Massachusetts Cardiac Device Manufacturer Faces Cyberattack Impacting Global Operations
Boston Scientific, a prominent cardiac device manufacturer based in Massachusetts, has recently fallen victim to a significant cyberattack. The incident, which occurred on August 25, 2026, disrupted the company’s IT systems and operations on a global scale. In a statement released to investors and reported by ISMG, Boston Scientific acknowledged that the cyber incident led to a network outage affecting some of their critical IT systems, leaving them grappling with operational disruptions.
The details surrounding this cyberattack have raised alarm bells, especially given the increasing frequency of similar incidents targeting the medical technology sector. Following Boston Scientific’s announcement, insiders have noted that the attack is part of a troubling trend involving numerous other firms in the industry. Just this year, several high-profile medical technology and biotechnology companies have reported being the target of severe cyber intrusions, including Baxter International, Medtronic, and Abbott Laboratories. Notably, Stryker, another key player in the medical device field, experienced a highly disruptive cyber assault earlier this year.
Ross Filipek, the Chief Information Security Officer at IT and security services firm Corsica Technologies, remarked on the unsettling pattern that medical device companies are becoming increasingly familiar with: The sequence of incidents involving major companies, such as Stryker, Medtronic, Abbott, and now Boston Scientific, has occurred within a remarkably short timeframe. He emphasized that disruptions from such attacks can extend beyond the company itself, impacting order processing and shipping operations. Hospitals, even with functioning equipment, rely heavily on these manufacturers to supply essential replacement devices and medical supplies.
The intersection of cybersecurity and business continuity has become an undeniable reality in healthcare, Filipek noted. An operational outage at a manufacturer, he stated, can snowball into a broader operational problem for healthcare providers downstream, complicating the overall healthcare delivery process.
In its filing with the U.S. Securities and Exchange Commission (SEC), Boston Scientific noted that it is still in the early stages of determining whether the incident is likely to have a material impact on the company. This manufacturer produces various medical devices, including cardiac products such as pacemakers, defibrillators, and stents, along with neurological equipment including devices for brain and spinal cord stimulation. In 2025, the company reported a net revenue of $20.1 billion, highlighting its significant presence in the healthcare industry.
Upon detecting the cyber threat, Boston Scientific activated its incident response protocols and engaged third-party cybersecurity experts to investigate and contain the situation. The attack has inevitably compromised access to vital operating systems and business applications, hindering the company’s ability to process and ship customer orders. Although Boston Scientific is working diligently to restore affected functions and systems access, the full scope of the incident remains unclear.
Despite attempts to gather more details about the attack, such as the identity of the perpetrators and whether a ransom demand has been made, Boston Scientific has not provided additional information in response to inquiries from ISMG. They did confirm, however, that the comprehensive nature and implications of the incident, including any operational and financial impacts, are still being assessed.
The year has already seen prominent medical device makers and biotechnology firms suffer substantial cyber attacks. For instance, the Iranian hacktivist group Handala executed a wiper attack on Stryker in March, causing widespread disruption that lingered for weeks and affected the company’s global manufacturing and distribution operations. Handala claimed they had stolen an astonishing 50 terabytes of critical data from Stryker and permanently erased large quantities of data that had taken years and significant financial resources to protect.
Likewise, in a recent incident, extortion gang ShinyHunters claimed to have leaked 7.1 million Salesforce records from Baxter International, including personally identifiable information of patients and employees. In another case, the same group reportedly stole 9 million records from Medtronic, further exemplifying the pervasive threat facing the industry. In July, Abbott Laboratories and its cancer diagnostics division, Exact Sciences, were also reported to have suffered significant data breaches.
The scope of these cyber threats extends beyond U.S. borders, affecting global firms. The Danish drugmaker Novo Nordisk faced its own challenges as the cybercrime gang FulcrumSec claimed to have leaked extensive data from a June attack, which included sophisticated AI and machine learning elements crucial to the company’s operations.
As the frequency and scale of cyberattacks targeting the healthcare sector continue to grow, Filipek suggested that it is too early to attribute the Boston Scientific incident to any specific cybercrime group. Without any major ransomware or extortion groups publicly claiming responsibility, the investigation remains open-ended, underscoring the complex and evolving landscape of cybersecurity threats facing medical technology firms today.
In summary, the cyberattack on Boston Scientific serves as a stern reminder of the vulnerabilities that persist within the healthcare sector and highlights the importance of robust cybersecurity measures and strategic business continuity planning in mitigating the risks associated with such incidents.

