Medical device manufacturer Boston Scientific said it is experiencing a global operational disruption after detecting a cyberattack on August 25.
The incident has restricted access to information systems and business applications used across the company, including systems needed to process and ship customer orders. Boston Scientific said the disruptions are expected to continue while recovery efforts are underway, and it does not yet have a timeline for full restoration.
In Ireland, staff at its Cork facility were sent home Tuesday, and employees able to work remotely were subsequently instructed to do so.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A cardiac device that misses its ship date can mean a cancelled surgery. That’s what makes a company like Boston Scientific such an attractive extortion target. The attacker doesn’t need to destroy anything. They just need to make downtime more expensive than whatever they’re asking for.
“Medical devices also aren’t something a hospital can always swap out at the last minute. Physicians have selected specific devices, patients are scheduled, inventory is already in place, and procedures have been planned around them. Disrupt order processing and shipping and the consequences show up in hospitals pretty quickly.
“The harder problem is getting manufacturing back online. These aren’t ordinary IT systems. Software involved in producing and tracking FDA-regulated devices sits inside a validated quality system. Restoring a server is one thing. Establishing that the data coming out of that system can still be trusted is another.
“You can’t ship something that gets implanted in a human body on trust alone. If production or quality systems were affected, Boston Scientific may have to establish that records are intact and trustworthy before normal operations resume.
“That’s why employees at Boston Scientific’s manufacturing facility in Cork, Ireland being sent home matters. This isn’t just people losing access to email. The company has already confirmed disruption to order processing and shipping, and Cork shows that disruption reaching manufacturing operations. If quality or production data was also affected, getting the servers running could be the easy part.”
Damon Small, Board of Directors, Xcape, Inc.:
“When a cyberattack halts order fulfillment and logistics across a global enterprise, an IT security incident becomes an immediate revenue and medical supply chain crisis. Because details regarding the initial attack vector remain sparse, it is not possible to recommend specific preventive technical steps for other organizations. That said, cybercriminals are often opportunistic and exploit vulnerable systems as soon as they discover them; it is currently unknown whether this was a targeted attack or just bad luck. Regardless of the entry point, disruption to core business applications forces defensive network isolation to stop lateral movement.
“To maintain operational continuity during an ongoing intrusion, security teams must enforce strict logical boundaries between corporate administrative networks and fulfillment environments, maintain immutable offline backups, and regularly validate manual failover protocols.
“Critical Takeaways:
- When enterprise applications stall, cyber incidents rapidly escalate from IT disruptions to severe supply chain and revenue crises.
- Attack vectors remain unconfirmed because threat actors frequently exploit opportunistic vulnerabilities rather than executing targeted campaigns.
- Maintaining operational continuity requires enforcing strict network segmentation between administrative and fulfillment environments before an incident occurs.
“Whether hit by targeted sophistication or bad luck on an unpatched system, the operational result remains the same without proper segmentation.”
Medical devices are the next frontier in terms of threat actors pwning organizations. I hope that all medical device companies are paying attention to this situation.
UPDATE: Jeremy Leasher, Forward Deployed Security Architect, Binalyze Had This To Say:
“Boston Scientific appears to be the latest scalp for hackers targeting the healthcare industry, with many crucial suppliers and manufacturers affected in the past year or so.
“The fact that international staff have been told to work from home and offices have been shut suggests this may not be a simple smash-and-grab attack. It doesn’t appear to be about data but about stopping the business’ ability to provide its services. What we are likely to find out once the dust settles, is that the attack was predicated on some existing known security gap or flaw, and that the attacker’s initial entry is probably tied to some user or entity based credential that was exposed.
“This is another proof that the lines between types of cyberattack have essentially been wiped away. While we don’t know who’s behind it, affecting a medical company’s ability to supply things like pacemakers and stents is quite literally a matter of life and death for patients.
“Speed is everything for attacks like this. Investigation can’t be an afterthought, organisations need to know if the attackers are still inside systems, which systems were affected and how attackers got in. The faster those questions are answered, the faster you can begin recovery and ensure an appropriate response.”

A phishing-as-a-service platform now uses AI voice agents posing as “Apple Support” to unlock stolen iPhones, for under 10 cents a call
Posted in Commentary with tags Apple on August 26, 2026 by itnerdResearchers identified AnonyMousKIT, a phishing-as-a-service platform built to bypass Apple’s Activation Lock on stolen devices, using AI voice agents (all posing as “Alice from Apple Support,” running on the commercial Vapi voice platform in English, Spanish, and Portuguese) to trick victims into handing over passcodes, Apple ID credentials, and two-factor codes, information Apple says it never asks for.
You can find more details here: AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
Gidi Cohen, CEO & Co-Founder, Bonfy.AI:
“The real story here isn’t that AI can impersonate Apple Support convincingly, it’s how cheap that’s become. $0.096 a call gets you a voice agent that can run the whole script in three languages: ask for the passcode, then the Apple ID, then a live 2FA code. That used to take a skilled scammer sitting on the phone. Now it’s a rented service with published pricing and customer support. AI didn’t invent this scam, it just took the labor cost out of it, and that changes who can run one and how many they can run at once.
It’s also a good reminder that the backend behind these operations is usually way messier than the polished lure emails suggest. Researchers got into months of call logs, transcripts, and persona configs because of two exposed file paths, not some clever hack. Even the people running these platforms don’t seem to have much visibility into their own exposure.
But the part worth actually worrying about isn’t stolen phones, it’s what happens when this same trick gets pointed at employees instead of consumers. Cheap, real-time voice AI means help-desk calls, vendor calls, password-reset calls are all about to get a lot harder to sniff out just by listening. If a fake “Apple Support” agent can talk someone out of a 2FA code for pennies, the same setup works just as well faking IT support to get into a company. Security teams need eyes on how AI is being used against them, not just how it’s being used inside their own walls.”
Apple users need to be alive to this threat along with many other threats. Because there will always be a new threat that users need to keep their eyes out for.
Leave a comment »