Boston Scientific Corporation

Boston Scientific restored disrupted operations Sept. 9. Later disclosures identified limited on-premises access, scoped negative data findings and likely material 2026 financial impact; NHS Supply Chain closed its cyber disruption notice Sept. 25.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
A specific application or software platform became unavailable or unusable.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
Manufacturing, production, assembly, processing, or industrial operations were reduced, stopped, or impaired.
Procurement, inventory, warehousing, shipping, delivery, vendor, or other supply-chain processes were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees were sent home, placed on administrative leave, furloughed, or otherwise removed from normal duties because of the incident.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Boston Scientific Corporation experienced a confirmed cyberattack that disrupted information technology systems and global operations beginning Aug. 25, 2026. The company’s evolving incident page said unauthorized activity was limited to certain on-premises systems, cloud-based systems were unaffected and no related unauthorized activity had been observed after Aug. 25. Those findings support containment of the known intrusion but do not establish operational recovery.
The incident caused a global network outage and limited access to operating systems and business applications used for manufacturing, order processing and shipping. Boston Scientific continued accepting electronic orders into a queue. Its Sept. 1 update said manufacturing, order processing, shipping and new cardiac-device remote-monitoring activations remained affected and that it was working toward partial restoration of some product shipping. It did not provide a full-restoration timeline.
GHX documented continuing healthcare-supply-chain disruption Aug. 31. Boston Scientific’s global GHX connections remained disconnected, and North American customer orders continued to enter the Exchange. A temporary process sent higher-priority order information to Boston Scientific in a daily file for selective processing, while other orders remained queued, order-status information was unavailable and fulfillment delays could continue. GHX credentialing documents submitted by Boston Scientific representatives were also being processed on a delayed basis.
The disruption prompted a broader health-system response. NHS Supply Chain activated a Major Incident Team and coordinated with NHS England and the Department of Health and Social Care, which engaged the National Supply Disruption Response team. Its Aug. 28 update said automated ordering, picking, packing and shipping remained unavailable and warned that deliveries would be delayed, while selective internal radiation therapy products were unaffected.
The outage also affected clinical monitoring workflows. Boston Scientific said new remote-monitoring communicators for recently implanted cardiac-rhythm devices could not be activated, preventing available device data from reaching remote patient-management systems until activation. Newly implanted insertable cardiac monitors could record episodes but could not pair with a patient’s mobile phone; clinicians could retrieve the data through an in-person interrogation with the Clinic Assistant app.
The company reported no known impact to implanted cardiac-rhythm device function, previously established remote monitoring, programmer interrogations or devices not connected to a Boston Scientific network. It also reported no evidence that the affected environment increased cybersecurity risk to hospital networks through use of Boston Scientific devices. Those findings narrow the known clinical effect to new monitoring activation and data transmission rather than implanted-device operation.
The Irish Examiner reported that more than 7,000 employees across Boston Scientific’s Irish plants were informed of the global outage and that the Cork plant’s day shift was sent home. The outlet reported the next day that employees able to work remotely were told to do so, while workers in Galway and Clonmel were not required for scheduled shifts. These remain the only municipalities with plant-specific public impact details; Boston Scientific has not identified a particular U.S. facility as closed.
Boston Scientific initially described the event to employees as a global outage affecting network communications. It publicly identified the cause as a cybersecurity incident Aug. 26, one day after the first documented outage effects. Because the earlier public reporting did not characterize the event as cyber-related, the sequence remains organization-first.
Boston Scientific disclosed the incident in an SEC filing under Item 8.01, Other Events, rather than Item 1.05 for material cybersecurity incidents. The company said it had not determined whether the incident was reasonably likely to materially affect its business. On Sept. 8, it filed a subsequent Item 1.05 material cybersecurity incident report. It determined that the incident was likely to materially affect third-quarter and full-year 2026 results and that it was unlikely to meet its previously issued net-sales growth and adjusted earnings-per-share guidance. It expected to recover some affected revenue as orders and backlogs were processed, but had not quantified the full impact. It did not expect a material impact on its long-term financial condition.
Confidence is high that unauthorized access and substantial operational disruption occurred because Boston Scientific documented unauthorized activity, a network outage, manufacturing effects, order-fulfillment failure and product-monitoring limitations. The company’s Sept. 22 summary of CrowdStrike’s investigation identified access through an external-facing network device into a limited portion of the on-premises IT environment. It did not identify the device, an exploited vulnerability, malware or a responsible actor. The investigation found no evidence of continuing actor activity after Aug. 25 containment.
The incident caused a confirmed availability effect for some newly recorded cardiac-device data because it could not be transmitted to remote monitoring systems until activation or accessed through the documented in-person workaround. The Sept. 22 summary said CrowdStrike found no evidence of compromise in Microsoft Office 365, other cloud applications, manufacturing-maintenance systems, product and software development, medical-device maintenance, human resources and employee benefits, or SCADA environments. It also found no evidence that data from those systems and applications, including customer or patient data, was accessed, staged or exfiltrated. These are scoped negative investigation findings, not proof that every system or record was unaffected.
Ransomware and extortion remain unresolved. Separate searches for Boston Scientific Corporation, Boston Scientific and bostonscientific.com found no stable ransomware-group, extortion or leak-site claim through the Sept. 26 research cutoff. No ransom demand, negotiation channel, leak threat or payment has been reported.
Boston Scientific said Sept. 9 that manufacturing, order fulfillment and shipping were fully restored, remote-monitoring activation capability had returned and normal communications could resume. Some application restoration and backlog reduction continued, but the material operational disruption was resolved. NHS Supply Chain closed its incident notice Sept. 25, confirming manufacturing and distribution were back to business as usual and that normal system connections could safely continue. It distinguished two pre-existing product-supply notices from the closed cyber disruption. The closure date is not a new outage date or a replacement for the company’s Sept. 9 restoration date.
