Device Maker Rebuilds Supply Chain After Breach

A cybersecurity incident that stopped a global medical device manufacturer from making or shipping product has ended with operations fully restored. The one clinical workflow it degraded is working again.

The supplier of pacemakers, implantable defibrillators, and heart implants, Boston Scientific, identified the incident on 25 August 2026. It has published dated updates since, most recently on 9 September. CrowdStrike and other third-party experts remain engaged.

The company reported a network outage affecting certain operating systems and business applications. That included the ability to manufacture products and to process and ship customer orders.

Manufacturing, order fulfilment and shipping are now fully restored. Product is moving through the distribution network at or above normal levels.

Backlog remains the residual problem. The company is working through orders pending before 25 August alongside those received during the disruption, and says some customers may still see temporary delays.

On the security question, independent assessments have come back clean. Since containment began on 25 August, CrowdStrike and other experts have found no evidence of ongoing threat activity. They also found no evidence of compromise to Boston Scientific systems or product technologies.

That assessment covers product development systems, product software systems, and manufacturing and medical device maintenance systems. It also covers software and business applications, cloud-based systems, email platforms and external collaboration platforms.

Business applications are still being brought back progressively. Customers experiencing access problems are being notified directly as individual applications return.

The remote monitoring gap has closed. Activation capability has been restored, and activations for cardiac device implant communicators and insertable cardiac monitors have resumed.

What was affected while it lasted

That workflow was the sharpest edge of the incident. New implants could be placed, but the communicators that send device data to remote patient management systems could not be activated.

Newly implanted insertable cardiac monitors had to be activated through the company's Clinic Assistant app, and could not pair to the patient's monitoring phone. Recorded episodes had to be retrieved by in-person interrogation.

Implanted device function itself was never affected. Remote monitoring of devices already being monitored before the disruption continued, and programmer interrogations were unaffected throughout.

The company also stated there was no known impact to devices not connected to a Boston Scientific network. It found no evidence the affected environment increased cybersecurity risk to hospital networks.

On personal data, the position has not moved. The company says it is still investigating. It will notify affected individuals, regulators and customers in accordance with privacy laws if it determines data has been compromised.

Order intake continued throughout via EDI and local applications, with orders queued for later fulfilment.

Restoration ran shipping first. The company began restoring shipping for most products at major distribution centres on 3 September. It described the network as substantially restored on 5 September, and reported full restoration on 9 September.

The disclosure practice is worth noting alongside the recovery. Boston Scientific has run the incident through a single dated page, timestamped to the minute, with eight earlier updates archived beside the current one.

It says it will publish further forensic findings from the CrowdStrike investigation as they become available. The incident page is on its newsroom.

Business Solution