Boston Scientific has been hit by a cyberattack that continues to hamstring its ability to process and ship customer orders, making it the latest medtech company to fall victim to a cybersecurity incident in 2026.
In a Form 8-K filed with the US Securities and Exchange Commission (SEC), Boston said it is continuing to investigate the “full scope, nature and impacts” of the incident, while the ensuing operational and financial impacts of the incident have not yet been determined.
Discover B2B Marketing That Performs
Combine business intelligence and editorial excellence to reach engaged professionals across 36 leading media platforms.
Boston became aware of the attack affecting IT systems on 25 August, with the company disclosing the cybersecurity incident on 26 August. Boston said the incident has caused, and is expected to continue to cause, issues accessing information systems and business applications that support aspects of its operations, including its ability to process and ship customer orders.
Accordingly, the company has not yet determined whether the incident is “reasonably likely” to have a material impact, Boston stated.
In its Form 8-K filing, Boston shared that it is continuing to restore all functions and systems access provisions affected by the cyberattack, with the timeline for a full restoration as yet unknown.
Commenting on the cyberattack, Dray Agha, senior manager of security operations at cybersecurity specialist Huntress, said: “The attack on Boston Scientific demonstrates that cyber incidents in the medtech sector extend far beyond IT and actively threaten the global healthcare supply chain.
“When a major manufacturer is paralysed and unable to process or ship medical orders, the disruption creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line.
Cyberattack on Boston continues worrying trend for medtech industry in 2026
Becoming the latest victim of a cybersecurity incident for a company a part of the medtech industry, the cyberattack on Boston continues a concerning trend for the industry in 2026.
Other cyberattacks on medtech and related companies include an attack on AdaptHealth in June, one on Intuitive in March, and, in the same month, a targeted cyberattack on Stryker that has proven to be the most deleterious of these incidents.
The cyberattack on Stryker began in the early hours of 11 March. Claimed to have been carried out by Iran-linked hacktivist group Handala in retaliation for the US bombing Iran in its war alongside Israel, the incident thwarted the company’s ability to ship customer orders. Stryker, however, displayed resilience, with the orthopaedic implant specialist’s CEO, Kevin A Lobo, highlighting upon the release of its Q2 results in July that the company had been recovering well and “amped overall production to meet ongoing demand and support patient care.”
Following the attack on Stryker, the US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert advising organisations to harden their security posture by tightening their network security provisions, among other advisements.
“Modern cyberattacks quickly bridge the gap between digital networks and physical operations, and this should underscore why manufacturing and medical tech companies must prioritise strict network segmentation, ensuring that an intrusion in one corporate IT environment doesn’t completely derail global business continuity,” Agha added.