The public record does not establish the exact external-facing device and initial access technique, malware family, dwell time, detailed containment method, affected on-premises network segments, number of disrupted facilities, production volume lost, order backlog, recovery cost or the final restoration date for the remaining applications. It also does not establish whether patient care was delayed, whether providers exhausted on-hand inventory, whether other product families or connected services were affected, or the exact GHX reconnection date. The current GHX status page showed normal operations and no Boston Scientific entry in its visible recent feed; that bounded observation does not establish when the specific connection returned.
The public company summary supplies forensic scope and negative data-access findings, but no confirmed exfiltration, affected-person count, ransomware family or actor attribution. The linked investigation PDF could not be independently read through the available retrieval routes, so no additional findings are inferred from it.

Boston Scientific described global operational disruption, and its current directory identifies a principal manufacturing facility in Carlsbad; no site-specific impact statement was found.
An official Spanish-language directory identifies a Fremont facility, but the current English directory omits it and no site-specific incident impact was found.
Current recruiting material uses San Jose as an on-site location while referring to a Santa Clara office; no site-specific incident impact was found.
Current recruiting material supports Boston Scientific operations in Valencia, but no source specifically established operational impact there.
Boston Scientific's directory identifies a Washington government-affairs office, but no source specifically established operational impact there.
Boston Scientific's directory identifies its Latin America headquarters in Weston, but no source specifically established operational impact there.
Boston Scientific described global operational disruption, and its current directory identifies a principal manufacturing facility in Johns Creek; no site-specific impact statement was found.
Boston Scientific described global operational disruption, and its current directory identifies a principal manufacturing facility in Spencer; no site-specific impact statement was found.
Boston Scientific described global operational disruption, and its current directory identifies the Quincy customer fulfillment center; no site-specific impact statement was found.
Current recruiting material supports a staffed Boston Scientific site in Waltham, but no source specifically established operational impact there.
Boston Scientific described global operational disruption, and its current directory identifies principal manufacturing, R&D and training operations in Arden Hills; no site-specific impact statement was found.
Boston Scientific described global operational disruption, and its current directory identifies principal manufacturing, R&D and training operations in Maple Grove; no site-specific impact statement was found.
A current hybrid role supports a present Minnetonka site, but the position is expected to move to Maple Grove and no site-specific incident impact was found.
Boston Scientific described global operational disruption, and its current directory identifies a principal manufacturing facility in Dorado; no site-specific impact statement was found.
We reported that Boston Scientific’s Aug. 25 cybersecurity incident disrupted operations worldwide, limited access to systems used to process and ship customer orders, and affected employee shifts at plants in Cork, Clonmel and Galway. The company was restoring systems in phases and had not disclosed a completion timeline, the access method, data consequences or a responsible actor.
The Irish Examiner reported Aug. 25 that more than 7,000 employees across Boston Scientific’s plants in Cork, Clonmel and Galway were informed of a global outage affecting network communications across Irish sites and other locations worldwide. The outlet reported that the Cork plant’s day shift was sent home at 2 p.m. with full pay while restoration work continued.
The Irish Examiner reported that recovery would proceed in phases, employees able to work remotely were told to do so and on-site shift requirements would be decided individually. Staff were sent home from the Cork plant, while workers at the Clonmel and Galway plants were told they would not be required for scheduled shifts.
Boston Scientific disclosed that a cybersecurity incident detected Aug. 25 caused and was expected to continue causing disruptions and access limitations affecting information systems and business applications, including order processing and shipping. It said restoration was underway, the full timeline was unknown, and it had not determined whether the incident was reasonably likely to materially affect the business.
BleepingComputer reported that Boston Scientific’s cyberattack disrupted IT systems and operations globally, including order processing and shipping. The outlet said the company had not disclosed the attack type, actor, initial-access method or whether data was exposed or stolen, and it found no ransomware or data-extortion group claiming responsibility when it checked.
GHX said Sept. 2 that Boston Scientific’s global connections remained disconnected and no active alternative for order processing was available. GHX continued receiving and sharing order information, but could not provide order processing or fulfillment status. Credentialing documents remained delayed, and no reconnection timeline was available. GHX reported no impact to its systems or customer data.
Sept.22 company summary of CrowdStrike investigation: external-facing network device access to limited on-premises IT; no continuing activity afterAug25; no compromise or access/staging/exfiltration in specified cloud/business/SCADA systems, including customer/patient data. Normal connections safe.
Sept.25 closes ICN3464: manufacturing/distribution business as usual and normal system connections safe. Two remaining product notices pre-existing. Historical timeline retains August outage and September restoration/monitoring evidence.
Item1.05: likely material effect on Q3/full2026results and unlikely to meet prior net-sales growth/adjustedEPS guidance. Some revenue may recover; full impacts unknown; no expected material long-term financial-condition impact. Contemporaneous restoration progress, not a later new outage.
Boston Scientific’s current directory identifies its world headquarters in Marlborough; offices in Washington and Weston; principal manufacturing facilities in Arden Hills, Carlsbad, Dorado, Johns Creek, Maple Grove and Spencer; a Quincy fulfillment center; and R&D or training operations in Arden Hills, Maple Grove and Marlborough.
Boston Scientific’s current recruiting page lists on-site or hybrid research-and-development positions in Waltham, Valencia and San Jose, supporting staffed company operations in those geographies.
Boston Scientific lists a hybrid position based in Minnetonka with an in-office requirement and says the role will eventually move to the company’s Maple Grove location.
Boston Scientific’s Spanish-language location directory identifies a company facility at 47215 Lakeview Boulevard in Fremont, California.
Signed-in members can report an error, update, or missing source.