Boston Scientific Cyberattack Limited to Unauthorized Access on Certain On-Premises Systems
![]()

![]()

![]()
Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return.
The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applications underpinning day-to-day operations.
Boston Scientific is among the world's largest medical device manufacturers, reporting $20.07 billion in 2025 revenue and about $21 billion over the trailing 12 months. Its portfolio includes pacemakers, defibrillators, cardiac stents and neuromodulation implants, and the company says its products treat roughly 48 million patients a year. Thousands of employees in Ireland, where Boston Scientific operates three manufacturing and research sites, were told to work from home on August 26 after network communications were severed.
The company said it activated incident response protocols and engaged outside cybersecurity specialists to contain and investigate the intrusion. It has not said whether ransomware was involved, whether data was exfiltrated, or whether the disruption touches patients with implanted devices. No extortion group had claimed responsibility as of August 26. Shares fell more than 4% following the disclosure.
A Boston Scientific spokesperson declined to answer questions about patient impact and directed reporters to the published statement. Neither the company nor U.S. regulators have said whether hospital procedures have been delayed as a result of the shipping halt, though device suppliers typically hold limited on-site inventory at hospitals, making sustained order outages a downstream supply concern.
The incident is the third disruptive attack on a major medical technology firm in six months. Stryker suffered a global network outage in March after attackers abused its Microsoft Intune deployment to wipe data from thousands of devices, and Medtronic disclosed in April that patient names, Social Security numbers and health information were exposed in a breach attributed to the ShinyHunters extortion group.
Boston Scientific said it cannot yet assess the full operational and financial impact, language that leaves room for an amended filing once the investigation matures.
The company's Irish footprint also raises the prospect of European scrutiny. If personal data proves to have been accessed, notification duties under the General Data Protection Regulation would attach, and medical device manufacturers operating in the European Union are increasingly captured by the NIS2 Directive's incident reporting regime as member states complete transposition.

![]()

![]()

![]()

![]()

![]()

![]()

![]()
A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.
The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.
According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.
An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.
As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.
The retailer said investigators are still determining whether any personal information has been compromised.
Based on the information currently available, data that may be involved includes:
De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.
The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.
For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.
De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.
Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.
The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.
The company said it will never request credit card details, gift card information, or other sensitive information via email.
The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.
In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.
For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

![]()

![]()

![]()

![]()

![]()
Kenya is investigating a Kenya cyberattack that temporarily defaced President William Ruto’s official website with an anti-government message and a Bitcoin ransom demand for five bitcoins, reportedly worth about $330,000. The attackers replaced the website’s homepage with the message, displayed a cryptocurrency wallet address and threatened to publish unspecified information about President William Ruto unless the ransom was paid.
The website was hacked on Saturday, July 18, 2026. Following the incident, access to the presidential website was temporarily restricted as authorities began containment, forensic analysis and restoration efforts. According to local media reports, access to the website was restored by Monday.
Kenya’s Ministry of Information, Communications and the Digital Economy confirmed that the official website of the President had been affected by a cybersecurity incident.
The ministry said that after the incident was detected, the ICT Authority immediately activated established cybersecurity incident response protocols.
As a precautionary measure, access to the presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts.
The ministry said appropriate mitigation measures had since been implemented and that restoration of the website was underway.
[caption id="attachment_113245" align="aligncenter" width="600"]At the time of the statement, the government said there was no evidence of unauthorized access to sensitive data, data exfiltration or loss of information. It also stated that government systems and digital services remained secure and operational.
The ICT Authority is working with relevant government agencies and technical partners to conduct a comprehensive forensic investigation and establish the full circumstances surrounding the incident.
The Kenya President William Ruto cyberattack involved the defacement of the president’s official website. The attackers replaced the homepage with an anti-government message, displayed a cryptocurrency wallet address and demanded five bitcoins.
The attackers also threatened to publish unspecified information about President William Ruto if the ransom was not paid.
The government has not reported evidence of unauthorized access to sensitive data or data exfiltration. The ongoing forensic investigation is expected to establish the circumstances surrounding the incident and determine the extent of the attack.
The latest Kenya government website hack follows previous cyber incidents involving government digital services and websites.
In July 2023, Kenya’s eCitizen platform, which is used for dozens of public services, was disrupted by a cyberattack. The incident affected agencies including the National Transport and Safety Authority and Kenya Power.
On November 17, 2025, hackers launched a coordinated attack on several government websites, including the presidency’s portal. The websites were temporarily knocked offline, while some pages were replaced with extremist messages.
According to the information provided by local media, the government later blamed a group calling itself PCP@Kenya, restored the affected platforms and promised stronger cyber defences.
The latest incident involved a Bitcoin ransom demand for five bitcoins, reportedly valued at approximately $330,000. The attackers displayed a cryptocurrency wallet address and threatened to release unspecified information about the president.
It remains unclear from the available information whether the attackers accessed systems or data beyond the presidential website. The Kenyan government has said there is currently no evidence of unauthorized access to sensitive data, data exfiltration or loss of information.
The ICT Authority and relevant government agencies are continuing their forensic investigation to establish how the incident occurred and determine the full circumstances surrounding the Kenya cyberattack.

