Visualização de leitura

Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide

Boston Scientific Cyberattack, Unopened medical device shipping cartons in a hospital corridor illustrating the Boston Scientific cyberattack disruption to order processing and delivery.

Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return.

The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission on Wednesday and in a statement on its official website. It said the intrusion affected certain information technology systems and limited access to business applications underpinning day-to-day operations.

Boston Scientific is among the world's largest medical device manufacturers, reporting $20.07 billion in 2025 revenue and about $21 billion over the trailing 12 months. Its portfolio includes pacemakers, defibrillators, cardiac stents and neuromodulation implants, and the company says its products treat roughly 48 million patients a year. Thousands of employees in Ireland, where Boston Scientific operates three manufacturing and research sites, were told to work from home on August 26 after network communications were severed.

The company said it activated incident response protocols and engaged outside cybersecurity specialists to contain and investigate the intrusion. It has not said whether ransomware was involved, whether data was exfiltrated, or whether the disruption touches patients with implanted devices. No extortion group had claimed responsibility as of August 26. Shares fell more than 4% following the disclosure.

A Boston Scientific spokesperson declined to answer questions about patient impact and directed reporters to the published statement. Neither the company nor U.S. regulators have said whether hospital procedures have been delayed as a result of the shipping halt, though device suppliers typically hold limited on-site inventory at hospitals, making sustained order outages a downstream supply concern.

The incident is the third disruptive attack on a major medical technology firm in six months. Stryker suffered a global network outage in March after attackers abused its Microsoft Intune deployment to wipe data from thousands of devices, and Medtronic disclosed in April that patient names, Social Security numbers and health information were exposed in a breach attributed to the ShinyHunters extortion group.

Also read: Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

Boston Scientific said it cannot yet assess the full operational and financial impact, language that leaves room for an amended filing once the investigation matures.

The company's Irish footprint also raises the prospect of European scrutiny. If personal data proves to have been accessed, notification duties under the General Data Protection Regulation would attach, and medical device manufacturers operating in the European Union are increasingly captured by the NIS2 Directive's incident reporting regime as member states complete transposition.

Stryker Cyberattack Lawsuit Faces Challenge as Company Seeks Dismissal

Stryker cyberattack

The legal fallout from the Stryker cyberattack continues to unfold, as the medical technology manufacturer has asked a federal court to dismiss a proposed class action lawsuit brought by current and former employees. The plaintiffs allege that their personal information was compromised during the cyberattack on Stryker, but the company argues that its investigation found no evidence supporting those claims. 

Employee Data Was Not Accessed During the Stryker Cyberattack 

In a court filing submitted Monday, Michigan-based Stryker said an internal review conducted with independent experts found that none of the eight named plaintiffs had personally identifiable information (PII) accessed during the incident. According to a statement from Chief Information Security Officer Juan Pablo Calderon, investigators examined files and data that the threat actor may have accessed during the attack.  “Those files and data were searched for plaintiffs' PII, and Stryker determined as a purely factual matter that none of the plaintiffs' PII exists in those files and data,” Calderon stated. He added that business email addresses belonging to two plaintiffs were found, but no sensitive personal information was identified. 

Iranian Hacktivists Claimed Massive Data Theft and Destruction 

The Stryker cyberattack was claimed by Handala, a group widely suspected of acting as a front for Iran’s Ministry of Intelligence. The Iranian hacktivists alleged in March that they had stolen 50 terabytes of critical company data. They further claimed to have erased 200,000 devices and 12 petabytes of data “in just a few hours,” describing the information as assets that had taken years to collect and billions of dollars to protect.  The cyberattack on Stryker occurred nearly two weeks after the United States and Israel launched major military operations against Iran on February 28. While Stryker maintained that customer-connected devices and systems were not affected, the incident disrupted electronic ordering and related services used by clients. Those systems remained unavailable for several weeks before being fully restored in early April. 

Legal Experts Weigh In on the Cyberattack on Stryker 

Stryker also argued that the plaintiffs rushed to court, filing lawsuits “merely 48 hours” after the company disclosed the cyberattack on March 11. According to the company, the lawsuits relied on speculation that names, Social Security numbers, and other personal information had been exposed.  The company further contends that each plaintiff’s PII had already been exposed in previous breaches involving other organizations, making it difficult to connect any alleged harm, including identity theft, directly to the cyberattack on Stryker. None of the named plaintiffs received breach notifications from the company, yet they seek to represent all U.S. individuals whose information was allegedly compromised.  Legal experts say the case highlights broader questions surrounding data breach litigation. Steven Teppler of Mandelbaum Barrett noted that “the complaint may outrun the facts” when lawsuits are filed immediately after a cyberattack. He added that courts increasingly require plaintiffs to show “more than speculation” that their information was affected. 
❌