Boston Scientific breach – What the breach notification doesn’t say
Paul Ducklin
08/27/2026
Share this article:
Down but not out
You’ve got to love SEC filings in which mega-rich, super-huge companies admit they’ve suffered a “cybersecurity incident.”
To you and me, a cybersecurity “incident” probably involves inadvertently clicking a dubious link, reaching a phishing site, but bailing out in time and then quickly double-checking that no harm was ultimately done.
Or it’s where you accidentally messaged friend X directly, when you really meant to moan about X behind their back to mutual friend Y, thus dropping all three of you into a cyber-awkward social standoff.
If our entire home network were trashed and then blasted offline by cyberattackers, we probably wouldn’t consider that an “incident,” but would reach for words such as crisis, disaster, wipe-out, and many other phrases not suitable for repeating on a family-friendly website.
But for Boston Scientific, a $20-billion-a year healthcare giant in the US, their latest reportable “incident” involves an attack against “certain of its information technology systems that has resulted in a global disruption to the Company’s operations.”
As Irish cybersecurity luminary Brian Honan reported yesterday, “This explains why staff in the Irish operations have been told to work from home.”
Boston Scientific continues:
The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.
What happened?
Given the level of operational disruption, this feels like a ransomware attack where critical files across the network were deliberately scrambled to stop users doing their jobs, followed by an extortion note demanding money for decryption keys to recover the ruined files and get business back on track.
Or it might have been a straight-out data breach, followed by a blackmail demand “promising” to “delete” the stolen information in return for a cryptocurrency payment, leading the company to take its own systems down in the hope of stopping the criminals from continuing their attack (for example, by scrambling files for additional leverage, or simply out of spite if the company refused to pay).
We don’t know exactly what happened yet, and apparently Boston Scientific doesn’t know either, so let’s give them the benefit of the doubt for now.
The amusing bit is the concluding sentence of the SEC report, which says, “[T]he Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company.”
Global disruption? Customer interactions halted? Staff sent home? No way to know how long it will take to fix?
Sure sounds like an impact, if you ask me.
What to do?
If you work for Boston Scientific, or are a customer or contractor, or even a patient who is has been treated with this company’s products, this breach might affect you personally. Employers are required to hold detailed personal information about their staff; companies typically have detailed information about customers, including financial data; and healthcare organizations often have and hold medical records about patients for research purposes. Boston Scientific has published an Update on recent cybersecurity incidentpage on its website, so be sure to keep up with its findings and its response.
If you hold data about other people in your own business, practice what you will do if you suffer a data breach. It’s OK to be honest up front and say that you don’t yet know, as long as you provide regular updates as your investigation proceeds. Employees and customers are more likely to forgive you and to rebuild their trust if you not only figure out what went wrong, but also show how you plan to prevent a similar incident from happening again.
Remember that you don’t have to do it all yourself. Stay on top of cyberthreats without distracting staff from your core business. Sign up with SolCyber to do it for you, human style.
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
More About Duck
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!
Paul Ducklin
08/27/2026
Share this article:
Table of contents:
The world doesn’t need another traditional MSSP or MDR or XDR.
We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
I am interested in SolCyber Foundational Coverage™
I am interested in a Free Demo
14762
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it. Privacy policy