Thousands of Boston Scientific employees at the company’s Cork campus were sent home on Tuesday after network communications were cut across the company, according to local media in Ireland. That’s the kind of detail that tells you more about the severity of a cyberattack than any regulatory filing does.
The filing came anyway. In a disclosure with the U.S. Securities and Exchange Commission on Wednesday, the Massachusetts-based medical device maker confirmed a cyberattack is causing an ongoing “global disruption” to its operations.
What the company has actually said
Boston Scientific said it began experiencing “disruptions and limitations of access” to its IT systems and business applications on Tuesday. Those systems are critical to how it operates.
The company said the attack has affected its ability to ship and process orders. What it hasn’t said is whether the disruption reaches customers who have its medical devices and implants.
That gap matters. Boston Scientific makes implanted devices including pacemakers and defibrillators, and it treats around 48 million patients a year, according to its website.
The questions nobody’s answering
We asked Boston Scientific spokesperson Chanel Hastings whether patients are affected, what steps patients should take, and what the nature of the incident was. Hastings shared the company’s public statement and wouldn’t comment on any of it.
The public statement says the investigation is ongoing and that a timeline for restoring systems isn’t yet known.
It’s still not clear what caused the attack.
Health tech keeps getting hit
Boston Scientific is the latest health technology company to be hacked this year. Medical device makers Abbott Laboratories and Medtronic were both breached.
Earlier this year, Iranian-backed hackers were blamed for a cyberattack on U.S. medical device maker Stryker. In that case, the hackers remotely wiped tens of thousands of employee devices across the company’s Windows network by abusing a centralized device management portal provided by Microsoft.
Worth knowing: public internet records show Boston Scientific relies largely on Microsoft and Amazon Web Services for its corporate infrastructure. That doesn’t establish a cause here, but it’s the same class of centralized corporate plumbing that turned the Stryker incident into a mass-wipe event rather than a contained one.
What to watch next
If you have a Boston Scientific implant, the company has told you nothing about whether you’re affected, and it declined to say what you should do. Until it does, the practical move is to route questions through your clinician rather than waiting for a corporate advisory that may not arrive.
The other number to track is the shipping backlog. Order processing is already broken, no restoration timeline exists, and hospitals order pacemakers and defibrillators on schedules that don’t pause for an incident response.