An independent forensic review found no evidence that the August cyber incident compromised patient or customer data, medical device maintenance systems, or manufacturing environments.
An unauthorized third party gained access to a limited portion of Boston Scientific’s on-premises environment in late August, but an independent investigation found no evidence that patient data, customer data, or medical device operations were compromised.
According to a summary report by cybersecurity firm CrowdStrike, the threat actor initially gained access to the network via an external-facing network management device. Boston Scientific first detected system availability issues affecting segments of its network on Aug 25, 2026, and initiated containment protocols that same day.
CrowdStrike launched its investigation on Aug 25, 2026, and concluded the assessment on Sept 18, 2026. Investigators confirmed that there was no evidence of data encryption in any Boston Scientific environment, nor was there any ongoing threat actor activity following the containment actions taken on August 25, 2026.
Based on the findings, Boston Scientific confirmed that customers and partners may safely continue normal business operations and system connections with the company.
Clinical and Device Maintenance Environments Unaffected
The forensic findings indicate that clinical technology and operational infrastructure remained isolated from the intrusion. CrowdStrike identified no evidence of interactive remote access to critical operational environments, including:
- Medical device maintenance systems
- Supervisory control and data acquisition systems
- Manufacturing and maintenance systems
- Software development and product development systems
- Human resources and employee benefit systems
Additionally, investigators found no evidence that the intruder authenticated at the application level within internally managed manufacturing or medical device environments, cloud applications, software-as-a-service platforms, or corporate financial systems such as SAP and Salesforce. No threat actor activity was detected within Microsoft 365, email, collaboration, or productivity platforms.
As for patient safety and data privacy, the investigation found no evidence that the unauthorized actor accessed, staged, or exfiltrated any files, including patient or customer records.
Containment and Remediation Measures
Following the detection of the incident, Boston Scientific instituted remediation measures to isolate the threat and protect network operations.
According to the summary, the network management device used for initial entry was disconnected and decommissioned. IT and security teams also implemented firewall blocks against known IP addresses and domains associated with the threat actor, enforced widespread password resets, and applied additional hardening measures across the affected IT infrastructure.
To protect against future incidents, Boston Scientific expanded its monitoring and threat detection capabilities across its environment by deploying additional CrowdStrike Falcon security tools, with ongoing support from Falcon OverWatch and CrowdStrike Active Defense Services.
ID 190688382 © Pavel Kapysh | Dreamstime.com