Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
Boston Scientific, a major medical device manufacturer, disclosed a cybersecurity incident that has disrupted its shipment processes. The company filed documents with the Securities and Exchange Commission and released a public statement confirming the attack was discovered on Tuesday.
The breach affects the firm's ability to ship medical devices, though the company has not specified which product lines are impacted or the extent of the disruption. Boston Scientific manufactures cardiac rhythm management devices, interventional cardiology products, and other critical medical equipment used in hospitals globally.
The timing is notable: medical device firms are high-value targets for ransomware groups seeking to exploit operational dependencies in healthcare supply chains. The company has not attributed the attack to any threat actor or confirmed whether data was exfiltrated.
- 01Hospitals relying on Boston Scientific devices may face inventory shortages or delayed procedures
- 02Investors should monitor SEC updates for revenue impact and operational recovery timelines
- 03Medical device sector faces heightened scrutiny on supply chain cyber resilience
- 04Ransomware groups may be testing healthcare manufacturing as a pressure point
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.
Toronto children's hospital breached again, employee data stolen
The Hospital for Sick Children disclosed a data theft incident linked to third-party software, two years after a disruptive ransomware attack.