A Major Medical Device Maker Was Hit by a Cyberattack. Here's What We Know.

Boston Scientific, a large medical device company based in Massachusetts, has told federal regulators that a cyberattack is causing an ongoing "global disruption" to its operations. The company said that on Tuesday it started losing access to key computer systems and business software it needs to run its business (TechCrunch.
The attack has affected Boston Scientific's ability to ship products and process orders, according to a filing with the SEC, the U.S. government agency that oversees publicly traded companies. The company said the disruption is expected to continue while it works on recovery (Reuters. The news sent the company's shares down about 4% (Journal Record.
Boston Scientific published a public statement on its own website saying its investigation is ongoing and that it does not yet know when systems will be back to normal (Boston Scientific. The update is currently placed on the company's homepage under a "Company news" section, alongside content about corporate responsibility and team culture (Boston Scientific Home).
Company spokesperson Chanel Hastings shared the statement but would not say whether patients are affected or what steps patients should take (TechCrunch. Boston Scientific treats approximately 48 million patients per year, according to its website.
The impact has been felt at the company's international sites. Local media in Ireland reported that thousands of staff at Boston Scientific's campus in Cork were sent home on Tuesday after the company's internal networks were shut down (TechCrunch. According to public internet records, Boston Scientific relies largely on Microsoft and Amazon Web Services for its corporate computer systems.
Boston Scientific confirmed on Wednesday that the cyberattack was disrupting its global operations, including some systems used to process and ship orders (Reuters.
The company has not said what kind of attack it was, who carried it out, or whether any data was stolen. The SEC filing was required under rules the agency adopted in 2023, which say that publicly traded companies must report serious cyberattacks within four business days of deciding the incident is significant enough to matter to investors.
What makes this incident stand out is the type of company involved and what it makes. Boston Scientific is not a retailer or a bank where a cyberattack might mean delayed packages or frozen accounts. It makes implantable medical devices — things like pacemakers, defibrillators, and stents — that doctors use in time-sensitive procedures. When the systems that process and ship these devices go down, the effect goes beyond lost sales. Hospitals that depend on getting specific device models delivered on schedule for planned procedures may have to scramble for alternatives or delay care.
In my view, the company's refusal to address whether patients are affected is a significant gap. For a firm that treats 48 million patients a year, even a brief disruption to shipping could create shortages at hospitals that keep limited device inventory on hand. Placing a cybersecurity update next to corporate culture content on the homepage also suggests the company is still figuring out how publicly to respond to the seriousness of what happened.
The company's reliance on Microsoft and Amazon for its computer systems is worth noting, though it is still unknown how the attackers got in. If the attack came through a weakness in a cloud service, it would be similar to other incidents where one provider's breach spread to many customers at once. If instead the attackers broke directly into the company's own network, the Cork campus shutdown, with its complete network cutoff, would suggest the company was trying to contain a threat that was spreading from one system to another inside the company.
The roughly 4% drop in the company's share price, while noticeable, is relatively modest for a major medical device firm facing an active cyberattack with no end in sight. That restraint likely reflects the fact that investors have seen this before. Cyberattacks have become a recurring event in healthcare and manufacturing over the past several years, and the stock market has, in a sense, already factored in this kind of risk for large medical device companies.
Several important questions remain unanswered: how long the disruption will last, whether patient data was compromised, and whether the attack reached any systems connected to the company's medical devices themselves. Boston Scientific has not said whether the incident affected its manufacturing control systems — the specialized computers that run factory production lines — which would be a different and potentially more serious situation than a business-software outage. Until the company shares more detail, the impact on patients and their data remains an open question that the current disclosure does not begin to answer.


