In 2008, a team of computer scientists and a cardiologist did something that should have been unnecessary. They bought a commercially available implantable cardioverter defibrillator—a device wired into a patient’s heart, capable of delivering a shock to stop a fatal rhythm—and set out to break into it. Using an oscilloscope and a low-cost, general-purpose software radio, they reverse-engineered the wireless protocol the device used to talk to its programmer. They did not stop at listening. They demonstrated that they could read the patient’s name, diagnosis, and real-time electrocardiogram from the clear, unencrypted radio traffic; that they could disable the therapies the device was programmed to deliver; and that they could command it to issue a shock that could induce ventricular fibrillation (Halperin et al., IEEE Symposium on Security and Privacy, 2008).
Their point was not that any patient had been attacked. No such case was then known, and none of the researchers suggested otherwise. Their point was that the security model of the device was a remote control—anyone holding the right one could change the settings—and that as implants grew more capable and more connected, a wireless breach would stop being a data problem and become a physical one. The paper won a best-paper award, and in 2019 the IEEE Computer Society recognized the team with a Test of Time award for founding an entire field.
That field now has a name and a definition. In 2009, the same research group proposed “neurosecurity”: the protection of the confidentiality, integrity, and availability of neural devices—with the explicit goal of preserving “the safety of a person’s neural mechanisms, neural computation, and free will” (Denning, Matsuoka & Kohno, Neurosurgical Focus, 2009). The definition is worth reading closely, because it puts something unusual into a security goal. Confidentiality, integrity, and availability are the standard triad of computer security, and they applied to a laptop. Here they are attached to a person’s capacity to think.
Why an implanted device is a different kind of target
A thermostat, a laptop, and a pacemaker can all run embedded software and speak over a radio. The consequences of a breach are not comparable, and the difference is structural rather than a matter of degree.
When a laptop is compromised, the attacker gains access to data and computation. When an implanted medical device is compromised, the attacker gains access to the boundary between computation and a body. The distinction matters because the effect of a command does not stay inside the device. Changing a stimulation parameter changes how a heart beats, how a tremor quiets, how a mood lifts or falls. The attack surface and the patient are physically continuous. That is why the U.S. Food and Drug Administration now treats cybersecurity as a component of device safety rather than as an information-technology side issue, and why its premarket guidance asks manufacturers to build a “secure product development framework” and to meet the statutory “cyber device” requirements of the Food, Drug, and Cosmetic Act—to monitor, patch, and coordinate disclosure over the device’s whole lifecycle (FDA, 2026).
The second difference is that the affected person is often least able to evaluate the threat. It is reasonable to ask a computer user to click through a security dialog. It is not reasonable to ask someone mid-seizure, or mid-tremor, or in a depressive episode, to make a rapid meta-decision about the firmware of their own brain. Denning and her coauthors made exactly this point: the consequence of a neurosecurity breach is different from that of an ordinary computer breach because human health and agency are at stake, and “changes made by hackers could have irreversible effects on human performance and cognition.”
Third, the devices are constrained. An implant runs on a battery that must last years, and every cryptographic operation, every authenticated handshake, every wake-up costs energy. The security literature on medical implants keeps returning to this tension: the strongest available defenses are the ones you cannot afford. Halperin’s team’s most elegant contribution was to sidestep the problem entirely, building prototypes that drew no power from the device battery at all—harvesting energy from the incoming radio signal to sound an audible warning or to authenticate a programmer request. “Zero-power” security was a design insight, not just a patch.
What the attacks actually look like
The most useful taxonomy of neuro-implant attacks comes not from a security conference but from a neurosurgery journal. In 2016, Laurie Pycroft and colleagues at Oxford published a review of what they called “brainjacking”: malicious control of brain implants, focused on deep brain stimulation, the therapy that delivers electrical pulses to deep structures to treat Parkinson’s disease, tremor, and other conditions (Pycroft et al., World Neurosurgery, 2016).
