News briefing
Boston Scientific says cyberattack will hit 2026 results as systems are restored

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
The medical device maker says CrowdStrike's final investigation found the attacker entered through an external-facing network device, with no evidence that customer or patient data was accessed or taken. It has already warned the attack will hit 2026 results.
01 / What happened
Boston Scientific identified a cybersecurity incident on 25 August 2026 affecting some of its IT systems, according to a Form 8-K filed with the US Securities and Exchange Commission the following day. The company said the incident had caused a global disruption to its operations, including its ability to process and ship customer orders. It activated its incident response protocols and brought in outside cybersecurity specialists to assess and contain the threat.
In that first filing the company said it had not yet determined whether the incident was reasonably likely to have a material impact, and that no restoration timeline was known. Its shares fell by more than 4% on the morning of the disclosure, The Register reported.
A second 8-K, dated 7 September and filed on 8 September under Item 1.05 (material cybersecurity incidents), described unauthorised activity that caused a network outage affecting operating systems and business applications, and said this had also disrupted manufacturing.
On 22 September the company published CrowdStrike's final investigation summary. It says the threat actor gained access through an external-facing network management device, and that its access was then limited to a portion of Boston Scientific's on-premises environment. The investigation ran from 25 August to 18 September.
02 / Why it matters
In the September filing, Boston Scientific said the incident is likely to have a material impact on its results for the third quarter and full year 2026, and that it is unlikely to meet the net sales growth and adjusted earnings per share guidance ranges it gave on 29 July. It did not put a figure on the shortfall.
A single intrusion has moved from an IT outage to a forecast warning in under a fortnight.
The company makes implanted cardiac devices such as pacemakers and defibrillators, and TechCrunch reports that it serves about 48 million patients a year. Interruptions to manufacturing, sterilisation and shipping therefore matter well beyond the company's own balance sheet. The incident follows other recent attacks on medical technology firms, including Stryker and Medtronic, according to The Register.
03 / Who is exposed
- Hospitals and clinicians relying on Boston Scientific supply chains, which faced order and shipping disruption from late August.
- Shareholders, given the company's warning on 2026 guidance.
- Patients: CrowdStrike found no evidence that the attacker accessed, staged or exfiltrated data from the systems and applications it examined, including customer or patient data. That is a finding of no evidence, scoped to the systems Boston Scientific identified, not a blanket guarantee.
04 / Confirmed vs. claimed
Confirmed (SEC filings and the company's 22 September update): detection on 25 August; global disruption to order processing, shipping and manufacturing; substantial restoration of distribution and manufacturing by early September; entry via an external-facing network management device; no evidence of threat actor activity after containment on 25 August; no evidence of encryption of data, and no evidence of activity in Microsoft 365, email, SCADA, HR, manufacturing, medical device maintenance or product development systems, according to CrowdStrike. Boston Scientific says customers and partners may safely continue normal business and system connections. Not confirmed: the company has not named the attacker, identified the device's make, or said whether a ransom was demanded. No group had publicly claimed the attack as of 29 September, and no further incident-related 8-K had been filed by then.
05 / What to do now
- Healthcare providers should confirm order status and lead times for affected Boston Scientific products directly with the company.
- Treat unsolicited messages referencing the incident, such as invoice or order changes, with caution and verify through known contacts.
- Inventory your own internet-facing network and management devices, patch them, and keep their logs; this incident began at one.
- Medtech and healthcare suppliers should test their ability to keep manufacturing and distribution running during a prolonged IT outage.
Source log / 2026-0908-BS
- Boston Scientific — Form 8-K, Item 8.01 (26 Aug 2026) Primary
- Boston Scientific — Form 8-K, Item 1.05 (report dated 7 Sep, filed 8 Sep 2026) Primary
- TechCrunch — Boston Scientific says a cyberattack is causing a 'global disruption' to its operations (26 Aug 2026) Secondary
- The Register — Boston Scientific discloses 'global disruption' in ongoing cyberattack (26 Aug 2026) Secondary
- HIPAA Journal — Boston Scientific unlikely to meet 2026 sales and profit forecast due to cyberattack (Sep 2026) Secondary
- Boston Scientific — Update on recent cybersecurity incident: final CrowdStrike investigation summary (22 Sep 2026) Primary
- CrowdStrike Services — Investigation summary prepared for Boston Scientific (22 Sep 2026) Primary