Cyberattack on Boston Scientific causes global ops disruption
Medical technology company Boston Scientific became the target of a cyberattack this week, which disrupted some of its IT systems, causing operational disruptions globally.
The company detected the incident on 25th August and, in an official announcement, has stated that it caused a network outage, impacting “access to certain operating systems and business applications, including the ability to process and ship customer orders.”
After identifying the intrusion, Boston Scientific activated its incident response procedures and contracted external cybersecurity experts to investigate the impact and help with containment efforts.
The company said it does not yet know when all affected systems will be restored.
Boston Scientific is a Massachusetts-based medical technology company that develops and manufactures devices used in minimally invasive procedures, including stents, catheters, pacemakers, defibrillators, endoscopes, and others.
It is one of the largest medical device manufacturers in the world, with 59,000 employees, 13 manufacturing facilities, a presence in 127 countries, and annual revenue of over $20 billion in 2025.
The investigation into the cybersecurity incident is ongoing. While the company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.
The company filed an 8k on this incident and will provide updates on this webpage as appropriate. According to BleepingComputer, in the filing disclosing the attack to the US Securities and Exchange Commission (SEC), Boston Scientific “does not share any details about the type of cyberattack, the attacker, the initial access method, or whether any data has been exposed or stolen by the threat actor.”
This event follows a series of cyberattacks on life sciences companies this year.
In June, there was a $25 million extortion attempt by hack-and-leak group FulcrumSec on Novo Nordisk. Additionally, another individual, going by TheUSERS007, claimed to have lifted data from Novo Nordisk in a second, unrelated cyberattack.
This followed the reported cyberattack on AstraZeneca in March, in which LAPSUS$ maintained that they had stolen around 3GB of compressed AZ data.
Also in March, geopolitical tensions led to an Iranian hacker group claiming responsibility for a cyberattack against US medtech company Stryker, saying it was in retaliation for the bombing of the Minab school in Iran by US forces that killed 168 people, including 110 children.
Dray Agha, senior manager of security operations at security platform Huntress, has commented on the incident: “The attack on Boston Scientific demonstrates that cyber incidents in the MedTech sector extend far beyond IT and actively threaten the global healthcare supply chain. When a major manufacturer is paralysed and unable to process or ship medical orders, the disruption creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line.”