They split attacks into two classes. Blind attacks require no knowledge of the specific patient. They include cessation of stimulation, which for some patients means the return of disabling symptoms; deliberate battery drain, converting a years-long lifespan into a much shorter one; induction of tissue damage; and theft of information. Targeted attacks require patient-specific knowledge and are correspondingly more chilling: impairment of motor function, alteration of impulse control, modification of emotion or affect, induction of pain, and modulation of the brain’s reward system.
It is important to be precise about the epistemic status of these scenarios. Cessation, battery drain, and data theft are not hypothetical in the same way the others are; they follow directly from the access that has been demonstrated in cardiac devices and from the fact that stimulation settings are stored and remotely adjustable. The targeted manipulations are plausible engineering—they extrapolate from what deep brain stimulation is documented to do when its parameters are changed deliberately by a clinician, and they ask what happens when the same change is made by someone with hostile intent. They are not reports of events. Pycroft’s team framed them as a risk assessment, and their conclusion was institutional rather than alarmist: researchers, clinicians, manufacturers, and regulators should cooperate to minimize the risk before it materializes.
That framing echoes the whole field’s founding argument. Denning and coauthors drew an explicit parallel to the early internet, which was designed by people who all shared a purpose and did not imagine adversaries, and which proved almost impossible to retrofit with security after the fact. They argued that neural devices were at that same early stage, and that the moment to design security in is before the devices are ubiquitous, not after. They also anticipated a subtler hazard specific to the brain: because neural tissue is plastic, an attacker’s interference might not end when the attack does. Altering stimulation could, in principle, leave a durable change in how a circuit behaves—the brain adapting to an input that should never have arrived.
The record in the wider device population
If neural implants themselves have no public attack history, the broader family of connected medical devices has a substantial one, and it is the best available evidence for what neurosecurity will eventually have to defend against.
The cardiac case is the fullest. Halperin’s 2008 demonstration was followed by years of security research and, eventually, by formal advisories. In 2017, the U.S. cybersecurity agency published an advisory for Abbott (formerly St. Jude Medical) pacemakers: an authentication weakness that could let a nearby attacker issue unauthorized commands over radio frequency; an unlimited “RF wake-up” that could be used to drain the battery; and, in some models, unencrypted transmission of patient data (CISA, ICSMA-17-241-01). A firmware update was developed, and the advisory is candid about the trade-off that followed: applying a firmware update to an implanted device carries its own risks, including loss of settings, backup-mode entry, or, in the worst case, loss of device function. The clinician and patient were left to weigh a cybersecurity risk against an update risk.
Insulin pumps show the same pattern with a different endpoint. The National Vulnerability Database records that a range of Medtronic MiniMed 508 and Paradigm pumps used a wireless protocol that “does not properly implement authentication or authorization,” letting an attacker with adjacent access inject, replay, modify, or intercept data and, in principle, “change pump settings and control insulin delivery” (NVD, CVE-2019-10964). A related Medtronic MiniMed 600 Series issue was classified as a Class 2 recall over the risk of unauthorized remote bolus delivery. In 2020, the FDA warned that the “SweynTooth” set of Bluetooth Low Energy vulnerabilities—affecting microchips used across the industry—could let an unauthorized user crash a device, stop it working, or reach functions reserved for the authorized user, in products including pacemakers, glucose monitors, stimulators, and insulin pumps (FDA, 2020).
The most recent example is also the most instructive, because it involves a device that keeps a heart pumping. Abiomed sent customers a correction notice for its Automated Impella Controller after identifying cybersecurity vulnerabilities with “unacceptable residual risk” related to network and physical access. If exploited, the FDA’s alert says, the flaw could affect essential performance and “result in loss of device control or unexpected pump stop”—a life-threatening event. The mitigation was blunt and telling: take the device off the network. Its network capability could be disabled, and the controller could keep being used as intended once disconnected (FDA, 2025). The agency noted that no cyberattacks or patient harm had been reported in connection with the vulnerability.
Two lessons follow. The first is that the failure mode of a compromised medical device is often loss of function rather than malicious control—availability, one leg of the security triad, is where much of the real-world harm concentrates. The second is that the honest response to unresolvable risk is sometimes to remove connectivity entirely, which is only acceptable when the connectivity was a convenience rather than a necessity. For a device whose whole promise is remote monitoring and adaptive therapy, that escape hatch may not exist.
Putting neural devices in the same frame
The reason to dwell on cardiac and insulin devices is that neural implants are converging on exactly the architecture that made those devices vulnerable: wireless communication for convenience, remote adjustment for clinical flexibility, and, increasingly, closed-loop operation in which the device senses and acts on its own.
Deep brain stimulators already fit this description. They are implanted, they are wirelessly programmed, they store settings that change how a person moves and feels, and newer generations adjust their output based on the patient’s own brain signals. That last capability is the medical advance that makes the security question sharper rather than softer. A closed-loop device is, by construction, a system that reads a person’s neural state and writes to it. The better it is at reading and writing, the more precise and gentler the therapy; the same precision is what would make a hostile command more consequential.
A useful way to organize the risks is to separate what each attack violates. Some attacks target confidentiality: eavesdropping on neural telemetry, or on the communication between an implant and its programmer, to learn something about the patient. This is the least exotic risk and, given the clear-text transmissions documented in cardiac devices, among the most realistic. Some target integrity: changing settings, disabling therapy, or—in the speculative end—modulating mood, impulse control, or reward. And some target availability: draining a battery, crashing firmware, or causing a device to stop working at the moment it is needed.
These are not academic distinctions; they map onto different defenses. Confidentiality is addressed by encryption and by not broadcasting patient data. Integrity is addressed by authentication and authorization, by signed firmware, and by the principle that commands with bodily consequences require a stronger proof of authority than commands that merely read. Availability is addressed by rate limits, by refusing unbounded wake-up requests, and, ultimately, by the physical fallback: a way for the patient or clinician to keep the therapy working when the network fails.
The hard trade-offs
It would be dishonest to present these defenses as free. Each carries a cost, and the costs fall on the patient.
Authentication costs power and, if the key is lost, can lock a clinician out of a device that a patient depends on. Emergency access is the classic dilemma: a paramedic or an emergency physician may need to interrogate or adjust an implant in a situation where the patient cannot supply a credential. A system that is perfectly authenticated against attackers may also be authenticated against rescuers. This is why the cardiac-security literature keeps returning to human-centric designs, in which the patient themselves—by a physical gesture or a perceptible signal—participates in authorizing access.
Patching costs trust. An implant that can be updated can also be updated badly. The Abbott advisory is explicit that firmware updates can bring their own malfunctions, and that for pacing-dependent patients the update should happen where temporary pacing and a device change are readily available. A security posture that makes remote updates easy improves the system’s ability to respond to a newly discovered flaw; it also creates a channel an attacker might try to abuse. The FDA’s answer is to require monitoring, patchability, and coordinated disclosure as premarket expectations, so that updating is a designed capability rather than a scramble.
And every added defense of the device must be weighed against the patient’s interest in the device’s function. The reason these implants exist is to restore movement, lift depression, stop seizures, and keep a heart beating. A neurosecurity regime that made devices slower, larger, more power-hungry, or more prone to failure in the name of security could reduce the very welfare it is meant to protect. This is the tension the field inherited from the first paper: security is not free, and in a battery-constrained implant inside a human body, the bill is paid in something other than money.
Where speculation should be kept
The public image of neurosecurity is dominated by the least-grounded scenario: a remote adversary who reads thoughts, edits memories, or takes over a person’s decisions from a distance, undetected. That image is worth examining because it distorts both the threat and the response.
What is demonstrated: cardiac and insulin devices have had exploitable wireless vulnerabilities; clear-text transmissions have leaked patient data; firmware updates carry their own risks; and unauthenticated commands have been shown, in the laboratory, to disable therapy or command a harmful action. What is plausible engineering: the same classes of flaw in neural implants, with consequences that follow from what stimulation does when a clinician changes it deliberately. What remains speculative: undetected, remote, large-scale manipulation of minds, or attacks that operate through walls at ranges that the physics and the waveguide of the human body do not currently permit. Most documented attacks, in fact, require close adjacency—the attacker has to be near the patient—and that single physical constraint is a meaningful part of the real risk profile.
