Boston Scientific, a medical-device maker, said the cyberattack on its IT systems remains ongoing and has affected the activation of remote monitoring communicators for new cardiac rhythm management implants implanted after August 25. The company stated that available device data will not be transmitted to remote patient management systems until the communicators are activated. Specifically, new pacemakers and other heart devices cannot provide remote monitoring, and insertable cardiac monitors (ICMs) cannot pair with the patient mobile app. However, the devices will still record episodes, and patients can transmit data via in-person interrogation using the Clinic Assistant app. The company has no timeline for full restoration but is working to partially restore shipping of some products this week. The attack also impacted manufacturing, shipping, and ordering. Boston Scientific has hired CrowdStrike for investigation and said the breach was limited to certain on-premise systems, with no further unauthorized activity seen since August 25.
Separately, pharmaceutical and medical supply giant McKesson confirmed a data breach on Saturday after ShinyHunters told The Register it had broken into the company's Snowflake and Salesforce instances and stolen millions of patients' data. McKesson's executive VP and CIO, Francisco Fraga, stated that unauthorized access to certain third-party applications and data exfiltration was associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The company has not disclosed the number of affected patients or the specific data stolen. McKesson supports about 3,300 oncology providers across 29 states. The company said distribution centers remain operational and product shipping continues.