Skip to content
Rush Commerce
Commerce & Retail Tech3 min read

Boston Scientific cyberattack: can you still take orders?

A cyberattack knocked out order processing and shipping at a global medical device maker. The lesson isn't about data theft — it's about order intake.

Most breach coverage asks what data walked out the door. The Boston Scientific cyberattack is a different kind of story, and a more useful one for anyone who sells things: nobody has confirmed stolen data yet, but the company can't reliably process and ship customer orders. The revenue stopped before the lawyers got involved.

What actually happened

Boston Scientific disclosed in an 8-K filed with the SEC that it detected a cybersecurity incident on August 25, 2026. Per Cybersecurity Dive, the attack hit the company's IT network and key business applications, and the disruption to order processing and shipping is global. The company activated its incident response plan and brought in outside cybersecurity specialists.

What it has not said is nearly as important. Boston Scientific hasn't determined the full scope, hasn't said how attackers got in, hasn't confirmed whether data was taken, and couldn't estimate how long restoration will take. Citing the Irish Examiner, Cybersecurity Dive reported that thousands of workers were told to work from home in Ireland, where the company runs three manufacturing and R&D sites. No group has publicly claimed the attack. Shares fell roughly 4–6% on the news.

Why it matters for your business

Boston Scientific's customers are hospitals waiting on stents and catheters. Yours are waiting on something less dramatic. The mechanism is identical: when the order system goes dark, the business stops taking money, and nobody outside needs to have stolen a single record for that to happen.

So run the drill on your own stack. If your order management system, your ERP, or the integration between them went down at 9am tomorrow, what happens? Most operators discover three things at once. Open orders exist only inside the system that's down. Nobody knows current stock without querying it. And there is no procedure for taking an order by phone and getting it into fulfillment later.

The fix is cheap and boring. Export open orders, customer contacts, and inventory counts on a schedule to somewhere outside the primary system — a nightly CSV to object storage will do. Write a one-page manual intake procedure and make sure someone other than you has run it. Draft the customer notice now, while you're calm, so you're not composing it during the outage. And ask your own critical suppliers the same question, because their downtime becomes your stockout.

Availability is a security property. Most small-business continuity plans budget for a data breach and quietly assume the order pipe stays up.

Key takeaways

  • Boston Scientific detected a cyberattack on August 25, 2026 and disclosed it in an SEC 8-K; order processing and shipping are disrupted globally
  • No data theft has been confirmed and no group has claimed responsibility — the damage so far is operational, not disclosure-driven
  • The company could not estimate restoration time or financial impact at the time of filing
  • Test your own failure mode: can you take and fulfill an order with your primary system offline?
  • Schedule exports of open orders, customer contacts, and stock counts to a system that isn't the one at risk

If your order system went down this morning, how long until you could take an order again? We build commerce stacks with the boring parts covered — scheduled exports outside the primary system, a manual intake path that actually works, and integrations that fail loudly instead of silently. See how we work.

Sources: Boston Scientific 8-K (SEC), Cybersecurity Dive.

  • #cyberattack
  • #business-continuity
  • #order-management
  • #vendor-risk
  • #operations
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.