Update on recent cybersecurity incident

Sep 9, 2026

Latest update -- September 9, 2026 7:53 p.m. ET

Business Operations Restored

Manufacturing, order fulfillment and shipping operations are now fully restored following the cybersecurity incident identified on August 25, 2026. Products are moving through our distribution network at or above normal levels, as our teams work around the clock to fulfill customer orders, reduce backlogs and accelerate the delivery of products to customers and the patients who depend on them.

 

As order processing continues, we are working to fulfill customer orders as quickly as possible, including those pending prior to the August 25 cybersecurity incident and those received during the disruption. While some customers may continue to experience temporary delays, we are prioritizing manufacturing and distribution efforts to support ongoing customer demand and minimize the impact on patients and healthcare providers.

 

Independent Assessments

Since Boston Scientific implemented containment procedures on August 25, independent assessments from CrowdStrike and other third-party cybersecurity experts have not identified evidence of ongoing threat activity nor evidence of compromise to the Boston Scientific systems or product technologies.

 

Those include the following areas:

  • product development systems
  • product software systems
  • manufacturing and medical device maintenance systems
  • software and business applications
  • cloud-based systems, email platforms and external collaboration platforms

 

Customers and vendors can be assured that they may continue communicating and exchanging information with Boston Scientific through their normal channels, including with sales representatives and other employees, in email and established digital platforms and connections.

 

Regarding business application availability, we are actively restoring applications. Customers and other stakeholders experiencing application access issues will receive direct notifications as specific applications become available for access and use.

 

The network disruption impact to remote monitoring activations has been resolved and activation capability has been restored. Remote monitoring activations for cardiac device implant communicators and ICM remote monitoring have resumed. Read more: Cardiac Device Remote Monitoring Activation Capability Restored.

 

We will continue to provide additional information about our forensic findings and CrowdStrike’s investigation as they become available through website updates and in our communications with customers, suppliers and other partners.  

 

We recognize the impact this incident has had on our customers and the patients they serve. We are grateful for the patience and partnership our customers, healthcare providers, patients, suppliers and other stakeholders have shown throughout this incident. The substantial progress achieved reflects the extraordinary dedication of employees, cybersecurity experts and partners across the company, whose collaborative efforts helped restore operations and support customers and patient care.

 

Archived:

9/8/26 update

9/5/26 update

9/3/26 update

8/30/26 update

8/29/26 update

8/28/26 update

8/27/26 update

8/26/26 update

Top