Artivion tells SEC cyberattack disrupted order and shipping processes

Organization
Artivion
Exploit
Ransomware
Industry
Medical Devices

Artivion, an Atlanta-area manufacturer of heart valves, aortic stent grafts and implantable human tissue, told the U.S. Securities and Exchange Commission on December 9, 2024 that it had been the target of a cyberattack involving the acquisition and encryption of files.

The company said it identified the incident on November 21, 2024 and took certain systems offline as a precaution while it investigated. In its Form 8-K it described disruptions to some order and shipping processes and to certain corporate operations, which it said had largely been mitigated by the time of the filing. Artivion said it continued to supply products and services to customers throughout.

Artivion did not say what data was taken or how many people were affected, and told regulators it was still evaluating any notification obligations. It engaged outside legal, cybersecurity and forensic advisers and said it was working to restore systems securely.

No ransomware group had claimed responsibility when TechCrunch and The Record reported the filing, and the company did not use the word ransomware itself. Both outlets characterised the incident as ransomware on the basis of the reference to files being acquired and encrypted. Artivion said cyber insurance would cover part of the cost but that it expected to incur further uninsured expenses, and that it did not currently anticipate a material financial impact, while cautioning that delays in recovery could change that.

Sources