The Boston Scientific cyberattack, detected on 25 August, has knocked out portions of the company’s IT infrastructure worldwide, blocking its ability to process and ship customer orders. Shares fell 3.5% in premarket trading, according to Reuters, as investors absorbed the news of an attack whose full scope remains unknown.
Boston Scientific disclosed the incident in a filing with the US Securities and Exchange Commission (SEC), stating that it ‘has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders.’ The company added that ‘the timeline for a full restoration is not yet known.’
What the Boston Scientific Cyberattack Has Disrupted
The attack triggered a network outage that cut access to certain operating systems and business applications. After detecting the intrusion, Boston Scientific activated its incident response procedures and brought in external cybersecurity experts to help with containment and investigation.
The company makes devices used in minimally invasive procedures (stents, catheters, pacemakers, defibrillators, endoscopes and more) across 13 manufacturing facilities and operations in 127 countries. It employs around 59,000 people and posted annual revenue of over $20 billion in 2025. A prolonged outage in order processing is not a trivial inconvenience for a supplier of that size and reach.
In its SEC disclosure, the company declined to share details about the type of attack, the identity of the attacker, the initial access vector, or whether any data was accessed or stolen. Its investigation is continuing, with work under way to determine the nature, scope, and any operational or financial consequences of the incident.
At the time of writing, no ransomware or data extortion group has publicly claimed responsibility for the breach.
Part of a Wider Wave Hitting Medtech and Biotech
The Boston Scientific cyberattack is the latest in a run of incidents targeting medical technology and biotechnology companies. HIPAA Journal notes that previous attacks in the sector include the recently disclosed ShinyHunters attack on Baxter International, as well as incidents affecting Medtronic, Stryker, Abbott Laboratories, iRhythm, and AdaptHealth.
That list underlines how consistently medical device and health technology firms have found themselves in attackers’ crosshairs. The sector carries a particular combination of risk factors: large revenue, complex global supply chains, regulatory filing requirements that force public disclosure, and (critically) devices whose availability affects patient care. Whether the Boston Scientific incident involved patient-related data has not been confirmed; the company has said nothing publicly on that point yet.
The SEC filing mechanism itself is worth a note here. Since the SEC’s cybersecurity disclosure rules came into force, publicly listed US companies have been required to report material cybersecurity incidents within four business days of determining materiality. Boston Scientific’s disclosure follows that framework, though the company has been careful to hedge: its statement that the incident ‘is expected to continue to cause’ disruption signals that materiality has been determined, while the absent details around attacker identity and data exposure suggest the investigation is still at an early stage.
Boston Scientific said it is working ‘diligently’ to restore affected functions, without committing to a timeline. The company has been contacted for further comment; a response is still awaited.

