Boston Scientific disclosed on August 26 that a cyberattack is disrupting its operations worldwide. The company detected the incident on August 25, activated incident response protocols, and brought in third-party cybersecurity experts. An 8-K filed on the 26th says the network outage has cut access to certain operating systems and business applications, including the ability to process and ship customer orders.
The company says the timeline for full restoration is not yet known, and neither are the full scope, nature, and operational and financial impacts. At the Cork campus in Ireland, thousands of staff were told to work from home, per the Irish Examiner. Boston Scientific declined to tell TechCrunch whether patient-facing devices were affected or whether data left its systems. No attacker has been named.
Markets treated the unknowns as material. Shares fell nearly 6 percent in premarket trading to $47.09 and stayed down more than 4 percent after the open. Stifel analysts wrote that there is now increased uncertainty around the company's 2026 revenue, margin, and earnings per share outlook.
Boston Scientific, which treats about 48 million patients a year, becomes the tenth medtech company with a disclosed cyber incident in 2026, five days after MedTech Dive counted nine. The Stryker attack in March showed what this looks like from here: weeks of disrupted ordering, shipping, and manufacturing, and a material quarter. Every hour of ERP downtime at a device maker converts directly into hospital backorders, so the recovery clock is the number that matters now.