Skip to main content

Hackers can gain control of an insulin pump to inject a harmful dose into patients

When someone mentions hacking, generally it’s about teens breaking into the government’s network or the latest retail/service breach grabbing the personal data of millions of customers. Cracking into an individual’s pacemaker or insulin pump doesn’t really come to mind, but it’s possible and does happen. Johnson & Johnson is actually warning patients now about a security vulnerability found in one of its insulin pumps.

The good news is that the risk of using the affected Animas OneTouch Ping insulin pump is extremely low, so there’s no need for panic. The bad news is that if exploited, hackers could overdose diabetic patients with insulin. Right now there are only around 114,000 patients who actually use this specific medical device.

Recommended Videos

The vulnerability was discovered by researcher Jay Radcliffe of the cybersecurity firm Rapid7 Inc., who also happens to be diabetic. Radcliffe revealed his findings to Johnson & Johnson in April and published the news on the Rapid7 blog on September 28. Johnson & Johnson is just now getting around to informing patients through standard mail.

According to the product page, the Animas OneTouch Ping provides a Meter Remote so that patients can give themselves an insulin dose without having to touch the pump itself. In addition to checking blood sugar levels, the remote also allows users to remotely control pump functions, calculate how much bolus insulin is needed, and more.

The problem is that the wireless connection between the remote and the pump is not secure. They communicate in the 900MHz band using a proprietary Wi-Fi protocol based on “cleartext” communications. Without encryption, a hacker could potentially fake a Meter Remote connection and give a patient a harmful dose of insulin.

“Due to these insulin vulnerabilities, an adversary within sufficient proximity (which can depend on the radio transmission equipment being used) can remotely harm users of the system and potentially cause them to have hypoglycemic reaction, if he or she does not cancel the insulin delivery on the pump,” Radcliffe reports.

By gaining access to the connection between the pump and the remote, hackers can see the blood glucose results and the insulin dosage data. They gain access by sniffing the 5-packet “key” passed between the pump and remote, which remains the same each time the two devices are paired. This is supposedly to prevent other household remote controls from activating the pump.

“Communication between the pump and remote have no sequence numbers, timestamps, or other forms of defense against replay attacks,” Radcliffe added. “Because of this, attackers can capture remote transmissions and replay them later to perform an insulin bolus without special knowledge, which can potentially cause them to have hypoglycemic reaction.”

So what took so long for Johnson & Johnson to report the problem? The company had to reproduce Radcliffe’s finding before it warned patients of a potential problem. Brian Levy, chief medical officer with Johnson & Johnson’s diabetes unit, told Reuters they discovered a hacker could actually inject patients with a harmful dose of insulin from up to 25 feet away.

In a letter to patients, Johnson & Johnson said that OneTouch Ping owners who are worried about a potential hack can stop using the remote, or program the pump to limit the maximum dose of insulin. Users can also turn on the Vibrating Alert feature to warn of an insulin dose that is about to be initiated via the remote control. Animas provides a letter to patients here.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
AMD’s RDNA 4 may surprise us in more ways than one
AMD RX 7800 XT and RX 7700 XT graphics cards.

Thanks to all the leaks, I thought I knew what to expect with AMD's upcoming RDNA 4. It turns out I may have been wrong on more than one account.

The latest leaks reveal that AMD's upcoming best graphics card may not be called the RX 8800 XT, as most leakers predicted, but will instead be referred to as the  RX 9070 XT. In addition, the first leaked benchmark of the GPU gives us a glimpse into the kind of performance we can expect, which could turn out to be a bit of a letdown.

Read more
This futuristic mechanical keyboard will set you back an eye-watering $1,600
Hands typing on The Icebreaker keyboard.

I've complained plenty about how some of the best gaming keyboards are too expensive, from the Razer Black Widow V4 75% to the Wooting 80HE, but nothing comes remotely close to The Icebreaker. Announced nearly a year ago by Serene Industries, The Icebreaker is unlike any keyboard I've ever seen -- and it's priced accordingly at $1,600. Plus shipping, of course.

What could justify such an extravagant price? Aluminum, it turns out. The keyboard is constructed of one single block of 6061 aluminum in what Serene Industries calls an "unorthodox wedge form." As if that wasn't enough metal, the keycaps are also made of aluminum, and Serene says they include "about 800" micro-perforations that allow the LED backlight of the keyboard to shine through.

Read more
Google one-ups Microsoft by making chats easier to transfer
Google Spaces in Google Chat on a MacBook.

In a recent blog post, Google announced that it is making it easier for admins to migrate from Microsoft Teams to Google Chat to reduce downtime. Admins can easily do this within the Google Chat migration menu and connect to opposing Microsoft accounts to transfer Teams data.

Google gave step-by-step instructions for admins on how to transfer the messages. Admins need to connect to their Microsoft account and upload a CSV of the Teams from where they transfer the messages. From there, it requires just entering a starting date for messages to be migrated from Teams and clicking Star migration. Once it's complete, it'll make the migrated space, messages, and conversation data available to Google Workspace users.

Read more