Boston Scientific has begun restoring shipping capabilities for the majority of its products at its major distribution centers globally. The company posted the news at 4:29 pm ET on September 3, its seventh newsroom update since detecting the cyberattack on August 25. It has not given a date for full restoration.
The scope statement tightened as well. Boston Scientific now reports growing confidence that the unauthorized access was limited to select internal-facing IT infrastructure. No unauthorized activity has been detected in its environment since August 25, the day it found the intrusion. Cloud-based systems and applications remain unaffected.
The data question stays open. The company says it is still determining whether personal data was compromised, and that if it confirms exposure it will notify affected individuals, regulators, and customers and provide support services in accordance with privacy laws. CrowdStrike and other third-party experts continue to work the investigation and forensics.
Order intake never stopped. Customers continue to submit orders electronically through EDI and local applications, and those orders queue for fulfillment as processing and shipping systems come back. The queue has been building since August 26, when an 8-K disclosed the company could not process or ship customer orders.
The recovery arc now runs nine days: detection on August 25, the 8-K on August 26, a manufacturing stop disclosed on August 28, a containment line drawn on August 30, and further updates on September 1 and September 3 as shipping came back for most of the catalog.
Distribution recovers ahead of production because a warehouse can ship from inventory the moment its systems return. The harder restart is the validated manufacturing line behind it, and the slower answer is the data one, which tends to arrive weeks after the forensic images do. Watch whether the order backlog clears before hospitals start reporting backorders on cardiac and endoscopy lines.