Boston Scientific Still Recovering From Cyberattack
Boston Scientific is recovering from a cyberattack that disrupted global operations and manufacturing.
Summary
Medical technology company Boston Scientific is still recovering from a cyberattack detected on August 25th, which caused a global network outage impacting manufacturing, order processing, and shipping. While the company stated that existing implantable cardiac devices were unaffected, new remote activations for some cardiac monitors were disrupted. Cybersecurity experts, including CrowdStrike, have been engaged to investigate the incident, which appears to be limited to on-premises systems.
Full text
Nearly one week after being hit by a highly disruptive cyberattack, US medical technology giant Boston Scientific is still recovering and working on resuming operations. Boston Scientific detected an intrusion into some of its IT systems on August 25 and disclosed the incident the next day. The cyberattack led to a network outage that disrupted global operations, including product manufacturing, customer order processing, and shipping. Boston Scientific develops and manufactures devices and therapies used in cardiology, neurology, and oncology. The company said the hacker attack did not affect existing implantable cardiac rhythm management (CRM) devices, but it did disrupt new remote activations for some cardiac monitors. CrowdStrike and other cybersecurity experts have been called in to assist with the investigation. Advertisement. Scroll to continue reading. In updates shared over the weekend, Boston Scientific said it found no signs of malicious activity on its networks since August 25, and the breach appears to be limited to some on-premises systems. The company hopes to resume shipping some products at least partially this week, but it could not provide a full restoration timeline. It’s still unclear who is behind the attack. No known cybercrime group appears to have taken credit for the breach. Related: Berlin Won’t Pay Extortion Group Claiming Data Theft Related: Hasbro Data Breach Exposed Employee Personal Information Related: Sensitive Information Exposed in Nutex Health Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own SystemsTech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense PledgePaperCut Releases Emergency Patch for Exploited Zero-DayTrump Order Aims to Block Foreign Backdoors in US Power Grid GearAustralia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackCyberattack Causes Global Disruption at Boston ScientificUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Latest News Critical Ruby on Rails Vulnerability in Attackers’ CrosshairsExtortion Group Claims Manchester Airports Group Data BreachJudge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’Berlin Won’t Pay Extortion Group Claiming Data TheftMore Details Emerge on Exploited PaperCut VulnerabilitiesHasbro Data Breach Exposed Employee Personal InformationIn Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker SanctionsATF Confirms Cyber Incident After Ransomware Group Claims Attack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email