Boston Scientific Cyberattack Impacting Operations
The Massachusetts-based biotechnology and biomedical engineering firm Boston Scientific has disclosed a major cyber incident that is affecting certain information technology systems. The incident has caused a network outage, prevented access to certain business applications, and is disrupting company operations.
Boston Scientific is a medical device company that operates in 127 countries, employs around 59,000 individuals globally, and has annual revenues of around $20.1 billion. The company manufactures devices for interventional cardiology such as pacemakers and cardiac ablation systems, and a range of devices and products for neuromodulation, neurological surgery, urology and pelvic health, endoscopy, pulmonology, interventional radiology, and vascular surgery. The company’s products are used to treat more than 48 million patients a year.
According to the August 26, 2026, announcement, the company identified the incident on August 25, 2026. The company also filed a Form 8-K report with the U.S. Securities and Exchange Commission (SEC) to alert shareholders. At the time of the filing, Boston Scientific had yet to determine if the incident is reasonably likely to have a material impact on the company.
Boston Scientific immediately implemented its incident response procedures and engaged a third-party cybersecurity company to assist with assessment, containment, and to determine the nature and scope of the unauthorized activity. Boston Scientific said the incident has prevented access to certain operating systems and business applications, and is affecting the company’s ability to process and ship customer orders. The disruption is global, with employees in its manufacturing facilities in Cork, Ireland, sent home as they are unable to work. Work is ongoing to safely and securely restore the affected functions and systems, and investigate the incident to determine the extent, if any, of data theft. Boston Scientific is currently unable to provide a timeline of when systems will be fully restored and normal business operations will resume.
Boston Scientific has not publicly disclosed information about the exact nature of the attack, such as whether ransomware was involved, how access to its systems occurred, if a ransom demand was received, and if the company is aware of any data theft claims. The threat actor behind the attack does not appear to have claimed responsibility, which, given that the attack occurred only two days ago, is not unusual.
The Boston Scientific cyberattack is the latest in a string of attacks on medical technology and biotechnology firms. Previous attacks include the recently disclosed ShinyHunters attack on Baxter International, and cyberattacks on Medtronic, Stryker, Abbott Laboratories, iRhythm, and AdaptHealth. Several threat groups were behind those attacks, including financially motivated data theft and extortion operations, ransomware groups, and, in the case of Stryker, an Iran-linked threat group.
Cyberattacks on medtech companies typically involve data theft and extortion, but as this incident shows, they can cause major disruption to business operations, which can impact patients. “A cardiac device that misses its ship date can mean a cancelled surgery. That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for,” said Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs.
“Medical devices also aren’t something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them,” Krell said. “Disrupt order processing and shipping, and the consequences show up in hospitals pretty quickly. The harder problem is getting manufacturing back online. These aren’t ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another.”



