Cyber Security News

Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations

Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing, and product shipments.

The company said the incident was detected on August 25, 2026. It caused a network outage involving certain internal information technology systems and business applications.

The medical device manufacturer has engaged CrowdStrike and other third-party cybersecurity specialists to investigate, contain, and recover from the incident.

In its latest update issued August 30 at 8:25 p.m. ET, Boston Scientific said it had found no indication of unauthorized activity in its environment since August 25.

The company said the incident is limited to certain on-premises systems. Its cloud-based systems and applications have not been impacted, according to the ongoing investigation.

This distinction is significant because it indicates that the disruption is affecting localized enterprise infrastructure rather than the company’s broader cloud environment.

Boston Scientific said the affected systems include operational technology support functions and business applications required to manufacture products, process customer orders, and ship medical devices.

Boston Scientific Cyberattack

While customers can continue to submit orders electronically through electronic data interchange, or EDI, and local applications, those orders are being placed into a fulfillment queue until processing and shipping services are restored.

The company said it is working toward a partial restoration of shipping for some products during the week following the August 30 update. Full ordering and shipping capacity will resume after the company validates that the restored systems are fully operational.

The disruption has raised concerns for hospitals, clinicians, suppliers, and patients that depend on Boston Scientific products. However, the company said there is no known impact on devices that are not connected to a Boston Scientific network.

It also reported no known impact on clinicians’ ability to use disconnected devices and no evidence that the incident has increased cybersecurity risks to hospital networks through Boston Scientific medical devices.

Boston Scientific also provided an update on its Cardiac Rhythm Management device portfolio, including implantable cardiac devices such as pacemakers, implantable cardioverter defibrillators, cardiac resynchronization therapy devices, subcutaneous ICDs, and insertable cardiac monitors.

According to the company, existing remotely monitored CRM devices remain functional. Remote patient monitoring for devices enrolled before the outage is also operational, and programmer interrogations are unaffected.

Boston Scientific said there is no evidence that the incident has disrupted transfers of CRM monitoring data to electronic medical record systems.

However, new remote monitoring activations are affected. New communicators for newly implanted CRM devices cannot currently be activated, delaying transmission of device data to remote patient management systems.

Newly implanted insertable cardiac monitors can continue recording episodes after activation through the Boston Scientific Clinic Assistant app. However, they cannot pair with patient mobile phones for remote transmission until systems are restored.

Boston Scientific said it is prioritizing systems that have the greatest effect on customer access, product delivery, and patient care. The company has not disclosed the threat actor, attack method, data theft, ransomware involvement, or a timeline for full recovery.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago