Boston Scientific said September 22 that CrowdStrike has completed its investigation into the cyberattack the company identified on August 25, 2026. Investigators found no evidence the intruder accessed, staged, or exfiltrated data from any Boston Scientific system or application, including patient and customer data.
The intrusion started at an external-facing network management device. From there the attacker reached a limited portion of Boston Scientific's on-premises IT environment. Everything past that point stayed sealed off: Microsoft 365 and email, other cloud applications, manufacturing and maintenance systems, medical device maintenance systems, software development environments, HR systems, and any SCADA environment.
CrowdStrike ran the investigation from August 25 to September 18, 24 days that overlapped almost entirely with the plant shutdowns and shipping delays Boston Scientific has been working through since the attack began.
Containment work included disconnecting and decommissioning the compromised network device, blocking known threat actor IP addresses and domains at the firewall, resetting passwords company-wide, and hardening affected infrastructure. Boston Scientific has added CrowdStrike Falcon monitoring on top of that work.
A finding of no evidence is a forensic result, limited by what CrowdStrike could recover from logs and endpoint data. For manufacturers reading the update from outside, the open external-facing management device is the detail that carries past the headline, the kind of interface a segmentation review catches before an attacker finds it first.
Boston Scientific told customers and partners they can resume normal business activities and system connections with the company. The forensic chapter of the incident is closed. The financial one, including the third-quarter guidance miss the company flagged earlier in September, is still playing out.