Boston Scientific, a major global manufacturer of medical devices such as pacemakers, stents, and defibrillators, disclosed in a regulatory filing on Wednesday that it is experiencing a “cybersecurity incident” that has caused a “global disruption to the company’s operations.” The attack, which began on Tuesday, has limited access to certain information systems and business applications, including those used to process and ship customer orders.
The company said it has engaged third-party forensic experts to investigate and contain the breach, but it has not yet provided a timeline for full restoration. The full scope, nature, and financial and operational impacts remain unknown, according to the filing. Boston Scientific did not immediately respond to inquiries from The Register, and as of press time, no ransomware group or other threat actor had claimed responsibility.
The incident follows a string of cyberattacks on medical technology firms. In March, Stryker experienced a global network outage after a breach linked to Iranian state-backed hackers. In April, Medtronic disclosed a cyberattack that later was claimed by the extortion group ShinyHunters, resulting in the theft of patient data including names, Social Security numbers, and health information. The medical device sector has become a high-value target for both financially motivated ransomware gangs and state-sponsored actors, given the critical nature of its products and the sensitivity of patient data.
Boston Scientific has not specified whether the current attack is ransomware or whether any data has been exfiltrated. The company’s stock fell more than 4% on Wednesday, reflecting investor concern about potential operational disruptions, regulatory penalties, and reputational damage. The company operates in more than 100 countries and reported over $14 billion in revenue in 2025.