
Boston Scientific, a Massachusetts-based medical device manufacturer, is grappling with a cyberattack that has disrupted its ability to manufacture, process and ship products worldwide, with no timeline yet for restoring normal operations.
The company identified the intrusion on August 25, 2026, and disclosed it publicly the following day in a filing with the U.S. Securities and Exchange Commission. Boston Scientific said it activated its incident response plan and brought in outside cybersecurity specialists to help assess the scope of the breach, contain it and investigate whether any data was stolen.
Boston Scientific makes devices used in interventional cardiology, including pacemakers and cardiac ablation systems, along with products for neuromodulation, neurological surgery, urology, pelvic health, endoscopy, pulmonology, interventional radiology and vascular surgery. The company operates in 127 countries, employs roughly 59,000 people and reports annual revenue of about $20.1 billion. Its devices reach more than 48 million patients each year.
The outage has taken down certain operating systems and business applications, and it initially disrupted the company’s ability to process and ship customer orders. Boston Scientific later acknowledged that manufacturing had also been affected, a detail not included in its earlier statements. Employees at the company’s manufacturing site in Cork, Ireland, have been sent home because they are unable to work amid the outage.
Boston Scientific said it can still accept orders electronically, placing them in a queue for fulfillment once systems come back online. In a statement posted to its website, the company said it is focusing resources on the systems most critical to customers and product delivery, and that it has made progress restoring its core business system.
As of its SEC filing, Boston Scientific had not determined whether the incident is reasonably likely to have a material impact on the company. It has not disclosed whether ransomware was used, how attackers gained access, whether a ransom demand was made, or whether it has seen any claims of data theft. No threat actor had claimed responsibility as of the disclosure.
The company is also examining whether the attack has affected patients who use its connected or implanted devices. So far, it has found no impact on the function of implantable cardiac rhythm management devices, no disruption to those devices’ ability to transmit data, and no interference with clinicians’ remote access to patient data collected before the outage began. Boston Scientific also said it has seen no evidence of heightened cybersecurity risk or problems moving data from remote monitoring systems into electronic medical records for devices that were already being monitored.
The disruption is affecting new activations of remote monitoring for cardiac rhythm devices. For newly implanted devices other than insertable cardiac monitors, new remote communicators cannot be activated, delaying transmission of patient data to remote monitoring systems. For newly implanted insertable cardiac devices, the devices cannot yet pair with patients’ monitoring mobile phones, meaning recorded episode data will not reach the remote monitoring system until pairing is possible. Boston Scientific said the devices will continue recording episodes in the meantime, and that data can be retrieved through an in-person interrogation using the clinic assistant app. Once systems are restored and home monitoring equipment can pair, recorded data will transmit to the remote monitoring system, the company said.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543