Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing, and product shipments.
The company said the incident was detected on August 25, 2026. It caused a network outage involving certain internal information technology systems and business applications.
The medical device manufacturer has engaged CrowdStrike and other third-party cybersecurity specialists to investigate, contain, and recover from the incident.
In its latest update issued August 30 at 8:25 p.m. ET, Boston Scientific said it had found no indication of unauthorized activity in its environment since August 25.
The company said the incident is limited to certain on-premises systems. Its cloud-based systems and applications have not been impacted, according to the ongoing investigation.
This distinction is significant because it indicates that the disruption is affecting localized enterprise infrastructure rather than the company’s broader cloud environment.
Boston Scientific said the affected systems include operational technology support functions and business applications required to manufacture products, process customer orders, and ship medical devices.
Boston Scientific Cyberattack
While customers can continue to submit orders electronically through electronic data interchange, or EDI, and local applications, those orders are being placed into a fulfillment queue until processing and shipping services are restored.
The company said it is working toward a partial restoration of shipping for some products during the week following the August 30 update. Full ordering and shipping capacity will resume after the company validates that the restored systems are fully operational.
The disruption has raised concerns for hospitals, clinicians, suppliers, and patients that depend on Boston Scientific products. However, the company said there is no known impact on devices that are not connected to a Boston Scientific network.
It also reported no known impact on clinicians’ ability to use disconnected devices and no evidence that the incident has increased cybersecurity risks to hospital networks through Boston Scientific medical devices.
Boston Scientific also provided an update on its Cardiac Rhythm Management device portfolio, including implantable cardiac devices such as pacemakers, implantable cardioverter defibrillators, cardiac resynchronization therapy devices, subcutaneous ICDs, and insertable cardiac monitors.
According to the company, existing remotely monitored CRM devices remain functional. Remote patient monitoring for devices enrolled before the outage is also operational, and programmer interrogations are unaffected.
Boston Scientific said there is no evidence that the incident has disrupted transfers of CRM monitoring data to electronic medical record systems.
However, new remote monitoring activations are affected. New communicators for newly implanted CRM devices cannot currently be activated, delaying transmission of device data to remote patient management systems.
Newly implanted insertable cardiac monitors can continue recording episodes after activation through the Boston Scientific Clinic Assistant app. However, they cannot pair with patient mobile phones for remote transmission until systems are restored.
Boston Scientific said it is prioritizing systems that have the greatest effect on customer access, product delivery, and patient care. The company has not disclosed the threat actor, attack method, data theft, ransomware involvement, or a timeline for full recovery.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations appeared first on Cyber Security News.
