Boston Scientific said late on September 9 that manufacturing, order fulfillment and shipping are fully restored, two weeks after a cyberattack knocked out plants and distribution centers worldwide. The update, posted to the company newsroom at 7:53 p.m. Eastern, credited CrowdStrike and other outside investigators with finding no evidence of ongoing threat activity or compromise to its systems, product technologies, or cloud platforms.

The attack, detected August 25, forced the company to send Cork, Ireland staff home and pause new activations of remote cardiac device monitoring. Shipping resumed for most products by September 3. Remote monitoring activation is back online now too, and product is moving through distribution at or above normal levels, the company said.

The recovery came a day after Boston Scientific told the SEC the incident is likely to hit its bottom line. A September 8 Form 8-K filed under Item 1.05, the section reserved for material cybersecurity incidents, said the company is unlikely to meet the guidance it gave on July 29: full year adjusted EPS of $3.28 to $3.32 on 5.5 to 6.5 percent net sales growth, and third quarter adjusted EPS of $0.80 to $0.82. Shares fell more than 4 percent to $45.73 on the filing.

CEO Mike Mahoney filled in more of the picture at the Wells Fargo Healthcare Conference this week, saying every plant and distribution center was down globally and that some hospitals ordered from competitors while Boston Scientific's systems were offline. He called it too early to put a precise dollar figure on the damage. Updated guidance is due with third quarter results on October 28.

No group has claimed the attack, and Boston Scientific has not named a ransomware family or said how attackers got in. Three weeks of silence on attribution tracks with an operator playing this by the book: forensics and restoration first, naming names later, if ever.

The gap between detection and disclosure is the part other manufacturers should study. Boston Scientific filed an Item 8.01 the day after detection, then escalated to Item 1.05 two weeks later once the sales hit became quantifiable. Under the SEC's four business day disclosure clock, sizing the damage is taking longer than reacting to it, and a delayed Item 1.05 amendment is becoming the pattern for cyber incidents at device makers, not the exception.