The distinction matters for policy. A threat model that assumes omnipotent remote mind-hacking will produce defenses aimed at a phantom while neglecting the mundane failure modes—a leaked telemetry stream, an unpatchable firmware, a battery that dies early under a flood of wake-up commands—that are actually documented. Getting the threat model right is the difference between protecting patients and performing protection.
What to actually demand
If the goal is to translate the years of research into expectations a person can hold a manufacturer to, a small number of questions do most of the work.
Does the device authenticate the commands that change therapy, and does it do so with a scheme that survives a lost battery and an emergency? Does it encrypt the data it transmits, or does it broadcast a person’s diagnosis and physiology in the clear? Can the patient physically or perceptibly verify and stop an action—does the design keep a human in the loop at the moments that matter? Can the device be cut off from the network without losing its therapy, so that connectivity is a benefit rather than a dependency? Does the manufacturer commit to monitoring, to patching, and to telling users when something is wrong, and does it publish a threat model rather than only a privacy policy? And does the system limit how much it wakes, transmits, and responds, so that an adversary cannot turn the device itself into the weapon against its battery?
None of these questions require predicting the future. They are the questions the medical-device security community has been asking since 2008, applied to the newest class of implants.
The boundary that security is protecting
The deepest reason neurosecurity is different from ordinary cybersecurity is that its subject is not just a device but a person’s capacity to act. The founding definition says as much: the goal is to preserve not only confidentiality, integrity, and availability, but “free will.”
That word needs care. A brain implant does not, today, control a person’s will; it modulates circuits, and the person remains a person. But the boundary that a secure device protects is exactly the boundary between the outside world and the machinery of a person’s own decisions and feelings. Every wireless channel, every remote update path, every unauthenticated command is a place where that boundary could be crossed by someone other than the person behind it. Securing the boundary is not a metaphor; it is the practical content of keeping the device a servant of the person rather than a portal into them.
The uncomfortable truth is that the technology and the governance are again moving on different clocks. The hardware is getting more capable and more connected. The regulatory expectations—the FDA’s cyber-device requirements, the recognition that cybersecurity is safety—are real but young, and they bind manufacturers in one jurisdiction unevenly. And the scenarios that should drive design are still, for neural implants specifically, draws from the documented behavior of their cardiac and metabolic cousins. The opportunity is that the field has been warned early, in unusual detail, and by the people who built the devices. Whether it heeds that warning before the implants are as common as pacemakers is the whole question. A nightmare is only inevitable if it is ignored while there is still time to design it away.
Sources and further reading
- Halperin, D. et al., “Pacemakers and Implantable Cardiac Defibrillators: Software Radio Attacks and Zero-Power Defenses,” IEEE Symposium on Security and Privacy, 2008
- Denning, T., Matsuoka, Y. & Kohno, T., “Neurosecurity: security and privacy for neural devices,” Neurosurgical Focus, 2009
- Pycroft, L. et al., “Brainjacking: Implant Security Issues in Invasive Neuromodulation,” World Neurosurgery, 2016
- CISA, “Abbott Laboratories’ Accent/Anthem, Accent MRI, Assurity/Allure, and Assurity MRI Pacemaker Vulnerabilities,” ICSMA-17-241-01
- NVD, “CVE-2019-10964: Medtronic MiniMed insulin pumps — improper authentication,” 2019
- FDA, “FDA Informs Patients, Providers and Manufacturers About Potential Cybersecurity Vulnerabilities in Certain Medical Devices with Bluetooth Low Energy” (SweynTooth), 2020
- FDA, “Alert: Automated Impella Controller Correction due to Cybersecurity Issue from Abiomed,” 2025
- FDA, “Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions,” 2026
Loading comments…