US Edition
Your source for latest news
BusinessCybersecurity

Boston Scientific Cyberattack Halts Order Processing Worldwide

The medical device maker told federal regulators that a cybersecurity incident discovered Tuesday has caused a global disruption to its operations, including its ability to process and ship customer orders, with no restoration timeline yet in sight.

PB
By PressTemps Business DeskPublished Yesterday, 09:03 ET · 5 min read
Boston Scientific Cyberattack Halts Order Processing Worldwide
A Boston Scientific facility in Yokneam, Israel. The company disclosed this week that a cybersecurity incident discovered Aug. 25 has disrupted operations globally. Photo: Jakednb, CC BY-SA 4.0, via Wikimedia Commons.
What to know
Boston Scientific disclosed in an Aug. 26 SEC filing that a cybersecurity incident discovered the prior day has caused a global disruption to its operations, including order processing and shipping.
The company has engaged third-party cybersecurity experts and says a full restoration timeline is not yet known; shares fell as much as 6 percent on the news.
Boston Scientific, maker of pacemakers, the Watchman heart device and cancer-care equipment, reported $20.1 billion in 2025 sales.
The company has not disclosed the nature of the attack, whether data was stolen, or whether patient care has been affected, and healthcare remains the most-targeted sector for cyberattacks.

Boston Scientific, one of the world's largest medical device makers, disclosed this week that a cybersecurity incident has disrupted its operations globally, cutting off access to systems it uses to process and ship customer orders and leaving the company unable to say when normal service will resume.

In a filing with the Securities and Exchange Commission, the Marlborough, Massachusetts-based company said it discovered the incident on Aug. 25 and that it "has resulted in a global disruption to the Company's operations." The 8-K filing, submitted Wednesday under Item 8.01, states that the breach affected "access to certain operating systems and business applications, including the ability to process and ship customer orders," and that the company has "not yet determined whether the incident is reasonably likely to have a material impact."

Third-party investigators called in

Boston Scientific said it activated its incident response protocols upon discovery and brought in outside cybersecurity specialists to investigate and contain the threat, according to both the SEC filing index and a statement posted to the company's newsroom. "The timeline for a full restoration is not yet known," the company said, adding that it is "working diligently to restore affected functions and systems access." Neither the SEC filing nor the newsroom post identifies the nature of the attack, names a perpetrator, or addresses whether patient data or the function of implanted medical devices was affected; the disclosed disruption is described specifically in terms of order processing, shipping, and back-office systems access.

The company's shares fell as much as 6 percent in early trading Wednesday on the news, according to CBS News, before paring some of the decline. Boston Scientific is a substantial company by any measure: its investor relations disclosures show 2025 sales of $20.1 billion and adjusted earnings of $3.06 per share, built on a product line that spans cardiac devices such as pacemakers and defibrillators, the Watchman heart-implant device, and equipment used in cancer care and gastrointestinal procedures.

Part of a wider pattern

The incident lands in a healthcare sector that has become the most frequently targeted industry for cybercriminals. Healthcare organizations accounted for 22 percent of all disclosed cyberattacks in 2025, according to research cited by CBS News, a share driven in part by the value of medical and insurance data and the operational pressure hospitals and device makers face to restore service quickly rather than negotiate at length with attackers. The disclosure also follows a string of costly incidents at other health-sector companies in recent years that disrupted prescription processing, insurance claims and hospital billing systems nationwide, underscoring how a single vendor's outage can ripple through hospitals and clinics that depend on its equipment and supply chain.

For now, Boston Scientific has not said whether the attackers are demanding a ransom, whether any data was exfiltrated, or whether hospitals and clinics that rely on its devices have experienced any disruption to patient care as a result of the order and shipping delays. The company's SEC filing is written in the cautious, still-unfolding language typical of an active incident: full scope unknown, financial impact undetermined, restoration timeline unset. Investors and hospital customers are, for now, left to watch the same newsroom page the company says it will update as the investigation proceeds.

More on this story

All Business