Boston Scientific has been hit by a cyberattack that continues to hamstring its ability to process and ship customer orders, making it the latest medtech company to fall victim to a cybersecurity incident in 2026.
In a Form 8-K filed with the US Securities and Exchange Commission (SEC), Boston said it is continuing to investigate the “full scope, nature and impacts” of the incident, while the ensuing operational and financial impacts of the incident have not yet been determined.
Boston became aware of the attack affecting IT systems on 25 August, with the company disclosing the cybersecurity incident on 26 August. Boston said the incident has caused, and is expected to continue to cause, issues accessing information systems and business applications that support aspects of its operations, including its ability to process and ship customer orders.
Accordingly, the company has not yet determined whether the incident is “reasonably likely” to have a material impact, Boston stated.
In its Form 8-K filing, Boston shared that it is continuing to restore all functions and systems access provisions affected by the cyberattack, with the timeline for a full restoration as yet unknown.
Commenting on the cyberattack, Dray Agha, senior manager of security operations at cybersecurity specialist Huntress, said: “The attack on Boston Scientific demonstrates that cyber incidents in the medtech sector extend far beyond IT and actively threaten the global healthcare supply chain.
“When a major manufacturer is paralysed and unable to process or ship medical orders, the disruption creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line.
Cyberattack on Boston continues worrying trend for medtech industry in 2026
Becoming the latest victim of a cybersecurity incident for a company a part of the medtech industry, the cyberattack on Boston continues a concerning trend for the industry in 2026.
Other cyberattacks on medtech and related companies include an attack on AdaptHealth in June, <a href="https://www.medicaldevice-network.com/news/intuitive-hit-by-targeted-cybersecurity-incident/” rel=”nofollow noopener” target=”_blank”>one on Intuitive in March, and, in the same month, a targeted cyberattack on Stryker that has proven to be the most deleterious of these incidents.
The cyberattack on Stryker began in the early hours of 11 March. Claimed to have been carried out by Iran-linked hacktivist group Handala in retaliation for the US bombing Iran in its war alongside Israel, the incident thwarted the company’s ability to ship customer orders. Stryker, however, displayed resilience, with the orthopaedic implant specialist’s CEO, Kevin A Lobo, highlighting upon the release of its Q2 results in July that the company had been recovering well and “amped overall production to meet ongoing demand and support patient care.”