Boston Scientific Hit by Cyberattack, Pacemaker and Stent Shipments Disrupted Globally
Boston Scientific disclosed this morning that a cyberattack detected yesterday has caused a global disruption to its operations — including its ability to process and ship customer orders. The company filed an 8-K with the US Securities and Exchange Commission and published a statement on its own website. Shares fell roughly 4% in morning trading.
Boston Scientific makes pacemakers, coronary stents, catheters, spinal cord stimulators, and neuromodulation devices. It operates in more than 100 countries and generated over $16 billion in revenue last year. When its shipping systems go down, hospitals and clinics waiting on medical equipment feel that immediately.
What Boston Scientific Has Disclosed
The company detected the incident on August 25. Its own statement describes what happened next in textbook incident response language: it activated internal protocols, engaged third-party cybersecurity experts, and began working to contain the threat and restore systems.
Beyond that, details are scarce by design. The SEC filing does not name the attacker, does not confirm whether ransomware is involved, and does not state whether any patient or customer data was accessed or stolen. Boston Scientific said explicitly that the full scope, nature, and operational and financial impact are not yet known — and that it cannot yet determine whether the incident will have a material effect on the business.
That last line is significant. Under SEC rules introduced in late 2023, companies must disclose cybersecurity incidents that are “material” within four business days. Filing an 8-K this quickly — before materiality is even determined — suggests Boston Scientific’s legal team decided disclosure was the right call regardless. That’s a cautious and professionally sound approach, and it differs meaningfully from companies that have quietly absorbed incidents without public notice.
Why Medical Device Attacks Are Uniquely Serious
A cyberattack on a retail company disrupts orders. A cyberattack on a medical device maker disrupts procedures.
Boston Scientific’s products include devices implanted in patients — pacemakers, defibrillators, neurostimulators — and consumable supplies used in surgical procedures: catheters, stents, guide wires. Hospitals typically maintain buffer inventory, but disruption to a major supplier’s shipping capabilities creates genuine supply pressure within days, especially for less commonly stocked specialty items.
This is why the healthcare sector has become the most targeted industry for ransomware. Attackers know that hospitals cannot simply wait out a disruption the way a retailer might. The pressure to restore operations quickly makes healthcare organisations more likely to pay — and makes the data they hold particularly valuable for extortion. According to BlackFog research, healthcare accounted for 22% of all disclosed ransomware attacks in 2025.
Boston Scientific is also not the first major medical device maker to be hit recently. Abbott Laboratories, Stryker, and Medtronic have all disclosed cybersecurity incidents in 2026. The pattern is clear: medical technology companies have become a primary ransomware target, and the sector’s investment in cybersecurity has not kept pace with the threat.
What Happens Next
Boston Scientific said it is working to restore affected systems but has not provided a timeline. That phrasing — “the timeline for full restoration is not yet known” — suggests the incident is still active and contained systems are not yet back online. Hospitals relying on Boston Scientific for supplies should check with their procurement teams and verify current inventory levels for critical items.
As the investigation progresses, three things will clarify the full picture: whether ransomware was deployed, whether patient or customer data was exfiltrated, and how long the operational disruption lasts. Each of those will shape the regulatory and financial consequences the company faces in the coming weeks.
For now, Boston Scientific is managing an active incident in real time. Watch the company’s official news page and SEC filings for updates as the investigation continues. For more on how cyberattacks are targeting critical sectors, see our roundup of the worst cyberattacks and data breaches of 2026 and our guide on protecting yourself from AI-powered cyber threats.
Read more tech related articles here.
