Boston Scientific Says Cybersecurity Incident Likely Material, Will Miss 2026 Guidance

BSX

·

Boston Scientific said Tuesday that the cybersecurity incident it first disclosed in August is now likely material and is expected to hurt both third-quarter and full-year 2026 results, making it unlikely the medical-device maker will meet the sales-growth and adjusted earnings guidance it gave in July.

In a Form 8-K filed with the Securities and Exchange Commission, the company said, “The incident involved unauthorized activity on certain of the Company’s systems that resulted in a network outage affecting access to certain operating systems and business applications, which impacted the Company’s ability to manufacture as well as process and ship customer orders.” Boston Scientific said the disruption affected operations globally.

The company identified the incident on Aug. 25, 2026. It first disclosed the matter the next day in an 8-K filed under Item 8.01, a section companies often use to provide general updates, saying a materiality determination had not yet been made. In a subsequent 8-K filed under Item 1.05, the SEC’s category for material cybersecurity incidents, with a Sept. 7, 2026 report date and accepted Sept. 8, Boston Scientific said it has now concluded the incident is, or is likely to be, material.

That filing said Boston Scientific “has determined that the incident is likely to have a material impact on the Company’s results of operations for the third quarter and full year 2026.” It also said the company “believes that it is unlikely to meet the net sales growth and adjusted EPS guidance ranges for the third quarter and full year 2026 that the Company previously provided on July 29, 2026.”

Boston Scientific said it activated its incident-response protocols and brought in outside cybersecurity specialists, including CrowdStrike, to investigate, contain the impact and help restore operations. The company said the investigation is ongoing. In public updates, it said, “We see no indication of unauthorized activity in our environment related to this incident since August 25.”

The company also said recovery has progressed. Its major distribution centers have been substantially restored and are processing and shipping products at or above normal operating levels. Sterilization facilities are operational, and manufacturing has resumed across most facilities globally. Boston Scientific’s public updates have said the unauthorized activity appears limited to certain on-premises systems, while cloud systems were unaffected.

Because Boston Scientific makes implantable and other medical devices, the outage had implications beyond a typical corporate network disruption. The company said there is no known impact to the function of devices that were already implanted and remotely monitored before the incident. But it also said new remote-monitoring activations were affected during the outage.

Boston Scientific has not publicly identified who was behind the unauthorized activity, described how the intrusion happened, or confirmed any exfiltration of personal or patient data.

The two-step disclosure reflects the SEC’s cybersecurity reporting rules, which require public companies to file an Item 1.05 8-K within four business days after determining that a cyber incident is material. Boston Scientific said it will provide an updated operational and financial outlook on its Oct. 28, 2026, third-quarter earnings call.

Tags: #bostonscientific, #cybersecurity, #medicaldevices, #earnings

Stocks: BSX