Boston Scientific said Wednesday that a cybersecurity incident disrupted operations worldwide, limiting access to systems used to process and ship customer orders as recovery continued without a completion timeline.
Boston Scientific Corporation is a global medical technology company headquartered in Marlborough, Massachusetts. It employs about 59,000 people and develops and manufactures devices for minimally invasive procedures.
The company said it detected the incident Tuesday, activated its incident-response procedures and hired outside cybersecurity specialists to investigate and contain the threat.
In a filing with the Securities and Exchange Commission, Boston Scientific said the disruption was expected to continue limiting access to information systems and business applications, including those supporting order processing and shipping. It filed under Item 8.01, Other Events, rather than Item 1.05, which covers material cybersecurity incidents.
Boston Scientific said the full operational and financial effects remained unknown and it had not determined whether the incident was reasonably likely to materially affect its business.
More than 7,000 employees across Boston Scientific plants in Cork, Clonmel and Galway experienced workplace disruptions, the Irish Examiner reported. The Cork plant’s day shift was sent home Tuesday, while workers in Clonmel and Galway were told they would not be required to report for scheduled shifts.
Employees who could work remotely were told to do so Wednesday. On-site staffing was being decided case by case as the company restored sites and functions in phases based on business needs, according to the newspaper. A company message reviewed by the Irish Examiner described a global network outage affecting Irish sites and other locations worldwide.
Despite the reported global scope, Boston Scientific has not identified a specific U.S. facility that was disrupted or said whether implanted devices, remote-monitoring systems or other patient-facing technology were affected.
The company also has not disclosed how its network was accessed, whether data was viewed or taken, or who was responsible. DysruptionHub found no public claim of responsibility from a ransomware or data-extortion group as of Wednesday.
The incident echoes two recent cyberattacks at U.S. medical technology manufacturers whose global disruptions were documented in Europe. Irish reporting first surfaced Stryker’s March network outage, which locked employees out of systems in Ireland and the United States.
In May, German reporting documented interrupted operations at West Pharmaceutical Services sites in Germany and France. The company said some shipping, receiving and manufacturing recovery remained underway a week after detection.
Boston Scientific had not disclosed Wednesday whether customer deliveries were delayed or when its order systems would be fully available.