Hacker working on computer showing cyber attack caused operational disruption

Cyber Attack Hits Cardiac Device Maker Boston Scientific, Disrupting Global Operations

Boston Scientific is investigating a cyber attack that caused global network disruption affecting business applications and operating systems, impacting device manufacturing, order processing, and shipments.

The medtech company learned of the incident on August 25, 2026, after detecting a network outage and responded by activating cyber incident protocols, engaging external cybersecurity experts, and notifying federal regulators.

Cyber attack to disrupt Boston Scientific operations for weeks

According to the company’s SEC filing, the medical device maker was working to restore operations, but it could not estimate how long it would take to resume normal operations. Some estimates suggest it could take weeks for the company to resolve the cyber attack.

“While we are working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known,” the company explained.

However, the attack did not affect Boston Scientific’s cloud-based applications but was restricted to specific on-premises systems. Additionally, the company had not detected any unauthorized activity in its environment.

Additionally, devices connected to Boston Scientific’s network, as well as those used by clinicians but not connected to the network, were also unaffected. Similarly, there is no evidence suggesting that hospitals connected to the company’s network were affected.

At present, Boston Scientific can continue to monitor pacemakers and other cardiac devices that were already activated before the cyber attack. However, remote-monitoring activation for newly implanted devices was affected.

“A cardiac device that misses its ship date can mean a canceled surgery,” said Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs. “That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for.”

Nevertheless, affected devices continue to record data, which will be transmitted to Boston Scientific’s remote patient-management system once the remote-monitoring functions are fully restored. The medical technology company also apologized for the inconvenience caused and said it would continue working with patients and suppliers to address the impact of the incident.

So far, the full impact, scope, and nature of the cyber attack were still under investigation, and its material and financial impact was unknown, according to the SEC disclosure.

“For Boston Scientific, the potential impact also extends beyond its own four walls,” warned Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova. “This is one of the world’s largest medical device manufacturers, supplying products such as stents, catheters, pacemakers, defibrillators, and endoscopes. If a cyberattack interferes with the processing and shipment of those products, the disruption can reach the hospitals and clinics that depend on that supply chain.”

Meanwhile, Boston Scientific has not attributed the cyber attack to any hacking group. Similarly, no cybercrime gang has taken responsibility at the time of publication. The company has also not disclosed how the attackers gained initial access. However, compromise of internal systems typically involves techniques such as phishing, malware, stolen credentials, and exploitation of software vulnerabilities.

The multinational device maker also told its Irish staff to work from home, though it did not disclose whether the directive was a result of the cyber attack.

Hackers continue to target medical technology companies

Boston Scientific adds to the growing list of medical technology companies affected by cyber attacks. In May 2026, Iranian hackers breached Stryker, a Michigan-based medical technology company that provides MedSurg, Neurotechnology, and Orthopedics services.

In April 2026, unauthorized parties also breached medical technology company Medtronics and exfiltrated personal information from its corporate IT systems.

In the same year, hackers breached Abbott Laboratories’ cancer diagnostics center and ‌its LabCentral portal. While the cyberattack did not leak patient data or affect other departments, it raised serious concerns about the potential impacts of cyber attacks on healthcare.

Intuitive Surgical was also breached in 2026 from a phishing attack, while a third-party data breach leaked data from iRhythm, a cardiac monitoring medical technology firm. Other MedTech companies breached in 2026 include AdaptHealth, Cook Medical, Baylor Genetics, Novocure, and West Pharmaceutical Services.