Home
Blog
Boston Scientific breach – What the breach notification doesn’t say

Boston Scientific breach – What the breach notification doesn’t say

Paul Ducklin
08/27/2026
Share this article:

Down but not out

You’ve got to love SEC filings in which mega-rich, super-huge companies admit they’ve suffered a “cybersecurity incident.”

To you and me, a cybersecurity “incident” probably involves inadvertently clicking a dubious link, reaching a phishing site, but bailing out in time and then quickly double-checking that no harm was ultimately done.

Or it’s where you accidentally messaged friend X directly, when you really meant to moan about X behind their back to mutual friend Y, thus dropping all three of you into a cyber-awkward social standoff.

If our entire home network were trashed and then blasted offline by cyberattackers, we probably wouldn’t consider that an “incident,” but would reach for words such as crisis, disaster, wipe-out, and many other phrases not suitable for repeating on a family-friendly website.

But for Boston Scientific, a $20-billion-a year healthcare giant in the US, their latest reportable “incident” involves an attack against “certain of its information technology systems that has resulted in a global disruption to the Company’s operations.”

As Irish cybersecurity luminary Brian Honan reported yesterday, “This explains why staff in the Irish operations have been told to work from home.”

Boston Scientific continues:

The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders. While the Company is working diligently to restore affected functions and systems access, the timeline for a full restoration is not yet known.

What happened?

Given the level of operational disruption, this feels like a ransomware attack where critical files across the network were deliberately scrambled to stop users doing their jobs, followed by an extortion note demanding money for decryption keys to recover the ruined files and get business back on track.

Boston Scientific breach - What the breach notification doesn't say - SolCyber

Or it might have been a straight-out data breach, followed by a blackmail demand “promising” to “delete” the stolen information in return for a cryptocurrency payment, leading the company to take its own systems down in the hope of stopping the criminals from continuing their attack (for example, by scrambling files for additional leverage, or simply out of spite if the company refused to pay).

Boston Scientific breach - What the breach notification doesn't say - SolCyber

We don’t know exactly what happened yet, and apparently Boston Scientific doesn’t know either, so let’s give them the benefit of the doubt for now.

The amusing bit is the concluding sentence of the SEC report, which says, “[T]he Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company.”

Global disruption? Customer interactions halted? Staff sent home? No way to know how long it will take to fix?

Sure sounds like an impact, if you ask me.

What to do?

  • If you work for Boston Scientific, or are a customer or contractor, or even a patient who is has been treated with this company’s products, this breach might affect you personally. Employers are required to hold detailed personal information about their staff; companies typically have detailed information about customers, including financial data; and healthcare organizations often have and hold medical records about patients for research purposes. Boston Scientific has published an Update on recent cybersecurity incident page on its website, so be sure to keep up with its findings and its response.
  • If you hold data about other people in your own business, practice what you will do if you suffer a data breach. It’s OK to be honest up front and say that you don’t yet know, as long as you provide regular updates as your investigation proceeds. Employees and customers are more likely to forgive you and to rebuild their trust if you not only figure out what went wrong, but also show how you plan to prevent a similar incident from happening again.
  • Remember that you don’t have to do it all yourself. Stay on top of cyberthreats without distracting staff from your core business. Sign up with SolCyber to do it for you, human style.

Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!

Boston Scientific breach - What the breach notification doesn't say - SolCyber


More About Duck

Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

Paul Ducklin
Paul Ducklin
08/27/2026
Share this article:

Table of contents:

The world doesn’t need another traditional MSSP 
or MDR or XDR.

What it requires is practicality and reason.

Related articles

Choose identity-first managed security.

We start with identity and end with transparency — protecting where attacks begin and keeping you informed, with as much visibility as you want. No black boxes, just clear, expert-driven security.
No more paying for useless bells and whistles.
No more time wasted on endless security alerts.
No more juggling multiple technologies and contracts.

Follow us!

Subscribe

Join our newsletter to stay up to date on features and releases.

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.

©
2026
SolCyber. All rights reserved
|
Made with
by
Jason Pittock

I am interested in
SolCyber DPM++

I am interested in
SolCyber XDR++™

I am interested in
SolCyber MDR++™

I am interested in
SolCyber Extended Coverage™

I am interested in
SolCyber Foundational Coverage™

I am interested in a
Free Demo

14762