It has been two weeks since a cyberattack on the Massachusetts-based medical device manufacturer Boston Scientific prevented access to critical information systems and caused major disruption to operations globally. The attack was detected on August 25, 2026, and the company quickly activated its incident response protocol, contained the attack, and has been working round the clock to investigate the unauthorized activity and safely and securely bring systems back online.
Boston Scientific notified the U.S. Securities and Exchange Commission (SEC) about the attack on August 26, 2026, although at the time it was unclear to what extent, if any, the incident would impact its financial position. On September 8, 2026, Boston Scientific submitted another Form 8-K filing with the SEC providing further information on the attack and recovery progress, confirming that the incident is likely to have a material impact on the company’s results of operations for the third quarter and the full year. Boston Scientific explained that the company is unlikely to meet its net sales growth and adjusted EPS guidance ranges for the third quarter and full year 2026, which it provided in late July, around a month before the cyberattack; however, the company does not expect the incident to have an impact on its long-term financial condition.
Boston Scientific confirmed that the cyberattack and subsequent outage affected its ability to manufacture products and ship customer orders. No evidence has been found to indicate any further unauthorized system activity since it implemented its initial containment and remediation measures. Its investigation into the cause of the attack, the extent of compromise, and the nature of data access/exfiltration is continuing.
The company is making progress in its recovery, and a substantial part of its distribution network has been restored. The company’s sterilization facilities are operational, as are most of its manufacturing facilities. Progress is being made to address the backlog of customer orders, which are being shipped above normal operating levels, and the company continues to ramp up operations globally, which should allow it to recover a portion of the impacted revenue and reduce the remaining backlogs.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Boston Scientific cannot provide a timeline for when it will achieve full operational recovery, and the full impact of the incident has yet to be determined. The company will provide an update on the operational and financial outlook for the remainder of fiscal year 2026 in its planned conference call to discuss financial results and business highlights for the third quarter 2026 on Wednesday, October 28, 2026.
The nature of the attack, such as whether ransomware was involved, data was exfiltrated, and a ransom demand was received, has yet to be confirmed, and no threat group appears to have claimed responsibility for the attack.
August 27, 2026: Boston Scientific Cyberattack Impacting Operations
The Massachusetts-based biotechnology and biomedical engineering firm Boston Scientific has disclosed a major cyber incident that is affecting certain information technology systems. The incident has caused a network outage, prevented access to certain business applications, and is disrupting company operations.
Boston Scientific is a medical device company that operates in 127 countries, employs around 59,000 individuals globally, and has annual revenues of around $20.1 billion. The company manufactures devices for interventional cardiology such as pacemakers and cardiac ablation systems, and a range of devices and products for neuromodulation, neurological surgery, urology and pelvic health, endoscopy, pulmonology, interventional radiology, and vascular surgery. The company’s products are used to treat more than 48 million patients a year.
According to the August 26, 2026, announcement, the company identified the incident on August 25, 2026. The company also filed a Form 8-K report with the U.S. Securities and Exchange Commission (SEC) to alert shareholders. At the time of the filing, Boston Scientific had yet to determine if the incident is reasonably likely to have a material impact on the company.
Boston Scientific immediately implemented its incident response procedures and engaged a third-party cybersecurity company to assist with assessment, containment, and to determine the nature and scope of the unauthorized activity. Boston Scientific said the incident has prevented access to certain operating systems and business applications, and is affecting the company’s ability to process and ship customer orders. The disruption is global, with employees in its manufacturing facilities in Cork, Ireland, sent home as they are unable to work. Work is ongoing to safely and securely restore the affected functions and systems, and investigate the incident to determine the extent, if any, of data theft. Boston Scientific is currently unable to provide a timeline of when systems will be fully restored and normal business operations will resume.
Boston Scientific has not publicly disclosed information about the exact nature of the attack, such as whether ransomware was involved, how access to its systems occurred, if a ransom demand was received, and if the company is aware of any data theft claims. The threat actor behind the attack does not appear to have claimed responsibility, which, given that the attack occurred only two days ago, is not unusual.
The Boston Scientific cyberattack is the latest in a string of attacks on medical technology and biotechnology firms. Previous attacks include the recently disclosed ShinyHunters attack on Baxter International, and cyberattacks on Medtronic, Stryker, Abbott Laboratories, iRhythm, and AdaptHealth. Several threat groups were behind those attacks, including financially motivated data theft and extortion operations, ransomware groups, and, in the case of Stryker, an Iran-linked threat group.
Cyberattacks on medtech companies typically involve data theft and extortion, but as this incident shows, they can cause major disruption to business operations, which can impact patients. “A cardiac device that misses its ship date can mean a cancelled surgery. That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for,” said Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs.
“Medical devices also aren’t something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them,” Krell said. “Disrupt order processing and shipping, and the consequences show up in hospitals pretty quickly. The harder problem is getting manufacturing back online. These aren’t ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another.”
The post Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack appeared first on The HIPAA Journal.