Boston Scientific says a cybersecurity incident has disrupted its operations globally, and that what it cannot reliably do is process and ship customer orders
Stock photo
Boston Scientific has told the government it cannot reliably ship its orders.
The device maker filed a Form 8-K at 06:06 on Wednesday morning, before the market opened, saying it identified a cybersecurity incident the previous day that affects certain of its information technology systems and "has resulted in a global disruption to the Company's operations". There is no exhibit attached to it. There is no press release. The filing is the announcement.
The scope, in the company's own words
Read the sentence about scope slowly, because it is unusually specific for a disclosure made a day after detection.
The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain information systems and business applications that support aspects of the company's operations, the filing says, "including the ability to process and ship customer orders". Boston Scientific makes stents, catheters, pacemakers and defibrillators, and orders are how those reach the hospitals that implant them. The company says it is working to restore the affected functions and systems access. It does not say when that will be done. The timeline for a full restoration, in its own words, is not yet known.
What the filing does not contain
No attacker. No ransom demand, no extortion, no group claiming anything, and no country.
There is also no statement about data. Neither of the two comparable filings in this archive is silent on that point: Amgen said in July that patient protected health information had been exfiltrated, and Levi Strauss said in August that corporate information had. Boston Scientific says nothing either way, and an absence in a filing is an absence, not a denial.
The materiality question is left open
The filing sits under Item 8.01, the voluntary Other Events heading, rather than Item 1.05, which is the item a company uses once it determines a cybersecurity incident is material. The string 1.05 appears nowhere in the document. What is different here is the reason: the company does not say the incident is immaterial, it says the investigation is ongoing, the full scope and impacts are not yet known, and that accordingly it has not yet determined whether the incident is reasonably likely to have a material impact.
That is a third answer to the question, and it is the honest one available a day in.
Susan Thompson, the chief corporate counsel, signed it.

