A Week On, Boston Scientific Still Cannot Ship
The company says an incident identified on 25 August is affecting its ability to manufacture products and process orders. Cloud systems are unaffected; the damage is confined to certain on-premise systems.

Boston Scientific identified a cybersecurity incident on 25 August that caused a network outage and disrupted operations globally. A week later, by its update of 1 September, the company was still working towards partial restoration of shipping for some products, with a full-restoration timeline it described as unknown.
The company's own language is the part worth reading closely. The incident is affecting access to certain operating systems and business applications, it says, "including the ability to manufacture products, as well as process and ship customer orders." That is an IT-side intrusion producing an OT-side outcome, and it is the sentence that belongs in front of anyone who still treats plant systems and business systems as separate risk conversations.
The technical detail with the most general value is the boundary. The company states there is no impact to its cloud-based systems and applications, and that the unauthorised activity is limited to certain on-premise systems. Whatever the initial access, what determined the blast radius was reachability — which systems could be reached from where. That is a segmentation outcome, and it is a more persuasive argument for zone and conduit work than any framework document.
The response followed a conventional shape: incident response protocols activated, CrowdStrike and other third-party experts engaged for containment, investigation and forensics. In its 30 August update the company said it had seen no indication of unauthorised activity in its environment related to the incident since 25 August. Orders continue to be received electronically through EDI and local applications, and are being queued for future fulfilment — a reminder that order intake and order fulfilment fail separately, and that a queue with nothing behind it still buys goodwill.
On the clinical side the company reports no known impact to implantable device function, no known impact to remote monitoring for devices already being monitored before the disruption, and no impact to programmer interrogations. New remote-monitoring activations are affected: new CRM communicators cannot be activated, and newly implanted insertable cardiac monitors cannot pair to the patient mobile app, so episode data is recorded on the device but not transmitted until systems are restored.
For manufacturers watching from outside, the durable lesson is about duration rather than cause. A week of no shipping is not a security metric, it is an operations one, and the recovery time of a manufacturing and order-processing stack is a number most companies have never measured because nothing has ever asked them to.
Source: Boston Scientific