OTSecurity

Boston Scientific faces ongoing operational disruption after cybersecurity incident impacts IT systems, order processing


Medical equipment manufacturer Boston Scientific identified a cybersecurity incident affecting certain information technology systems that resulted in a network outage and disruption to the company’s operations. The company revealed in an SEC Form 8-K filing that the cybersecurity incident affected certain of its IT systems, leading to a global disruption to the company’s operations.

Susan Thompson, vice president, chief corporate counsel and assistant secretary at Boston Scientific, wrote in the filing that the incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the company’s information systems and business applications that support aspects of the company’s operations, including the ability to process and ship customer orders. 

“Once detected, the company activated incident response protocols and began an investigation to assess and contain the threat with the assistance of third-party cybersecurity experts,” Boston Scientific wrote in a Tuesday post on the cybersecurity incident. “The incident has impacted access to certain operating systems and business applications, including the ability to process and ship customer orders.”

It added that the investigation into the cybersecurity incident is ongoing. While the company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.

Commenting on the cybersecurity incident, Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, wrote in an emailed statement that a cardiac device that misses its ship date can mean a cancelled surgery. “That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for.”

“Medical devices also aren’t something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them. Disrupt order processing and shipping and the consequences show up in hospitals pretty quickly,” Krell assessed. “The harder problem is getting manufacturing back online. These aren’t ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another.”

He added, “You can’t ship something that gets implanted in a human body on trust alone. If production or quality systems were affected, Boston Scientific may have to establish that records are intact and trustworthy before normal operations resume.”

“That’s why employees at Boston Scientific’s manufacturing facility in Cork, Ireland being sent home matters,” Krell pointed out. “This isn’t just people losing access to email. The company has already confirmed disruption to order processing and shipping, and Cork shows that disruption reaching manufacturing operations. If quality or production data was also affected, getting the servers running could be the easy part.”

 “When a cyberattack halts order fulfillment and logistics across a global enterprise, an IT security incident becomes an immediate revenue and medical supply chain crisis. Because details regarding the initial attack vector remain sparse, it is not possible to recommend specific preventive technical steps for other organizations,” Damon Small, board of directors at Xcape, wrote in an emailed statement. “That said, cybercriminals are often opportunistic and exploit vulnerable systems as soon as they discover them; it is currently unknown whether this was a targeted attack or just bad luck. Regardless of the entry point, disruption to core business applications forces defensive network isolation to stop lateral movement.”

He added that “To maintain operational continuity during an ongoing intrusion, security teams must enforce strict logical boundaries between corporate administrative networks and fulfillment environments, maintain immutable offline backups, and regularly validate manual failover protocols.”

Earlier this year, the U.S. CISA (Cybersecurity and Infrastructure Security Agency) confirmed it is tracking malicious cyber activity targeting endpoint management systems across the nation’s organizations, following the March 11, 2026, cyberattack on medical technology giant Stryker Corp., which reportedly wiped corporate devices connected to the firm’s Microsoft environment and forced the company to restrict access to certain information systems while incident responders worked to contain the breach and restore operations. The incident, which has been linked in reporting to suspected Iran-aligned threat activity amid heightened Middle East tensions, highlights growing risks to critical healthcare and enterprise IT infrastructure.



Source link