Skip to main content

Hackers can gain control of an insulin pump to inject a harmful dose into patients

When someone mentions hacking, generally it’s about teens breaking into the government’s network or the latest retail/service breach grabbing the personal data of millions of customers. Cracking into an individual’s pacemaker or insulin pump doesn’t really come to mind, but it’s possible and does happen. Johnson & Johnson is actually warning patients now about a security vulnerability found in one of its insulin pumps.

The good news is that the risk of using the affected Animas OneTouch Ping insulin pump is extremely low, so there’s no need for panic. The bad news is that if exploited, hackers could overdose diabetic patients with insulin. Right now there are only around 114,000 patients who actually use this specific medical device.

The vulnerability was discovered by researcher Jay Radcliffe of the cybersecurity firm Rapid7 Inc., who also happens to be diabetic. Radcliffe revealed his findings to Johnson & Johnson in April and published the news on the Rapid7 blog on September 28. Johnson & Johnson is just now getting around to informing patients through standard mail.

According to the product page, the Animas OneTouch Ping provides a Meter Remote so that patients can give themselves an insulin dose without having to touch the pump itself. In addition to checking blood sugar levels, the remote also allows users to remotely control pump functions, calculate how much bolus insulin is needed, and more.

The problem is that the wireless connection between the remote and the pump is not secure. They communicate in the 900MHz band using a proprietary Wi-Fi protocol based on “cleartext” communications. Without encryption, a hacker could potentially fake a Meter Remote connection and give a patient a harmful dose of insulin.

“Due to these insulin vulnerabilities, an adversary within sufficient proximity (which can depend on the radio transmission equipment being used) can remotely harm users of the system and potentially cause them to have hypoglycemic reaction, if he or she does not cancel the insulin delivery on the pump,” Radcliffe reports.

By gaining access to the connection between the pump and the remote, hackers can see the blood glucose results and the insulin dosage data. They gain access by sniffing the 5-packet “key” passed between the pump and remote, which remains the same each time the two devices are paired. This is supposedly to prevent other household remote controls from activating the pump.

“Communication between the pump and remote have no sequence numbers, timestamps, or other forms of defense against replay attacks,” Radcliffe added. “Because of this, attackers can capture remote transmissions and replay them later to perform an insulin bolus without special knowledge, which can potentially cause them to have hypoglycemic reaction.”

So what took so long for Johnson & Johnson to report the problem? The company had to reproduce Radcliffe’s finding before it warned patients of a potential problem. Brian Levy, chief medical officer with Johnson & Johnson’s diabetes unit, told Reuters they discovered a hacker could actually inject patients with a harmful dose of insulin from up to 25 feet away.

In a letter to patients, Johnson & Johnson said that OneTouch Ping owners who are worried about a potential hack can stop using the remote, or program the pump to limit the maximum dose of insulin. Users can also turn on the Vibrating Alert feature to warn of an insulin dose that is about to be initiated via the remote control. Animas provides a letter to patients here.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Best 3D printer deals: Start printing at home for $159
best 3d printer deals featured image

There's a lot of stuff you can potentially do within the 3D printing space, whether it's printing some cool minis for your D&D game or turning into a fully-fledged business, especially with the new and faster 3D printers out there. But you don't have to buy the best 3D printers on the market to get started, and a lot of entry-level printers have gone a long way to the point where they are very fun and easy to use. Of course, we aren't at the point where you can 3D print a cheesecake, but there are probably quite a few companies working on making that a possibility.
For now, though, there are a ton of great 3D printer deals you can take advantage of, which is why we've gone out and found some of our favorites and compiled them for you below. Amazon deals, Best Buy deals and Walmart deals are the most common retailers to find discounted 3D printers, but we've found a few deals direct from the manufacturers.

Creality Ender-2 Pro — $159, was $179

Read more
Best external hard drive deals: Portable SSDs, game drives & more
A man uses a WD My Passport external hard drive alongside his laptop.

While a lot of content has gone digital these days, including things like cloud storage services allowing us to store our files online, having a physical form of storage to keep with you is important. In a similar vein, it's frustrating that some of the best phones on the market don't even come with a lot of internal space, while most laptop deals you take advantage of also likely will land you with less than 1TB of storage. To that end, we've gone out and collected some of our favorite external hard drive deals we could find and collected them below, and some of them are even the best external hard drives on the market. If you decide internal storage will fit your needs better, check out SSD deals, or PS5 SSD deals for your gaming needs.
Seagate FireCuda Gaming 2TB -- $60, was $100

If you have a gaming setup that's full of RGB and you want to add a little bit to it while still extending your hard drive space, then you should absolutely grab this 2TB Seagate FireCuda Gaming. It has a customizable LED under the bottom lip of the hard drive, and it even comes with the latest 3.2 gen USB standard, so you can game off of it directly on your PC or older console. While you hopefully won't need it, it also comes with 3-years of data recovery service, which is a nice plus at this price bracket.

Read more
Best GPU deals: MSI, XFX, EVGA
An AMD graphics card in an external GPU enclosure.

Getting into gaming can be an expensive hobby, especially if you're building a new PC from scratch and want to get the best GPU that you possibly can. Unfortunately, in the past couple of years, GPU prices have skyrocketed, especially for RTX 40-series cards, and they don't look to be coming down any time soon, whether you're going for AMD or Nvidia. Luckily, there are still quite a lot of great deals you can take advantage of that will let you snag a card for a great price, and we've collected some of our favorites below. If you're building your own PC from scratch, check out SSD deals and RAM deals as well. That said, if you'd rather go for something that's already been put together, check out these gaming PC deals instead.
XFX SPEEDSTER SWFT210 AMD Radeon RX 6600 Core 8GB GDDR6 -- $230, was $280

XFX is a pretty well-known brand that makes AMD Radeon GPUs, so you're getting a good-quality device right out of the gate. It has an impressive 8GB GDDR6, at least for this price bracket, and will give you a bit longer life out of it when games start using up a lot more VRAM, even at lower graphical settings. While the base clock runs at 2.0 GHz, the boosted clock speed is 2.5 GHz which is pretty good, and the whole thing is unlocked, so you could theoretically boost it higher if you have the right cooling. This RTX 6600 can support resolutions up to 8K, but really, this is an ideal 1080p gaming GPU.

Read more