Boston Scientific filed a second Form 8-K on the August cyberattack on September 8, 2026, and this one landed under Item 1.05, Material Cybersecurity Incidents. The August 26 filing had used Item 8.01, the voluntary shelf a company reaches for when it cannot yet judge materiality. The incident itself was identified on August 25, 2026.
The new filing says the incident is likely to have a material impact on results of operations for the third quarter and full year 2026, and that the company is unlikely to meet the net sales growth and adjusted EPS guidance ranges it issued on July 29, 2026. Those ranges were full year adjusted EPS of $3.28 to $3.32 on net sales growth of 5.5 to 6.5 percent, with third quarter adjusted EPS of $0.80 to $0.82 on growth of 3 to 5 percent. Shares fell more than 4 percent to $45.73. A revised outlook arrives with third quarter results on October 28, 2026.
Recovery is well along. Boston Scientific reports substantial restoration of its distribution network, with major distribution centers processing and shipping customer orders at or above normal operating levels, sterilization facilities operational, and manufacturing resumed across most facilities globally. In a newsroom update the same morning the company said product quality analyses indicate no impairment to product function, and that remote monitoring activations for cardiac device implant communicators and ICM remote monitoring can now resume. The timeline for full operational recovery is still uncertain.
The filing leaves the forensics open. It does not name an entry vector, does not say whether data was taken, and no ransomware group has publicly claimed the attack in the two weeks since detection. Boston Scientific says it has found no evidence of ongoing unauthorized access, and the investigation continues with third party cybersecurity experts.
Item 1.05 requires a filing within four business days of determining that an incident is material, and that determination has to be made without unreasonable delay. Thirteen days passed between detection and the determination here, with interim updates running through the company newsroom in the meantime. Forensics was not the gating factor. Sizing a revenue hole against a published guidance range takes operational data from restored systems, and that data only showed up as distribution and manufacturing came back online.
For a product security team the useful figure is that interval: 13 days from detection to a materiality call at a company with a mature response function and outside help already engaged. A disclosure committee cannot make that call without numbers only the responders hold. Wire the finance and disclosure inputs into the incident response plan before the plan gets used.