Implant technology01 sources

Boston Scientific cyberattack stops new pacemakers reporting home

A titanium-cased dual-chamber pacemaker photographed against white, its clear epoxy header showing two lead ports marked RA and RV above the engraved device model text.

Boston Scientific / image galleryPress kit

Boston Scientific detected a cybersecurity incident on 25 August 2026 affecting on-premise systems, and its update of 30 August sets out what the intrusion reached. The company states that its investigation to date demonstrates no impact to implantable cardiac rhythm management device function: pacemakers, defibrillators and monitors already inside patients keep working.

What stopped is the link back out. New remote monitoring communicators cannot be activated, so device data from cardiac devices implanted since the incident is not transmitted to remote patient management systems. Newly placed insertable cardiac monitors cannot pair with the patient’s monitoring phone, so the episode data they record stays on the device. Manufacturing was disrupted along with the ability to process and ship customer orders, across CRT-Ds, ICDs, CRT-Ps, pacemakers, subcutaneous ICDs and insertable monitors. Orders could still be taken electronically and queued.

The company said it expected partial restoration of shipping for some products during that week, and that the timeline for full restoration is not yet known.

An implant that cannot report is not a failed implant, but it is a downgraded one: remote monitoring is how arrhythmias and lead problems are caught between appointments. The attack surface of an implanted device now plainly includes the manufacturer’s own network.

Sources

  1. [1]Update on Recent Cybersecurity IncidentBoston Scientific··Newsroom