![]()

![]()

![]()

![]()
A vishing call to an overseas contact center agent. A fake IT ticket. A default setting nobody thought to lock down. That's all it took to expose the personal data of roughly 5 million Australians — and now the country's privacy regulator has decided Qantas isn't to blame for it.
The Office of the Australian Information Commissioner (OAIC) closed the book this week on its year-long preliminary inquiry into the June 2025 Qantas data breach, and the conclusion cuts against the instinct to punish the victim of a cyberattack.
According to the OAIC's report, the evidence gathered did not indicate a likelihood that Qantas had "failed" to take reasonable steps to protect the personal information it held, nor that it failed to ensure its overseas third-party provider complied with Australia's privacy principles. No investigation. No enforcement action.
"After more than a year of making inquiries and obtaining information on the data breach, we're satisfied that the evidence does not support the likelihood that a breach of privacy law occurred. As a result, we've decided not to commence a full investigation of Qantas at this stage." - Carly Kind, Australian Privacy Commissioner.
The breach traces back to a single phone call. A threat actor posing as "Qantas IT help" convinced a contact center agent to visit a website tied to the customer relationship management platform used by Qantas agents, walking them through steps framed as necessary to close an IT support ticket. That interaction connected the agent's CRM session to a data extraction tool controlled by the attacker, who then pulled data from every contact profile the agent could access. It was pure social engineering — no malware, no exploited vulnerability, just a convincing lie.
Qantas caught it fast. A staff member spotted an unusual spike in login-attempt alerts on the morning of June 30, two days after the call, and escalated it to the cybersecurity team. Within hours, the company had frozen the compromised account, assessed for data exfiltration, and triggered its incident response process. Public disclosure followed on July 2.
The regulator's numbers are more precise than what circulated publicly last year. Roughly 5.67 million customer records were compromised, with about 4 million exposing names, phone numbers, email addresses and Frequent Flyer details, and a further 1.7 million records including combinations of home or business addresses, dates of birth, gender and meal preferences. Critically, no credit card numbers, financial information or passport details lived on the compromised platform, and customer passwords and login credentials were never touched.
The OAIC's reasoning is a rare, explicit acknowledgment that good controls don't guarantee immunity. Investigators found that social engineering training generally targets credential theft, not the rarer tactic of talking an employee into authorizing a legitimate-looking system connection — meaning the attack likely would have succeeded even with standard training in place. They also noted the flaw was structural: a default configuration let the agent authorize a third-party app connection, a setting the CRM vendor has since changed for all its customers.
Commissioner Carly Kind put the broader stakes plainly in the OAIC's statement announcing the report, warning that AI-driven threats are only raising the bar. As she framed it, agentic and advanced AI will keep escalating the cybersecurity risks businesses face, making continuous review of security posture non-negotiable — not optional.
“Data breaches are a persistent feature of today’s digital world, and can occur despite organisations taking steps to protect personal information,” Commissioner Carly said. “Agentic and advanced AI will only increase the cybersecurity risks that businesses face, and it is critical that all organisations continuously review and enhance their security to protect against this growing threat.”The takeaway here isn't that Qantas got a pass. It's that a regulator has now drawn, in writing, the line between negligence and the limits of what training and access controls can realistically stop.

![]()

![]()