Boston Scientific just told the SEC that a cyberattack is disrupting its ability to ship medical devices worldwide.
The Massachusetts-based device maker filed an 8-K this week confirming it detected an intrusion, activated its incident response protocols, and brought in outside cybersecurity experts to help contain the threat. The company hasn't disclosed what kind of attack this is or who is behind it, and no group has claimed responsibility. The filing describes disrupted IT systems and degraded order processing and shipping, with no restoration timeline given, a pattern typical of ransomware. Boston Scientific says there is no evidence yet that any data was stolen.
Boston Scientific is not a niche player. It makes pacemakers, stents, and endoscopy tools sold in more than 100 countries, putting it in the same league as Medtronic, Abbott, and Johnson & Johnson MedTech. When a company that size cannot process orders, hospitals waiting on cardiology or urology devices feel it fast, and this is not just a headache for shareholders.
Healthcare's supply chain, not just its patient records, has become a favorite ransomware target. Change Healthcare learned that lesson in 2024, when a ransomware attack froze claims processing for weeks. Boston Scientific will be hoping its own recovery is much quicker.