Boston Scientific cannot yet quantify cyberattack costs, CEO says
Boston Scientific CEO Mike Mahoney told the Wells Fargo Healthcare Conference on September 11 that all of the company's plants and distribution centers were shut down globally during its August cyberattack, and that it still cannot pinpoint a dollar impact ahead of the October 28 earnings call.
Stryker CFO Preston Wells told the Wells Fargo Healthcare Conference on September 10 that the March cyberattack will cost 70 to 80 basis points of third quarter sales, about $45 million, concentrated in the peripheral vascular unit built from the Inari Medical acquisition. Shares fell more than 10 percent for the week.
PULSE
Latest Intelligence
ENISA updated its list of CSIRTs designated as coordinators on September 4, 2026, covering all 27 member states, one week before Article 14 reporting obligations apply on September 11. The Single Reporting Platform launches with no API and no support for voluntary reporting under Article 15. Registration runs through EU Login with multi factor authentication, and platform downtime does not pause the 24 hour clock.
Philips published a September 4 advisory for CVE-2026-75604, a Next.js path traversal scored 9.0 that lets remote requests read private build data on Windows hosts and reach remote code execution. Versions 13.4.0 through 15.5.23 and 16.0.0 through 16.3.2 are affected, and Vercel fixed it in 15.5.24 and 16.3.3. Philips says no Philips products are known to be impacted at this time.
SonicWall disclosed CVE-2026-83548, a pre-authentication SSRF in SMA1000 appliances with a base score of 10.0, and CVE-2026-83549, an OS command injection, on September 1. Attackers chained them in the wild before disclosure. CISA added both to the KEV catalog September 3; hotfixes 12.4.3-03526 and 12.5.0-02952 fix them.
Boston Scientific said in a September 3, 2026 update that it has begun restoring shipping capabilities for the majority of its products at its major distribution centers globally. The company reports growing confidence that the unauthorized access was limited to select internal-facing IT infrastructure, with no unauthorized activity detected since August 25. Whether personal data was compromised is still under investigation.
Novocure disclosed in a September 1, 2026 SEC filing that attackers accessed some of its information systems in mid-August after entering through a subsidiary. Internal ID numbers for more than 1,400 US patients were exposed, along with identifying information for fewer than 50 patients in the western United States. The company filed under Item 8.01, says no medical treatment devices were reached, and reports all systems fully functional.
A federal court in Colorado granted preliminary approval on August 21, 2026 to a settlement of up to $15 million in Jenkins et al. v. DaVita Inc., resolving class litigation over the April 12, 2025 Interlock ransomware attack that compromised data on 2,689,826 dialysis patients. Class members can claim up to $2,500 in documented losses plus a cash payment expected near $50.
SponsoredAI-Native Medical Device Pentesting and Vulnerability Management.
Advertise on MedDevice Cyber →Put your platform in front of the security engineers, regulatory affairs leads, and device makers who read MedDevice Cyber every day.
Become a Sponsor → →