Boston Scientific Says Cyberattack Likely to Hurt 2026 Sales and Profit
What's Happening
Medical-device maker Boston Scientific said a cybersecurity incident that disrupted parts of its global operations means it is unlikely to meet the sales and adjusted-profit forecasts it previously issued for 2026.
The company identified unauthorized activity on some of its information-technology systems on August 25. The incident caused a network outage that disrupted manufacturing as well as the processing and shipment of customer orders. Boston Scientific said it now expects the disruption to affect its financial performance, although the final impact remains uncertain. (Reuters)
The company said it has already resumed manufacturing across most of its facilities and that major distribution centers are processing and shipping orders at or above normal levels. However, the interruption created backlogs that will take time to clear.
The Cyberattack Disrupted Core Operations
Manufacturing was affected
This was not just a data-security incident.
The unauthorized activity caused a network outage that interfered with manufacturing operations. Because medical-device production depends heavily on interconnected systems, an IT disruption can quickly become a physical supply-chain problem.
Production interruptions can affect how many devices a company is able to manufacture, package, sterilize and ultimately deliver to customers.
For Boston Scientific, that meant the cyber incident moved directly from the technology side of the business into its manufacturing and commercial operations. (Reuters)
Customer shipments were also disrupted
The incident also affected the processing and shipment of customer orders.
That created a second problem. Even where products were available or manufacturing could resume, the company still had to work through delayed orders and restore normal distribution workflows.
Boston Scientific said its major distribution centers are now processing and shipping orders at or above normal levels, suggesting that recovery is underway. (Reuters)
Boston Scientific Is No Longer Expecting to Meet Its 2026 Forecast
Previous guidance is now out of reach
Before the cyberattack, Boston Scientific had forecast 2026 adjusted earnings of $3.28 to $3.32 per share and reported sales growth of 5.5% to 6.5%.
For the third quarter alone, the company had expected adjusted earnings of 80 cents to 82 cents per share.
Boston Scientific has now said it no longer expects to meet its previously issued third-quarter and full-year 2026 sales and adjusted-profit forecasts. (Reuters)
That is a significant change because the company had entered the year with expectations for continued growth in its medical-device businesses.
The Financial Damage Is Not Fully Known Yet
Some revenue may be recovered
Boston Scientific said it expects to recover some of the affected revenue as operations ramp back up and the company works through its order backlog.
That means the cyberattack does not necessarily represent a permanent loss of all disrupted sales.
Some procedures and customer orders may simply have been delayed rather than eliminated. As manufacturing and distribution return to normal, part of that demand can potentially be fulfilled later. (Reuters)
But the final impact remains uncertain
The company said the full financial impact is still uncertain.
That uncertainty reflects the fact that the company is still assessing how much business was delayed, how quickly backlogs can be cleared and whether some customers or procedures will move to competing products during periods of constrained supply.
Most Facilities Have Resumed Manufacturing
Operations are recovering
Boston Scientific said manufacturing has resumed across most of its facilities globally.
Its sterilization facilities are also operational, while major distribution centers are processing and shipping orders at or above normal levels. (Reuters)
That indicates the company has moved beyond the initial shutdown phase and into recovery.
However, recovery from a cyberattack is not necessarily instantaneous. Businesses can restore systems while still dealing with delayed production schedules, outstanding orders and disrupted customer workflows.
Product Quality Was Not Broadly Affected
The company says the problem was operational
Boston Scientific said the incident's effects were limited to select internal infrastructure.
Its product-quality analyses found no impairment to its products beyond disruptions involving new activations of its cardiac-device remote-monitoring platform. (Reuters)
That distinction is important.
The company is not reporting that the cyberattack compromised the safety or functionality of its medical devices generally. The principal commercial impact has instead been on operations, manufacturing, order processing and shipments.
Cardiac Device Monitoring Was One Exception
Remote monitoring activations were disrupted
Although product-quality testing did not find broader impairment, Boston Scientific said the incident caused disruptions to new activations of its cardiac-device remote-monitoring platform. (Reuters)
Remote monitoring is increasingly important in cardiovascular care because connected devices allow physicians and healthcare teams to receive information from patients without requiring every interaction to occur in person.
That makes digital infrastructure part of the clinical workflow.
A disruption in that infrastructure can therefore create operational consequences even when the physical medical device itself remains fully functional.
The Attack Adds to a Growing Healthcare Cybersecurity Problem
Medical-device companies are increasingly being targeted
Boston Scientific is the latest major healthcare company to disclose a cyber incident.
Reuters noted that other medical-device manufacturers, including Abbott Laboratories, Stryker and Medtronic, have recently experienced cyberattacks. Drugmaker Novo Nordisk has also been affected. (Reuters)
The pattern shows that cyber risk is spreading across the healthcare supply chain.
The target is no longer simply a hospital's patient database. Manufacturers that produce devices used in hospitals and physicians' offices are increasingly part of the same risk environment.
Why Medical-Device Manufacturers Are Particularly Vulnerable
Cybersecurity can affect both IT and physical operations
A conventional corporate cybersecurity incident might disrupt email, internal systems or access to company data.
For a medical-device manufacturer, the consequences can extend much further.
The same connected infrastructure can support:
- Manufacturing
- Inventory management
- Order processing
- Distribution
- Customer support
- Connected medical-device services
- Internal business systems
When those systems are disrupted, an attack can create an immediate commercial impact even if no medical device is physically compromised.
