Boston Scientific said a cyberattack identified on August 25 forced it to take systems offline, disrupting global manufacturing, customer-order processing, and shipments. The medical-device maker withdrew its previous third-quarter and full-year 2026 sales and adjusted-profit guidance, warning that the incident will likely materially affect sales growth and earnings while the full financial impact remains uncertain.
The company said major distribution centers, sterilization facilities, and most manufacturing sites have substantially resumed operations, and it expects to recover some deferred revenue as backlogs normalize. Product-quality reviews found no impairment, though new activations of its cardiac-device remote-monitoring platform were disrupted; some internal systems and business applications remain impaired. Boston Scientific reported no evidence of continuing unauthorized access, while the attack vector, responsible actor, potential ransomware or data theft, and overall impact remain under investigation.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Boston Scientific publicly disclosed the cybersecurity incident and said the unauthorized activity appeared limited to certain on-premises systems, while cloud applications were unaffected. It reported no known impact to medical devices outside its network and no evidence of increased cybersecurity risk to hospital networks.
Boston Scientific took certain systems offline to contain the incident, causing a network outage that disrupted global manufacturing and applications used to process and ship customer orders.
Boston Scientific identified unauthorized activity on some of its IT systems, triggering a cybersecurity incident that affected its network.
Boston Scientific said it had found no evidence of continuing unauthorized access but that its investigation remained ongoing. The company had not disclosed the initial access method, responsible actor, ransomware involvement, or whether data was stolen.
The company reported that major distribution centers, sterilization facilities, and most manufacturing sites had resumed operations; the interruption to new remote cardiac-device patient activations was resolved. Some systems and business applications remained impaired, and the company could not estimate full recovery timing.
Boston Scientific said it was unlikely to meet its previously issued third-quarter and full-year 2026 sales-growth and adjusted-earnings guidance because the incident's full financial impact remained uncertain. It expected to recover some deferred revenue while clearing operational backlogs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcebusinessinsurance.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.