Boston Scientific Cyberattack Disrupts Operations and Customer Order Processing

Boston Scientific reported a cyber incident on August 26, 2026, that disrupted its information technology systems, blocked access to selected operating systems and business applications, and affected the company’s ability to process and ship customer orders.

Cyber Incident Obstructs Information Technology Systems

Boston Scientific identified the incident on August 25, 2026. The Massachusetts-based biotechnology and biomedical engineering firm reported that the incident caused a network outage and disrupted company operations. The company filed a Form 8-K with the U.S. Securities and Exchange Commission to notify shareholders about the incident. At the time of the filing, Boston Scientific had not determined whether the incident was reasonably likely to have a material impact on the company.

Boston Scientific immediately implemented its incident response procedures and engaged a third-party cybersecurity company. The third party helped to assess and contain the incident and to determine the nature and scope of the unauthorized activity.

Global Operational Disruption

The incident prevented access to certain operating systems and business applications. Boston Scientific reported that the disruption is affecting its ability to process and ship customer orders.

The disruption extends across the company’s global operations. Employees at Boston Scientific manufacturing facilities in Cork, Ireland, went home because they were unable to work. The work on restoring affected functions and securing systems is in progress while investigators examined the incident and assessed whether any data, including PHI, may have been stolen. Boston Scientific has not provided a timeline for full system restoration or the return of normal business operations.

Attack Details Remain Undisclosed

Boston Scientific has not publicly disclosed the exact nature of the attack. The company has not stated whether ransomware was involved, how access to its systems occurred, whether a ransom demand was received, or whether it was aware of claims involving data theft. The threat actor had not publicly claimed responsibility at the time of the report.

The investigation includes determining the extent, if any, of data theft. The available information does not establish that data was stolen.

Impact on Medical Device Operations

Boston Scientific operates in 127 countries and employs around 59,000 individuals globally. The company has annual revenues of around $20.1 billion and manufactures medical devices used across several areas, including neuromodulation, neurological surgery, interventional cardiology, urology and pelvic health, pulmonology, endoscopy, interventional radiology, and vascular surgery. Its products are used to treat more than 48 million patients a year.

The report states that cyberattacks against medical technology companies can involve data theft and extortion as well as operational disruption. The Boston Scientific incident has affected order processing and shipping, creating operational consequences associated with the availability of medical devices.

The software used to produce and track FDA-regulated devices operates within a validated quality system. Restoring affected servers therefore involves more than restoring technical access because the reliability of data produced by those systems also has to be established.

Investigation and Restoration

Boston Scientific continues to investigate the incident while working to restore affected functions and systems. The company has not disclosed when full restoration will occur or when normal business operations will resume. The available information does not establish the attack method, whether a ransom demand was made, or whether protected data was compromised.

About Christine Garcia 1278 Articles
Christine Garcia is the staff writer on Calculated HIPAA. Christine has several years experience in writing about healthcare sector issues with a focus on the compliance and cybersecurity issues. Christine has developed in-depth knowledge of HIPAA regulations. You can contact Christine at [email protected]. You can follow Christine on Twitter at https://twitter.com/ChrisCalHIPAA