Boston Scientific hit by cyberattack, halting order processing

Boston Scientific disclosed a cyberattack that disrupted its IT systems and business applications, including order processing and shipping, on August 25. The company has activated incident response and engaged external experts, but the full restoration timeline is unknown. No details about the attacker or data exposure have been released, and no ransomware group has claimed responsibility.
Boston Scientific's global footprint makes this disruption particularly consequential. With roughly 59,000 employees, 13 manufacturing sites, and operations spanning 127 countries, the company supplies stents, pacemakers, defibrillators, and other devices used in minimally invasive procedures. Annual revenue exceeded $20 billion in 2025, and any prolonged halt in order processing and shipping could ripple through hospital supply chains and scheduled procedures worldwide.
The company's SEC filing offers few specifics: no attacker identity, no initial access method, and no confirmation of data exposure. No ransomware group has yet claimed responsibility, and Boston Scientific has not indicated whether extortion demands were made. The company has activated incident response protocols and brought in external cybersecurity experts, but has stated that a full restoration timeline remains unknown.
This incident could affect hospitals, clinics, and patients who depend on Boston Scientific's medical devices for time-sensitive procedures. Delays in order processing and shipping may postpone surgeries or force healthcare providers to seek alternative suppliers, potentially straining already limited inventories. If patient or business data was compromised, privacy concerns could emerge for individuals and partner organizations. The company's global reach means disruptions may be felt across multiple healthcare systems, though the full operational and financial impact remains uncertain.