Boston Scientific’s Cyberattack Is Now Hitting the Numbers

Cyberattacks don't only steal information. Sometimes they show up directly in an earnings report.

Medical-device giant Boston Scientific says a cybersecurity incident discovered on August 25 is likely to have a material impact on its third-quarter and full-year 2026 results.

The company now believes it is unlikely to meet the sales growth and adjusted earnings guidance it issued in July.

That makes the incident a useful example of something cybersecurity teams have warned about for years.

Cyber risk is business risk.

The attack disrupted physical operations

Boston Scientific said unauthorized activity affected some of its IT systems and caused a network outage.

That disrupted access to operating systems and business applications used for critical activities, including manufacturing, processing customer orders and shipping products.

The company's response involved third-party cybersecurity experts, including CrowdStrike.

Boston Scientific says it has not identified evidence of continuing unauthorized access, while its investigation remains underway.

Recovery doesn't instantly recover revenue

Many of the affected systems are returning.

Major distribution centers are again processing and shipping orders, sterilization facilities are operational and manufacturing has restarted across most global locations.

But restoring a server isn't the same as restoring a quarter.

Orders can pile up.

Manufacturing schedules move.

Deliveries are delayed.

Employees lose productive hours.

Customers may find alternatives.

That is why even a successfully contained cyberattack can create financial damage long after attackers lose access.

The numbers make cyber risk easier to understand

Before the incident, Boston Scientific had projected full-year adjusted earnings of approximately $3.28 to $3.32 per share and sales growth of 5.5% to 6.5%.

The company now says those targets are unlikely to be met because of the operational impact from the incident.

It plans to provide a more detailed financial update with its third-quarter results in October.

For boards and executives, cases like this change the cybersecurity conversation.

Security spending can often look like insurance against something hypothetical.

A cyber incident affecting revenue makes the return on prevention much easier to see.

Healthcare is an especially difficult target

Cybersecurity is particularly consequential in healthcare.

The sector depends on complex networks connecting manufacturers, hospitals, medical devices, suppliers, insurers and patient systems.

A disruption somewhere in that chain can produce effects far beyond IT.

Boston Scientific has said its analyses found no impairment to product function beyond previously disclosed disruption involving some new remote-monitoring activations.

Still, the incident demonstrates how cyberattacks against medical companies can quickly become operational events.

Cybersecurity is moving onto the balance sheet

Companies have spent years describing cybersecurity as a strategic priority.

Incidents like this make that statement measurable.

When network downtime affects manufacturing, shipments and earnings guidance, cybersecurity is no longer simply the CISO's responsibility.

It becomes relevant to operations teams, finance executives, investors and the board.

The new cybersecurity metric may not be how many attacks were blocked.

It may be how much revenue stayed protected because the systems kept running.


Our latest news