St. Jude Medical stock went into a brief free-fall Thursday morning following publication of a short seller's research report that lambasted the company for lax cybersecurity practices and predicted nearly half the med-tech company's revenue may evaporate for two years.
Muddy Waters Capital, a combative financial research group, revealed an aggressive bet against the Little Canada-based maker of heart devices because of what it called "worrying" problems with the cybersecurity of St. Jude's medical devices. The group said St. Jude pacemakers and other heart-rhythm devices are vulnerable to attacks that can disable the implantable lifesaving devices.
"We find STJ cardiac devices' vulnerabilities orders of magnitude more worrying than the medical device hacks that have been publicly discussed in the past," the 34-page Muddy Waters report says, referring to St. Jude Medical by its stock ticker symbol.
Muddy Waters called on St. Jude to recall and fix the devices, which it said could take two years. The firm noted that pacemakers, implantable defibrillators, and cardiac resynchronization therapy devices made up about 46 percent of St. Jude's 2015 revenue.
St. Jude officials, who are in the processing of selling the company to Abbott Laboratories for $25 billion, immediately fired back.
"The allegations are absolutely untrue," Phil Ebeling, St. Jude chief technology officer, said via an e-mailed statement. "There are several layers of security measures in place. We conduct security assessments on an ongoing basis and work with external experts specifically on Merlin@Home and on all our devices."
Merlin@Home is a monitoring device intended to be used at home to communicate and remotely send information from implanted heart devices.
Muddy Waters said that even "low-level" hackers could figure out how to exploit security vulnerabilities with the system and impersonate a Merlin@Home device to communicate with heart devices, and potentially St. Jude Medical's internal computer network.