Breaking
SecurityDeveloping Story

Boston Scientific outage shows medical device exposure

Medtech firm discloses cyberattack disrupting global operations, with no timeline for full restoration.

··2 hours ago·2 min read
a hand holding a smart watch
Photo by Nappy on Unsplash

Boston Scientific, one of the world's largest medical device makers, disclosed Wednesday that an ongoing cyberattack has disrupted its global operations, leaving the company without a timeline for restoring its IT systems. The admission, made in a filing with the U.S. Securities and Exchange Commission, marks the latest in a string of intrusions targeting the medical technology sector this year.

A Tuesday intrusion, a Wednesday disclosure

According to the SEC filing, the 'cybersecurity incident' began on Tuesday and resulted in a 'global disruption to the company's operations.' Upon detecting the intrusion, Boston Scientific initiated an investigation with third-party information security experts who are working to contain the threat, the filing states.

The company has not said whether the attack involved ransomware, nor has it disclosed whether any data was stolen. The Register's inquiries to Boston Scientific, including questions about the nature of the attack and potential data theft, went unanswered as of publication time.

Operations hit at the order-processing stage

The disruption is already affecting the company's ability to conduct normal business. In its filing, Boston Scientific reported that the incident 'has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the company's information systems and business applications that support aspects of the Company's operations, including the ability to process and ship customer orders.'

The company acknowledged that the 'full scope, nature and impacts, including operational and financial impacts' of the cyberattack remain unknown, and it has not provided a timeline for when systems might be fully restored.

Market reacts negatively

The news rattled investors. Boston Scientific's shares fell more than 4% on Wednesday morning following the disclosure, reflecting concerns about the potential operational and financial fallout from the ongoing incident.

As of press time, no known ransomware or extortion group had claimed responsibility for the attack, leaving the identity and motives of the attackers unclear.

A troubling pattern in medtech

The incident is not an isolated one. In recent months, both ransomware gangs and government-backed hackers have disrupted operations and stolen sensitive data from other medical device makers.

In March, Stryker was hit by a cyber crew with ties to Iran's intelligence agency, causing a global network outage at the company. A month later, medical-device maker Medtronic disclosed a cyberattack in a filing with federal regulators. Notorious data-theft-and-extortion group ShinyHunters claimed to be behind that intrusion, and Medtronic in July warned patients that their names, contact details, dates of birth, Social Security numbers, and health information were stolen in the breach.

Why it matters

The extended disruption at Boston Scientific could have serious implications for hospitals, clinics, and patients who rely on its devices, which range from pacemakers to surgical tools. If the company cannot process or ship orders for an extended period, that could create medical supply shortages.

For the medtech industry as a whole, this incident suggests that attackers are increasingly targeting device makers — a trend that could force companies to invest more heavily in cyber defenses and incident response.

#boston scientific#cyberattack#medical devices#sec filing#ransomware#medtech

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories