Medical device giant Boston Scientific (NYSE: BSX) said on August 26, 2026 that it has been hit by a cyberattack that is disrupting operations globally, including its ability to process and ship customer orders, according to an announcement and a filing with the U.S. Securities and Exchange Commission.
Incident detected August 25
The Marlborough, Massachusetts company identified the intrusion on August 25 and said it caused a network outage that "impacted access to certain operating systems and business applications." Boston Scientific activated its incident response procedures and engaged an external cybersecurity firm to help with assessment, containment and forensics. The company said the full restoration timeline is not yet known and that the operational or financial consequences remain under investigation.
Regulatory disclosure and attacker attribution
In the Form 8-K filed with the SEC on August 26, Boston Scientific did not name the attacker, disclose the initial access vector or say whether any data has been exfiltrated. A pro-Russian hacker group calling itself Server Killers claimed responsibility, though no independent verification has been offered and no known ransomware or data-extortion leak site had posted Boston Scientific stolen material at the time of disclosure.
Scale of the disruption
Boston Scientific is one of the largest medical device manufacturers in the world, with 59,000 employees, 13 manufacturing sites, a presence in 127 countries and 2025 revenue north of $20 billion. Its cardiology stents, catheters, pacemakers, defibrillators, endoscopes and neuromodulation devices are used in thousands of hospitals worldwide, so any prolonged order-processing outage will ripple through hospital purchasing and scheduled interventional procedures.
Widening pattern of medtech attacks
The incident continues a punishing run for medical device and healthcare-technology companies in 2026. Coverage of adjacent breaches this week includes CareCloud's confirmation of 3.75 million patient records stolen from AWS, the ShinyHunters campaign against McKesson and the Manchester Airports Group data theft affecting 8.7 million travellers. Boards and cyber insurers are increasingly focused on the availability of operational-technology systems in regulated industries, not just data confidentiality.
Reporting based on coverage from BleepingComputer, The Register, HIPAA Journal, CBS News and Boston Scientific's SEC 8-K filing.
