturer/operator responsibility.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsUnauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Secrets - passwords, API keys, certificates - embedded in firmware or source code shipped on every device.
Umbrella term for hacking activity directed at medical devices, ranging from criminal attack to coordinated security research and patient-led modification.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
Primary references
4 sources- 1
TrapX MEDJACK.2 (2016) coverageVerifiedDark Readingdarkreading.com
- 2
Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook (MITRE, 2022)VerifiedMITREmitre.org
- 3
HHS HC3 Threat Briefs - Medical Device SecurityVerifiedHHS HC3hhs.gov
- 4
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
Inline markers like [1] jump to the matching reference above.