Visualização de leitura

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

Boston Scientific Cyberattack, Unopened medical device shipping cartons in a hospital corridor illustrating the Boston Scientific cyberattack disruption to order processing and delivery.

Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return.

The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applications underpinning day-to-day operations.

Boston Scientific is among the world's largest medical device manufacturers, reporting $20.07 billion in 2025 revenue and about $21 billion over the trailing 12 months. Its portfolio includes pacemakers, defibrillators, cardiac stents and neuromodulation implants, and the company says its products treat roughly 48 million patients a year. Thousands of employees in Ireland, where Boston Scientific operates three manufacturing and research sites, were told to work from home on August 26 after network communications were severed.

The company said it activated incident response protocols and engaged outside cybersecurity specialists to contain and investigate the intrusion. It has not said whether ransomware was involved, whether data was exfiltrated, or whether the disruption touches patients with implanted devices. No extortion group had claimed responsibility as of August 26. Shares fell more than 4% following the disclosure.

A Boston Scientific spokesperson declined to answer questions about patient impact and directed reporters to the published statement. Neither the company nor U.S. regulators have said whether hospital procedures have been delayed as a result of the shipping halt, though device suppliers typically hold limited on-site inventory at hospitals, making sustained order outages a downstream supply concern.

The incident is the third disruptive attack on a major medical technology firm in six months. Stryker suffered a global network outage in March after attackers abused its Microsoft Intune deployment to wipe data from thousands of devices, and Medtronic disclosed in April that patient names, Social Security numbers and health information were exposed in a breach attributed to the ShinyHunters extortion group.

Also read: Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

Boston Scientific said it cannot yet assess the full operational and financial impact, language that leaves room for an amended filing once the investigation matures.

The company's Irish footprint also raises the prospect of European scrutiny. If personal data proves to have been accessed, notification duties under the General Data Protection Regulation would attach, and medical device manufacturers operating in the European Union are increasingly captured by the NIS2 Directive's incident reporting regime as member states complete transposition.

Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

Fairlife ransomware attack

The Fairlife ransomware attack has temporarily halted production operations at Coca-Cola-owned dairy company fairlife in the United States after unauthorized access was detected in a portion of its systems, including production-related systems. According to The Coca-Cola Company, fairlife identified unauthorized access by a third party in connection with a ransomware event. Following the discovery, the company activated its incident response and business continuity protocols while launching an investigation with the support of external advisors and cybersecurity experts. Law enforcement has also been notified. The company said the investigation is ongoing and that the full scope, nature, and impact of the incident are not yet known.

Fairlife Ransomware Attack Suspends U.S. Production

The Fairlife ransomware attack has resulted in the temporary suspension of production operations at fairlife facilities across the United States. However, the company stated that product quality and safety have not been affected by the incident. According to the company's statement, fairlife's production operations in Canada remain operational and have not been impacted by the ransomware event. The Coca-Cola Company also confirmed in a Form 8-K filing dated July 16, 2026, that fairlife detected the unauthorized access on Thursday. The filing reiterated that the company immediately activated its incident response procedures and business continuity protocols after identifying the intrusion. While the company continues to assess the incident, it said it has not yet determined whether the ransomware attack is reasonably likely to materially affect its business because the full impact remains unknown. The company added that it is working to complete its investigation and restore affected systems and production operations as quickly as possible.

Investigation Into Unauthorized Access Continues

The ongoing investigation is being conducted with assistance from outside cybersecurity experts. According to the company, the incident involved unauthorized access to a portion of fairlife's systems, including systems related to production. At this stage, The Coca-Cola Company has not disclosed how the attackers gained access, whether any data was compromised, or if a ransomware group has claimed responsibility for the attack. The company emphasized that its assessment is still underway and that additional details will be shared as more information becomes available.

Food and Beverage Sector Faces Growing Cybersecurity Risks

The food and beverage cyberattack trend has continued to affect manufacturers and logistics providers worldwide in recent months. On July 16, a cyberattack targeting Nichirei disrupted food deliveries across Japan after the frozen food and logistics provider confirmed unauthorized access to its servers. The incident affected logistics operations supporting KFC Japan, leading to temporary service disruptions while systems were being restored. Earlier this year, in February 2026, Australian poultry processor Hazeldenes also experienced a cybersecurity incident that disrupted production across its network. The Victoria-based company later announced it had begun a phased return to production to restore operations safely and securely while investigations continued. The latest incident involving fairlife adds another major food producer to the list of companies dealing with operational disruptions linked to cyber incidents. While production has been paused at fairlife's U.S. facilities, the company has maintained that product quality and safety remain unaffected and that its Canadian production continues without disruption. As the investigation progresses, The Coca-Cola Company said it remains focused on restoring impacted systems and resuming normal production operations. The company also noted that the complete scope and potential business impact of the incident have not yet been determined.

Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply

Nichirei Cyberattack

The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a cybersecurity incident involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary service disruptions while the company investigates the incident and works to restore systems. Nichirei Corporation said it detected system failures on July 13 and established an emergency response headquarters the same day. "Nichirei Corporation (the "Company") experienced system failures on July 13, 2026, and has since been investigating its cause. The Company hereby announces the facts identified through the investigation to date and the measures it plans to take going forward," reads notice issued by Nichirei. An investigation later confirmed that company servers had been targeted in a cyberattack. While the company has not disclosed technical details to prevent further damage, it said recovery efforts are underway with the support of an external cybersecurity specialist.

Nichirei Cyberattack Disrupts Logistics and Food Shipments

Following the attack, Nichirei disconnected systems across the Nichirei Group to protect customer and business partner data. The decision disrupted inbound and outbound operations at Nichirei Logistics refrigerated warehouses and halted frozen food shipments handled by Nichirei Foods. The company said it plans to gradually resume affected operations from July 17 after implementing additional security measures. Nichirei also confirmed that some affected servers contained personal information. As a precaution, it submitted an initial report to Japan's Personal Information Protection Commission regarding the possibility of a personal information leak. The company emphasized that, as of its latest update, there is no confirmed evidence that personal information or customer data has been exposed externally. Investigations remain ongoing, and Nichirei said it will notify relevant parties if any data leakage is confirmed.

Nichirei Cyberattack Impacts KFC Japan Store Operations

The incident quickly spread beyond Nichirei's own operations, affecting KFC Japan, which relies on Nichirei Logistics to deliver ingredients to stores nationwide. According to KFC Japan, deliveries have been disrupted since July 14 following the unauthorized access at its logistics partner. As inventory levels fluctuate, customers may experience product shortages, limited menu availability, shortened operating hours, or temporary store closures. The restaurant chain also temporarily suspended mobile orders, delivery services, coupons, and online ordering through its official website and mobile application. KFC Japan said it is working closely with Nichirei Logistics and other partners to restore normal operations as quickly as possible. However, it has not provided an estimated timeline for full recovery.

Investigation Continues Into Japan Cyberattack

Nichirei said the financial impact of the incident is still being assessed. The company expects to release its first-quarter financial results for the fiscal year ending December 31, 2026, on August 7 as scheduled unless further developments require additional disclosure. The company added that it will continue investigating the cyberattack on Nichirei and release additional information if material findings emerge. The incident follows a series of recent Japan cyberattack disclosures involving major organizations. Earlier this week, The Cyber Express reported that Nihon Kotsu experienced a malware-related security incident that disrupted taxi dispatch services after portions of its IT infrastructure were taken offline. Earlier this month, The Cyber Express also reported cyber incidents involving Aflac Japan, KDDI, Sapporo Holdings, and Nidec. While those cases affected different industries, attackers frequently gained access through subsidiaries, overseas operations, or third-party infrastructure rather than directly compromising corporate headquarters. Separately, Asahi Group Holdings continues recovering from a ransomware attack that significantly disrupted online ordering and shipment operations, forcing the company to rely on manual processes.

Supply Chain Risks Remain in Focus

The Nichirei cyberattack highlights how attacks on logistics providers can quickly evolve into broader supply chain disruption affecting downstream businesses and consumers. Although Nichirei has begun restoring operations, investigations into the incident remain active. Authorities are also continuing to examine whether any personal information was compromised while the company works to return logistics services and KFC Japan operations to normal. With multiple high-profile cyber incidents affecting Japanese organizations in recent weeks, the latest disruption highlight he growing operational impact of attacks targeting critical logistics and supply chain infrastructure.

Dutch Health Tech Firm ChipSoft Confirms Destruction of Stolen Patient Data

ChipSoft cyberattack

The Cyber Express previously reported the ChipSoft cyberattack, in which ransomware actors stole patient data. Now, reports have surfaced from the Dutch medical software provider, noting that the compromised data has been destroyed, though key details about the incident remain undisclosed.  In an update issued on April 28, 2026, ChipSoft stated that all data collected during the cyberattack had been deleted. According to the company, cybersecurity specialists verified that the destruction was carried out in a “technically sound manner,” although no further explanation was provided about the methods used.  The company emphasized that preventing the publication of stolen data was a top priority. “With the support of cybersecurity experts, we managed to prevent the data from being published. Furthermore, the stolen data has been destroyed,” the statement read. However, ChipSoft has not clarified whether it paid a ransom to the attackers, despite earlier indications that negotiations had taken place.  “Protecting our customers’ data has always been our top priority. In this exceptional situation, that priority weighed very heavily,” the company added, hinting at the difficult decisions made during the ransomware attack response. 

Timeline of the ChipSoft Cyberattack 

The ChipSoft cyberattack first came to light in early April 2026. On April 12, ChipSoft disclosed that it had fallen victim to a cyberattack on its systems earlier that week. As an immediate precaution, the company disabled connections to several key services, including its Care Portal, Care Platform, and HiX Mobile applications, starting April 8.  At the time, ChipSoft confirmed it had engaged Z-CERT, the Dutch healthcare cybersecurity expertise center, and external cybersecurity professionals to conduct a forensic investigation. The company acknowledged the disruption caused to healthcare providers and patients, noting that patient portals were temporarily unavailable and data exchange via the platform had been halted. 

