Boston Scientific reported a cyber incident on August 26, 2026, that disrupted its information technology systems, blocked access to selected operating systems and business applications, and affected the company’s ability to process and ship customer orders.
Cyber Incident Obstructs Information Technology Systems
Boston Scientific identified the incident on August 25, 2026. The Massachusetts-based biotechnology and biomedical engineering firm reported that the incident caused a network outage and disrupted company operations. The company filed a Form 8-K with the U.S. Securities and Exchange Commission to notify shareholders about the incident. At the time of the filing, Boston Scientific had not determined whether the incident was reasonably likely to have a material impact on the company.
Boston Scientific immediately implemented its incident response procedures and engaged a third-party cybersecurity company. The third party helped to assess and contain the incident and to determine the nature and scope of the unauthorized activity.
Global Operational Disruption
The incident prevented access to certain operating systems and business applications. Boston Scientific reported that the disruption is affecting its ability to process and ship customer orders.
The disruption extends across the company’s global operations. Employees at Boston Scientific manufacturing facilities in Cork, Ireland, went home because they were unable to work. The work on restoring affected functions and securing systems is in progress while investigators examined the incident and assessed whether any data, including PHI, may have been stolen. Boston Scientific has not provided a timeline for full system restoration or the return of normal business operations.
Attack Details Remain Undisclosed
Boston Scientific has not publicly disclosed the exact nature of the attack. The company has not stated whether ransomware was involved, how access to its systems occurred, whether a ransom demand was received, or whether it was aware of claims involving data theft. The threat actor had not publicly claimed responsibility at the time of the report.
The investigation includes determining the extent, if any, of data theft. The available information does not establish that data was stolen.
Impact on Medical Device Operations
Boston Scientific operates in 127 countries and employs around 59,000 individuals globally. The company has annual revenues of around $20.1 billion and manufactures medical devices used across several areas, including neuromodulation, neurological surgery, interventional cardiology, urology and pelvic health, pulmonology, endoscopy, interventional radiology, and vascular surgery. Its products are used to treat more than 48 million patients a year.
The report states that cyberattacks against medical technology companies can involve data theft and extortion as well as operational disruption. The Boston Scientific incident has affected order processing and shipping, creating operational consequences associated with the availability of medical devices.
The software used to produce and track FDA-regulated devices operates within a validated quality system. Restoring affected servers therefore involves more than restoring technical access because the reliability of data produced by those systems also has to be established.
Investigation and Restoration
Boston Scientific continues to investigate the incident while working to restore affected functions and systems. The company has not disclosed when full restoration will occur or when normal business operations will resume. The available information does not establish the attack method, whether a ransom demand was made, or whether protected data was compromised.