Boston Scientific earnings hit by cyberattack fallout
Medical device giant warns August intrusion will dent Q3 and full-year sales and earnings as recovery drags on.
Boston Scientific's bottom line is feeling the sting of last month's cyberattack. The medical device giant said in a regulatory filing that the disruption from the August intrusion will likely knock its third-quarter and full-year sales and earnings off course, missing the guidance it issued just weeks before the incident.
SEC filing details
The company disclosed the expected financial impact in an SEC filing published Tuesday, two weeks after an intrusion knocked systems offline and disrupted operations worldwide. Boston Scientific detected unauthorized activity on its network on August 25 and took some systems offline as it scrambled to contain the attack. At the time, it said the resulting outage had affected business applications used to process and ship customer orders, but couldn't say what the incident would ultimately cost it.
Now it has a better idea, and the news isn't great. In its latest filing, Boston Scientific said the disruption is likely to have a "material impact" on its third-quarter and full-year results, leaving it unlikely to meet the net sales growth and adjusted earnings-per-share guidance ranges issued in July.
Revenue recovery uncertain
Boston Scientific expects to recover some of the affected revenue as it clears the backlog, but does not yet know the incident's full financial impact. The company plans to update its operational and financial outlook when it reports third-quarter results on October 28.
The recovery is at least moving along. Boston Scientific said it had substantially restored its distribution network, with major distribution centers processing and shipping orders at or above normal levels. Its sterilization facilities are operational, and manufacturing has resumed at most sites worldwide.
An interruption affecting new patient activations for remote monitoring of certain cardiac devices has also been resolved, according to the filing. The company has previously said it knows of no impact on devices that are not connected to a Boston Scientific network.
Full recovery still pending
Still, the company hasn't put a date on when everything will be back to normal. It said some systems and business applications remain affected and that it cannot yet estimate when it will achieve full operational recovery.
Boston Scientific said it has identified no evidence of ongoing unauthorized access to its systems, although its investigation remains underway.
Exactly what happened remains a mystery. The company has yet to say how the attackers got in, whether ransomware was involved, who was responsible, or whether any data was stolen. No ransomware group had publicly claimed responsibility at the time of writing.
Financial guidance at risk
The company's July guidance had set expectations for net sales growth and adjusted earnings per share for both the third quarter and the full year. Missing those targets would mark a notable shift for Boston Scientific, which had been riding a wave of growth in its medical device business.
The company said it does not expect the incident to materially affect its long-term financial condition, even if its outlook for 2026 looks considerably less healthy since intruders breached the network.
Why it matters for the industry
Boston Scientific's warning underscores the real-world consequences of cyberattacks on medical device makers, extending beyond data breaches to direct hits on revenue and operations. The fact that a major company is publicly revising its financial guidance due to a cyber incident suggests that the cost of such attacks is not just technical but deeply financial.
For hospitals and healthcare providers that rely on Boston Scientific's products, the delay in recovery could mean supply chain disruptions, though the company says distribution centers are back to normal levels. The incident also raises questions about the resilience of medical device supply chains, which are critical to patient care. As investigations continue, the full scope of the impact — including any potential data compromise — remains unknown, but the financial fallout is already clear.
Sources
- The Register Original source
- an SEC filing published Tuesday Also reporting
Continue Reading
Spending Spree Unravels $240M Crypto Heist
Young scammers' lavish purchases led FBI to suspects in $240M bitcoin theft.
Grindr's £26M Settlement and the Stakes for User Trust
Grindr agrees to pay £26m to settle U.K. claims over pre-2020 data sharing, without admitting liability.
Fake IT help desks push M365 data theft
Executives targeted in vishing attacks that steal tokens and extort victims.