FDA recalls around 465,000 St. Jude Medical pacemaker models in US, many implanted in patients, for firmware patching of vulnerabilities; OTA fix not an option
Abbott Laboratories' Accent/Anthem … Kate Conger / Gizmodo : If Grandma Has a Pacemaker, Please Take Her in For a Firmware Update Lisa Vaas / Naked Security : Pacemaker gets firmware update - go and see your doctor Dreyer Smit / Neowin : The FDA recalls 465,000 pacemakers which are at risk from possible hacking attacks Ionut Arghire / SecurityWeek : St. Jude Medical Recalls 465,000 Pacemakers Over Security Vulnerabilities Duncan Riley / SiliconANGLE : FDA issues unprecedented recall for 465,000 hackable pacemakers Selena Larson / CNNMoney : Over half a million hackable pacemakers can now be fixed Chris Morris / Fortune : FDA Recalls 465,000 Pacemakers on Hacking Fears Natt Garun / The Verge : Almost half a million pacemakers need a firmware update to avoid getting hacked Rishabh Jain / International Business Times : Half A Million Pacemakers At Risk Of Hacking, Security Protocols Immediately Needed Rob Thubron / TechSpot : FDA tells 465,000 pacemaker users to visit doctor for firmware patch Chris Merriman / Inquirer : FDA recalls 465,000 pacemakers for firmware update Zeljka Zorz / Help Net Security : Patients with St. Jude pacemakers called in for firmware update Rob Price / Business Insider : Nearly half a million peoples' pacemakers are at risk of being hacked Waqas / HackRead : 465k Pacemakers vulnerable; users must visit doctors for fix Richard Staynings / Cisco Blog : FDA announces first-ever recall of a medical device due to cyber risk Ian Sherr / CNET : Nearly a half million pacemakers could get hacked BBC : Cyber-flaw affects 745,000 pacemakers DataBreaches.net : At risk of hack, 465,000 pacemakers are recalled for software update Evan Sweeney / FierceHealthcare : FDA announces firmware update to resolve cybersecurity vulnerabilities in Abbott pacemakers Dan Goodin / Ars Technica : 465k patients told to visit doctor to patch critical pacemaker vulnerability US Food and Drug Administration : Medical Specialties — Cardiac Electrophysiology, Cardiology … Tweets: Internet of S**t / @internetofs**t : When you put a device in your body to run your heart you don't expect software updates let alone the ability to be hacked https://twitter.com/...
Context & Ripple Effects
This recall is the endpoint of a two-year arc: security startup MedSec first surfaced vulnerabilities in St. Jude's cardiac devices in 2016 via an unusual deal with an investment firm to short the manufacturer's stock, and the FDA followed in January by warning that St. Jude's Merlin@home transmitters used to monitor pacemakers were hackable. Now the regulator has escalated from advisory to formal recall of roughly 465,000 Accent/Anthem pacemakers, many already implanted.
What makes it unprecedented is the remediation model: with no over-the-air option, each patient must see a doctor for a firmware patch — a logistics burden that immediately ran into resistance, as some doctors grew wary of applying the update over malfunction risk.
First-order effects
- Hundreds of thousands of implanted-device patients must schedule clinic visits for firmware patches, converting a software fix into a physical-world appointment burden on cardiology practices.
- Abbott, which acquired St. Jude, bears the cost and reputational weight of an FDA-issued recall on devices it now owns — its second regulatory action on this device line within the year.
Second-order effects
- Doctor hesitancy over malfunction risk slows patch adoption, leaving the installed base exposed longer and pressuring Abbott to prove the update's safety before compliance scales.
- Rival manufacturers face the same exposure: within two years DHS flagged vulnerabilities in about 750,000 Medtronic implantable defibrillators worldwide, showing the problem is category-wide rather than one vendor's defect.
Third-order effects
- Implantable-device security is being forced toward design-time requirements — secure update paths and pre-market review — because retrofitting hundreds of thousands of implanted units without OTA capability is prohibitively slow and risky.
- Regulators are establishing a template for handling cybersecurity defects in life-sustaining hardware: coordinated disclosure, then recall-level mandates when remote patching is unavailable, a playbook later applied to other manufacturers.
The trend: Connected implantable medical devices are moving from unpatched-by-design to regulated, mandatory security remediation, with the FDA's recall cadence setting the industry's pace.