Boston Scientific Hit By Cyberattack, Global Order Shipments Disrupted

The medical device maker says it detected an intrusion on August 25 that knocked out business systems and stopped some customer orders from going out.

ThreatVectr Newsdesk· 3 min read
Full-frame overhead view of a generic fast-food mobile ordering app open on a smartphone resting on a wooden table, next to a paper cup and a red drink tray, wa
Share

Key points

  • Boston Scientific detected a cyberattack on August 25, 2025 that disrupted IT systems worldwide.
  • The company says the intrusion stopped it processing and shipping some customer orders.
  • Boston Scientific disclosed the incident to the U.S. Securities and Exchange Commission but has not named the attacker or the method used.
  • No ransomware gang has publicly claimed the breach.
  • The Massachusetts firm employs 59,000 people across 127 countries and reported over $20 billion in 2025 revenue.

Medical device giant Boston Scientific has been hit by a cyberattack that knocked parts of its IT network offline and disrupted operations around the world.

The company says it spotted the intrusion on August 25 and confirmed the details in a filing with the U.S. Securities and Exchange Commission, the American financial regulator that requires public companies to disclose serious incidents to investors.

Some operating systems and business applications went down. That included the systems Boston Scientific uses to process and ship customer orders, meaning hospitals and clinics waiting on stents, catheters, pacemakers or defibrillators may see delays.

The company has not said when everything will be back to normal.

What actually happened?

Someone broke into Boston Scientific's corporate network. The company detected it on August 25, activated its incident response plan, and brought in outside cybersecurity specialists to contain the damage and investigate.

Beyond that, details are thin. The SEC filing does not name the attackers, describe how they got in, or say whether any patient or employee data was stolen. No ransomware group, criminals who lock a victim's files and demand payment to unlock them, has publicly claimed responsibility so far.

BleepingComputer first reported the disruption after Boston Scientific's regulatory filing went live.

Who is Boston Scientific and why does this matter?

Boston Scientific is one of the world's largest makers of medical devices, the small pieces of hardware doctors use in minimally invasive procedures. Think heart stents that prop open arteries, catheters, pacemakers that regulate heartbeats, defibrillators, and endoscopes.

The company is based in Massachusetts, employs 59,000 people, runs 13 manufacturing plants, sells into 127 countries, and pulled in over $20 billion in revenue in 2025.

When a supplier that size cannot ship, the effects ripple into hospitals, surgical schedules and, eventually, patients.

Should patients or hospital staff be worried?

Not immediately, but pay attention to two things.

First, if a scheduled procedure relies on a specific Boston Scientific device, hospitals may need to reschedule or substitute. Ask the clinic directly rather than assuming.

Second, watch for phishing emails, fake messages designed to trick you into handing over passwords or clicking malicious links, that pretend to come from Boston Scientific or a hospital supplier. Attackers often piggyback on real news like this. If a message asks for login details or urgent payment, verify by phone using a number you already trust.

What we know so far

Detail What Boston Scientific has said
Date detected August 25, 2025
Impact Network outage, disrupted order processing and shipping
Systems affected Certain operating systems and business applications
Attacker identified No
Data theft confirmed Not disclosed
Restoration timeline Unknown

What is still unclear

The big open questions are whether this is ransomware, whether patient data or employee records were taken, and how the attackers got a foothold in the first place. On that last point, valid stolen credentials remain the most common way into large enterprises, and multi-factor authentication (MFA), which requires a second check like a phone prompt beyond the password, would honestly help in a lot of these cases. Whether it would have helped here, we do not yet know.

Boston Scientific says the investigation is ongoing and it is still working out the operational and financial fallout. Expect more detail in the company's next SEC filing.

© 2026 Threat Vectr