Boston Scientific's experience demonstrates this connection clearly. (Reuters)
The Attack Is Also Affecting Visibility Into the Business
Investors cannot easily separate cyber disruption from normal performance
Analysts are facing another problem beyond estimating the cost of the attack: determining what Boston Scientific's underlying business performance would have looked like without it.
J.P. Morgan analyst Robbie Marcus said the cyberattack has clouded visibility into the company's underlying trends, including growth and competitive dynamics in important franchises such as electrophysiology and Watchman heart devices. (Reuters)
That matters because a sudden decline in sales can come from several sources.
It may reflect weaker demand.
It may reflect stronger competition.
Or it may simply reflect the company's inability to manufacture and ship products normally.
A cyberattack makes those factors much harder to separate.
Investors Are Already Looking Toward 2027
2026 may become a distorted financial year
Stifel analyst Rick Wise said investors were increasingly viewing 2026 as a “lost year” for Boston Scientific and were likely to focus more heavily on the company's prospects for 2027. (Reuters)
That reflects the uncertainty around how much of the lost or delayed revenue can be recovered during the remainder of this year.
If operations stabilize quickly and backlogs are cleared, some effects could be temporary.
If disruption continues to affect customer orders or procedures, the consequences could extend further.
Boston Scientific Plans to Give a New Outlook in October
Third-quarter results will provide a clearer picture
The company said it plans to provide an updated financial outlook when it reports third-quarter results on October 28. (Reuters)
That update should give investors more information about:
- Revenue lost or delayed during the disruption
- The pace of manufacturing recovery
- Order backlogs
- The extent of the impact on profit
- Expectations for the remainder of 2026
- Potential implications for 2027
Until then, the company has not provided a definitive estimate of the total financial damage.
The Incident Shows How Cybersecurity Can Become a Supply-Chain Issue
The most important lesson is that cybersecurity and supply-chain resilience are increasingly connected.
Boston Scientific did not simply lose access to computers.
The incident affected factories, order processing and shipments.
That means cybersecurity has become part of operational risk management for medical-device companies.
A company can have strong demand and a strong product portfolio and still fail to convert that demand into revenue if a cyber incident prevents production or delivery.
Hospitals Could Also Feel the Effects
Medical-device manufacturers supply products that healthcare providers need for procedures.
If shipments are delayed, hospitals and other healthcare facilities can potentially face:
- Delayed procedures
- Product substitutions
- Inventory-management problems
- Scheduling disruptions
- Pressure to identify alternative suppliers
Boston Scientific said it is already recovering and shipping at or above normal levels from major distribution centers, which should help reduce these pressures. (Reuters)
But the episode demonstrates why hospitals increasingly have to think about the cybersecurity resilience of their suppliers, not just their own systems.
Why This Matters
Boston Scientific's experience demonstrates that cybersecurity can directly affect revenue in healthcare.
The financial impact is not limited to potential data breaches, legal costs or remediation expenses. A cyberattack can stop manufacturing, delay shipments and prevent healthcare products from reaching customers.
That makes cybersecurity a business-continuity issue as much as an IT issue.
It also highlights the growing interdependence between digital systems and physical healthcare infrastructure. Medical devices may be physical products, but the systems required to manufacture, distribute, monitor and support them are increasingly digital.
Looking Ahead
The immediate priority for Boston Scientific is to complete the recovery of its global operations and work through order backlogs.
The company says most manufacturing has resumed, sterilization facilities are operational and distribution centers are processing shipments at or above normal levels. (Reuters)
The more important question is whether the recovery is fast enough to prevent longer-term effects on customer relationships and market share.
The company will provide a clearer assessment with its third-quarter results on October 28.
Beyond Boston Scientific, the incident is likely to reinforce the healthcare industry's growing focus on cyber resilience across manufacturing, supply chains and connected medical technologies.
Key Takeaways
- Boston Scientific said it is unlikely to meet its previously issued 2026 sales and adjusted-profit forecasts after a cyberattack disrupted its operations. (Reuters)
- The company discovered unauthorized activity in its IT systems on August 25.
- The resulting network outage disrupted manufacturing, order processing and customer shipments. (Reuters)
- Boston Scientific had previously forecast 2026 adjusted EPS of $3.28 to $3.32 and reported sales growth of 5.5% to 6.5%.
- Its previous third-quarter adjusted EPS forecast was 80 to 82 cents. (Reuters)
- The company expects to recover some affected revenue as it ramps up operations and clears backlogs.
- The full financial impact remains uncertain.
- Manufacturing has resumed across most facilities globally, while major distribution centers are operating at or above normal levels. (Reuters)
- Product-quality analyses found no broad impairment, although new activations of its cardiac-device remote-monitoring platform were disrupted.
- The incident follows recent cyberattacks affecting other major healthcare companies, including Abbott, Stryker, Medtronic and Novo Nordisk. (Reuters)
- Analysts say the incident has made it harder to assess Boston Scientific's underlying business performance.
- Boston Scientific plans to provide an updated financial outlook on October 28 with its third-quarter results. (Reuters)
What This Means for Healthcare Marketers
This is a strong example of why operational disruption can become a market-intelligence signal.
A sudden decline in product availability does not necessarily mean demand has weakened. In Boston Scientific's case, the company's underlying demand may remain healthy while a cyberattack temporarily prevents products from being manufactured and shipped.
For healthcare marketers and business-development teams, that distinction matters. Order backlogs, shipment disruptions, manufacturing outages and changes in product availability can reveal market conditions that would be easy to misinterpret from sales data alone.
The broader signal is that cybersecurity events can now change when and where healthcare demand converts into actual revenue, making cyber incidents relevant not only to IT and compliance teams but also to commercial strategy.