Disclosed in an SEC 8 K on August 26, the intrusion has frozen order processing for stents, catheters, pacemakers, and endoscopes across 127 countries; no attack type or threat actor has been named.
Boston Scientific, a Marlborough, Massachusetts medical device maker with 13 plants, 59,000 employees, and operations in 127 countries, told the SEC on August 26 that a cyberattack detected a day earlier has frozen the systems it uses to process and ship customer orders worldwide.
In a Form 8-K filing and a parallel corporate statement, the company said the incident "has caused, and is expected to continue to cause, disruptions and limitations of access" to the IT systems that support order processing and shipping. Affected product lines include cardiology, endoscopy, urology, and peripheral interventions devices, spanning stents, catheters, pacemakers, defibrillators, and endoscopes.
Boston Scientific has activated its incident response protocols and engaged third-party cybersecurity experts. The company has not disclosed the nature of the attack, and no threat actor has publicly claimed responsibility. BleepingComputer and other security press have flagged ransomware-style disruption as a plausible explanation, but the company has not confirmed that framing.
The 8-K is explicit that the timeline for full restoration is "not yet known" and that the company "has not yet determined whether the incident is reasonably likely to have a material impact." BSX shares fell about 4.5% in Wednesday morning trading on the disclosure, according to CNBC. Piper Sandler analyst Matt O'Brien, in a note cited by CNBC, estimated that Boston Scientific "may be able to return to shipping all of its products in less than three weeks," while cautioning that "sales will likely be adversely impacted."