Cyberattack disrupts Boston Scientific as medtech incidents mount

Brokers face growing questions over operational resilience and BI coverage

Cyberattack disrupts Boston Scientific as medtech incidents mount

Cyber

By Gia Snape

Boston Scientific’s cyberattack is putting another spotlight on the operational consequences of cyber incidents for US healthcare companies, with the medical device maker warning that disruption is affecting systems used to process and ship customer orders.

The company said Wednesday that it detected the cybersecurity incident on August 25 and activated its incident-response procedures, bringing in third-party cybersecurity specialists to investigate and contain the threat.

The incident has disrupted Boston Scientific’s global operations and restricted access to some information systems and business applications. The company has not established a timeline for full restoration and has not yet determined whether the incident is reasonably likely to have a material impact on its business.

Boston Scientific has not disclosed whether data was stolen, whether ransomware was involved or how the attacker gained access. But the immediate impact on order processing and shipments means the financial consequences could increasingly depend on how long critical systems remain unavailable.

Medical device companies face wave of attacks

Boston Scientific is not the first major medical technology company to face this problem in 2026.

Stryker disclosed a cyberattack in March that caused global disruption to its Microsoft environment and affected order processing, manufacturing and shipping. The company initially said it had no indication of ransomware, although its investigation later identified malicious tooling used by the attacker.

Stryker subsequently determined that the incident had a material impact on its operations and first-quarter financial results. Most manufacturing operations had been restored by late March.

West Pharmaceutical Services experienced another material cyberattack in May in which an unauthorized party exfiltrated data and encrypted systems. The company took systems offline globally, temporarily disrupting manufacturing, shipping and receiving before restoring operations across its sites later that month.

Other incidents have produced very different outcomes. Medtronic disclosed an attack against its corporate IT network in April but said manufacturing and distribution were unaffected because those systems were separated from the compromised network. Abbott Laboratories similarly disclosed two cyber incidents in July without reporting an operational impact.

That contrast could be particularly relevant to brokers discussing cyber controls with healthcare and manufacturing clients. Network segmentation, business continuity arrangements and the ability to continue manufacturing, processing orders and shipping goods when corporate IT systems are unavailable can significantly change the ultimate severity of an incident.

What brokers should be looking at

The Boston Scientific incident also demonstrates why cyber conversations increasingly need to extend beyond breach response and privacy liability.

Where a cyber event shuts down systems needed to generate revenue, brokers may need to examine the scope of cyber business interruption coverage, including applicable waiting periods, how lost income is calculated and which systems must be impaired before coverage responds.

For manufacturers and healthcare supply-chain companies, the discussion can extend further. A prolonged outage can affect production schedules, inventory movement, customer contracts and downstream organizations waiting for critical products.

Dependent business interruption and contingent cyber exposures can therefore become part of the placement discussion alongside the insured’s own network risk.

The distinction between cyber and other insurance programs can also become important where an incident creates physical supply-chain consequences without causing physical damage.

Boston Scientific’s investigation remains at an early stage, meaning the ultimate financial and insurance implications are unclear. But with several large medical technology companies suffering cyber incidents in the space of a few months, the sector is giving brokers another reason to test how clients would actually continue operating when their core digital infrastructure goes down.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!