Data Theft Confirmed in the Netherlands 

By April 16, the investigation revealed that cybercriminals behind the ransomware attack had successfully stolen personal and medical data from several Dutch healthcare institutions. ChipSoft confirmed that affected organizations were being notified directly.  Hans Mulder, CEO of ChipSoft, addressed the breach, stating: “After forty years of dedication to reliable healthcare IT, it pains us that this situation has arisen. We cannot undo this data theft. However, we are doing everything we can to support the affected customers as best as possible in this situation.”  In contrast, a separate update on the same day confirmed that Belgian patient data had not been compromised in the cyberattack on ChipSoft systems. 

Systems Shutdown and Gradual Recovery 

The cyberattack forced ChipSoft to shut down multiple services as a preventive measure. Systems such as Zorgplatform, Zorgportaal, and HiX Mobile were temporarily taken offline, affecting daily operations in healthcare institutions.  By April 17, after extensive analysis conducted in collaboration with cybersecurity experts and Z-CERT, ChipSoft announced that the affected systems were safe to use again. A phased rollout began shortly afterward, with healthcare institutions being informed directly about the restoration process.  Further progress was reported on April 24, when ChipSoft confirmed that most healthcare institutions had regained access to Zorgplatform. Connections to Zorgportaal were also being restored, allowing many patient portals to become operational again. The HiX Mobile app became available once institutions reactivated their systems.  Despite these advancements, ChipSoft cautioned that the recovery process required time and careful handling. The company acknowledged the strain placed on healthcare providers, stating that the precautionary measures had significantly impacted daily workflows and patient care. 

Ransomware Attack on Dutch Software Vendor Disrupts Hospital Systems

ChipSoft ransomware incident

The ChipSoft ransomware incident has disrupted healthcare operations across multiple institutions after the Dutch software vendor was hit by a cyberattack on April 7. The attack forced hospitals to disconnect critical systems and triggered widespread precautionary actions, highlighting the ongoing risks ransomware poses to the healthcare sector. Z-CERT confirmed it has been working closely with ChipSoft, healthcare institutions, and other stakeholders since the incident was first detected. The organization is actively monitoring the situation while providing support and threat intelligence to affected entities.

ChipSoft Ransomware Incident Forces System Shutdowns

In response to the ransomware incident, the company disabled connections to key platforms, including Zorgportaal, HiX Mobile, and the Zorgplatform, as a precaution. These systems remain temporarily unavailable as ChipSoft works to restore services in phases. Users are being issued new login credentials as part of the recovery process. ChipSoft has maintained direct communication with its customers, outlining steps to manage disruptions while systems are gradually brought back online. According to reports, 11 hospitals disconnected ChipSoft software from their networks following the attack. A confidential advisory also urged customers to cut secure VPN connections after the compromise was identified.

Hospitals Face Operational Challenges, Not Critical Disruptions

The ChipSoft ransomware incident has led to logistical challenges across healthcare institutions rather than critical failures in patient care. Hospitals have increased staffing at service desks, expanded telephony support, and relied more heavily on direct communication channels. Systems were reported unavailable at several hospitals, including Sint Jans Gasthuis, Laurentius Hospital, VieCuri Medical Center, and Flevo Hospital. Despite these disruptions, Z-CERT noted that no critical care processes have come to a standstill so far, suggesting that contingency plans and manual workflows are helping maintain essential medical services.

Investigation Ongoing, Attackers Yet to Be Identified

At this stage, the source of the ChipSoft ransomware incident remains unknown, and no ransomware group has claimed responsibility. ChipSoft’s website was also reported unreachable at the time of writing, indicating ongoing technical or security challenges. The attack appears to have originated from a compromise within ChipSoft’s environment, prompting widespread defensive actions by its customers to limit further risk.

Ripple Effects Extend Beyond Immediate Disruptions

The impact of the ransomware incident has extended beyond system outages. Leiden University Medical Center (LUMC) announced it has postponed the rollout of a new electronic patient record system supplied by ChipSoft following the breach. The hospital clarified that there are no indications that patient data has been leaked, reinforcing the current assessment that the incident has not resulted in data exposure.

Healthcare Sector Remains a Prime Target

The ChipSoft ransomware incident highlights the persistent threat facing healthcare organizations. Cybercriminals frequently target hospitals and medical software providers due to the critical nature of their services, where downtime can create pressure to restore systems quickly. A recent example includes the cyberattack on University of Hawaiʻi Cancer Center, where a ransomware incident impacted research systems and exposed sensitive personal data collected over decades. While clinical operations were not affected, the breach highlighted the long-term risks associated with storing large volumes of historical data.

Z-CERT Continues Support and Monitoring

Z-CERT continues to play a central role in managing the fallout from the ransomware incident. The organization is assisting healthcare institutions with prevention, detection, response, and recovery efforts, while also sharing updated threat intelligence. As restoration efforts progress, authorities and healthcare providers remain focused on minimizing disruption and ensuring patient care remains uninterrupted. The ransomware incident serves as another reminder of how cyberattacks on third-party vendors can cascade across critical sectors, reinforcing the need for stronger resilience in healthcare cybersecurity systems.
❌