Boston Scientific is investigating a cyberattack that knocked some of its IT systems offline and disrupted its ability to process and ship customer orders worldwide.
The company detected the incident on Aug. 25, activated its incident response procedures, and brought in third-party cybersecurity experts to investigate and contain the intrusion.
What stands out to me is that this attack goes beyond another large company suffering an outage.
Boston Scientific manufactures medical devices used in patient care, so prolonged disruptions could have consequences beyond just IT systems.
“A cardiac device that misses its ship date can mean a cancelled surgery,” said Jacob Krell, senior director of Secure AI Solutions & Cybersecurity at Suzu Labs, in an email to eSecurityPlanet.
He added, “That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for.”
Having previously worked as an electrophysiology nurse with pacemaker and defibrillator patients, I’ve seen firsthand how important timely access to these devices can be.
As Jacob mentioned, delays in getting the right device to a hospital can have a direct impact on patient care.
Cyberattack disrupts Boston Scientific systems
Boston Scientific said the attack affected access to certain operating systems and business applications, including systems used to process and ship customer orders. No timeline has been provided for fully restoring affected systems.
The Massachusetts-based company operates globally and manufactures a wide range of medical devices.
Its products include cardiac devices such as pacemakers and defibrillators, as well as equipment used in other medical procedures.
Ross Filipek, CISO at Corsica Technologies, said the incident also comes during a difficult period for the medical device sector.
“Medical device companies have had a rough year. Stryker, Medtronic and Abbott have already disclosed cyber incidents,” Filipek said. “The concern for this latest attack reaches beyond another corporate IT outage.”
Boston Scientific continues to investigate the incident and it is unclear whether any data was stolen.
No ransomware or extortion group has claimed responsibility at the time of publication.
Operational resilience should be part of incident response
A cyberattack at a medical device company can quickly become an operational problem.
Restoring impacted systems is important, but organizations also need a plan for keeping critical business functions running during an outage.
“To maintain operational continuity during an ongoing intrusion, security teams must enforce strict logical boundaries between corporate administrative networks and fulfillment environments, maintain immutable offline backups, and regularly validate manual failover protocols,” said Damon Small, a member of the board of directors at Xcape, Inc, in an email to eSecurityPlanet.
I would also recommend organizations identify which systems are critical to manufacturing and fulfillment before an incident occurs.
Network segmentation can help keep an intrusion in corporate IT from spreading into production or logistics environments, while tested offline backups can help restore systems that need to be rebuilt.
Teams should also document manual procedures for essential operations and test them through tabletop exercises and attack simulation tools.
A failover plan that exists only on paper may not hold up when critical systems and other dependencies suddenly become unavailable.
For medical device manufacturers, the impact of an attack can extend beyond IT when disruptions affect the ability to get products to healthcare providers and patients.





