Visualização de leitura

Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems

Boston Scientific cyberattack

As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations. Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based on its investigation to date, the company said it has found no indication of unauthorized activity in its environment related to the incident since Aug. 25. The company also clarified that its cloud-based systems and applications have not been affected. The unauthorized activity identified so far is confined to only limited on-premises systems. The clarification comes as Boston Scientific continues working to restore systems supporting manufacturing, ordering and shipping. The company has not established a timeline for a full return to normal operations.

Boston Scientific Ordering and Shipping Recovery Underway 

Boston Scientific said its confidence in restoring ordering, shipping and related system access “continues to increase” and that it is working toward a partial restoration of shipping for some products during the week following its Aug. 30 update. The company said it expects ordering and shipping to ramp up to full capacity once it can demonstrate that the restored operations are fully functional. For now, customers can continue to submit orders electronically through Electronic Data Interchange (EDI) and local applications. Those orders can be placed into a queue for future fulfillment, including orders submitted through the Global Health Exchange (GHX). The latest update indicates that the company’s ability to receive orders electronically has remained intact even while systems required to fulfill and ship those orders have been disrupted. Boston Scientific has not provided a specific date for when full ordering and shipping capacity will return.

Investigation Has Not Confirmed a Data Breach 

Boston Scientific has not said that the cybersecurity incident resulted in a confirmed data breach. Its investigation remains focused on determining the nature, scope, and impact of the unauthorized activity. The Aug. 30 update also provides a more specific picture of the affected technology environment. While certain on-premises systems have been impacted, Boston Scientific said there has been no impact to its cloud-based systems and applications. The company previously said it had found no indication of unauthorized activity in its environment related to the incident since Aug. 25. It has not disclosed whether data was exfiltrated or whether ransomware was involved.

Impact on Medical Devices Remains Limited Based on Current Information

Boston Scientific previously said the incident had not affected devices that are not connected to a Boston Scientific network or clinicians’ ability to use those devices. For Cardiac Rhythm Management (CRM) products, the company reported no known impact on implantable device function, remote monitoring for devices that were already being remotely monitored before the disruption, or programmer interrogations. However, new remote-monitoring activations have been affected. For new CRM implants other than insertable cardiac monitors (ICMs), remote-monitoring communicators cannot currently be activated. As a result, available device data cannot reach remote patient-management systems until activation is possible. Newly implanted ICMs must be activated through the Boston Scientific Clinic Assistant app, but new ICMs cannot currently pair with patients’ remote-monitoring mobile phones. Recorded episodes can still be transmitted through an in-person interrogation using the app’s “Interrogate” function. Boston Scientific said that once its systems are restored and home-monitoring equipment is paired, recorded data will be transmitted to the remote-monitoring system. The company has also said there is no evidence that the affected network environment has increased cybersecurity risks for hospital networks through Boston Scientific devices.

Boston Scientific Continues Incident Response

Boston Scientific said it continues to work with CrowdStrike and other external cybersecurity specialists as the investigation and recovery effort proceeds. The company has been prioritizing systems with the greatest impact on customers and product delivery while working to recover its core business systems. Customers can continue communicating with sales representatives and other Boston Scientific employees through normal channels, including email, established digital platforms and existing connections. The company has acknowledged the potential challenges for customers, patients and suppliers as the disruption continues and thanked them for their patience and partnership. Boston Scientific disclosed the incident in an 8-K filing with the U.S. Securities and Exchange Commission on Aug. 26. The company said it will provide additional updates as appropriate. For now, the latest disclosure narrows the known technical scope of the incident: Boston Scientific says the unauthorized activity is limited to certain on-premises systems, while cloud-based systems and applications remain unaffected. At the same time, the continued disruption to manufacturing, order fulfillment, and shipping means the operational consequences of the attack remain significant as the investigation and recovery effort continue.

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

Boston Scientific Cyberattack, Unopened medical device shipping cartons in a hospital corridor illustrating the Boston Scientific cyberattack disruption to order processing and delivery.

Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return.

The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applications underpinning day-to-day operations.

Boston Scientific is among the world's largest medical device manufacturers, reporting $20.07 billion in 2025 revenue and about $21 billion over the trailing 12 months. Its portfolio includes pacemakers, defibrillators, cardiac stents and neuromodulation implants, and the company says its products treat roughly 48 million patients a year. Thousands of employees in Ireland, where Boston Scientific operates three manufacturing and research sites, were told to work from home on August 26 after network communications were severed.

The company said it activated incident response protocols and engaged outside cybersecurity specialists to contain and investigate the intrusion. It has not said whether ransomware was involved, whether data was exfiltrated, or whether the disruption touches patients with implanted devices. No extortion group had claimed responsibility as of August 26. Shares fell more than 4% following the disclosure.

A Boston Scientific spokesperson declined to answer questions about patient impact and directed reporters to the published statement. Neither the company nor U.S. regulators have said whether hospital procedures have been delayed as a result of the shipping halt, though device suppliers typically hold limited on-site inventory at hospitals, making sustained order outages a downstream supply concern.

The incident is the third disruptive attack on a major medical technology firm in six months. Stryker suffered a global network outage in March after attackers abused its Microsoft Intune deployment to wipe data from thousands of devices, and Medtronic disclosed in April that patient names, Social Security numbers and health information were exposed in a breach attributed to the ShinyHunters extortion group.

Also read: Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

Boston Scientific said it cannot yet assess the full operational and financial impact, language that leaves room for an amended filing once the investigation matures.

The company's Irish footprint also raises the prospect of European scrutiny. If personal data proves to have been accessed, notification duties under the General Data Protection Regulation would attach, and medical device manufacturers operating in the European Union are increasingly captured by the NIS2 Directive's incident reporting regime as member states complete transposition.

❌