Full-Time
Posted on 10/30/2025
Medical devices maker for interventional specialties
$61k - $115.9k/yr
No H1B Sponsorship
Waltham, MA, USA
Hybrid
Three to four days per week in-office required.
Bachelor's
See people who can refer or advise you
Boston Scientific designs and makes medical devices used in procedures across cardiology, endoscopy, urology, and neuromodulation. Its products help doctors diagnose and treat conditions by guiding minimally invasive interventions and delivering therapies inside the body, with revenue from hospitals and clinics. The firm differentiates itself through a broad, global portfolio and heavy ongoing investment in research and development to expand capabilities and address complex health issues. Its goal is to improve patient care by providing reliable, effective medical devices and solutions that enable clinicians to perform safer, more effective procedures while growing its business.
Company Size
10,001+
Company Stage
IPO
Headquarters
Marlborough, Massachusetts
Founded
1979
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Relocation Assistance
Performance Bonus
Boston Scientific cyberattack disrupts manufacturing and product shipments. September 1, 2026 Boston Scientific is working to restore its manufacturing, order processing, and distribution capabilities following a cybersecurity incident that caused a network outage across certain internal IT systems. Discover more Securing Personal Computers Exploring Online Dictionaries Computer Security In an August 30 update, the medical device manufacturer reported that investigators had found no signs of unauthorized activity in its environment since August 25. The disruption is limited to specific on-premises systems; cloud-based systems and applications remain unaffected. The company has engaged CrowdStrike and other third-party cybersecurity experts to assist with ongoing investigation and recovery efforts. Boston Scientific cyberattack. Boston Scientific first disclosed the incident on August 26, indicating that it had identified the issue a day earlier and activated incident response protocols to investigate and contain the threat. The outage has disrupted access to the operating systems and business applications necessary to manufacture products, process customer orders, and ship finished devices. Customers can still submit orders electronically through electronic data interchange (EDI) and local applications; however, these orders are currently held in a fulfillment queue until the affected operations resume. The company aims to partially restore shipping capabilities this week, with a plan to gradually ramp up order processing and shipping to full capacity once the environment is operational again. The operational disruption has direct clinical implications, as Boston Scientific provides medical technologies and manages connected device services. The company confirmed that there has been no known impact on devices not connected to the Boston Scientific network, nor is there any evidence that the affected systems have increased cybersecurity risks for hospital networks using its devices. It also reported no known issues with the functionality of implantable cardiac rhythm management devices, programmer interrogations, or remote monitoring for devices already enrolled before the outage. However, new remote monitoring activations are currently affected, delaying communications and data transmission for some newly implanted cardiac devices and insertable cardiac monitors. For non-ICM CRM implants, new remote monitoring communicators cannot be activated at this time, meaning that the available device data will not reach remote patient management systems until activation resumes. For new ICM implants, the Clinic Assistant app can activate recording. However, the affected devices cannot pair with the patient's remote monitoring mobile phone. Discover more Installing Security Systems Learning Computer Science Boston Scientific reported that episodes continue to be recorded and can be transmitted via the app during in-person interrogations. Once pairing and systems are restored, stored data should be sent to the remote monitoring platform. The company has not yet provided a timeline for complete restoration. Recovery now depends on safely rebuilding access to core on-premises business processes without compromising medical product availability or patient care. This incident highlights how IT outages at healthcare manufacturers can extend beyond corporate workflows into production, logistics, and connected care onboarding. Boston Scientific stated it is prioritizing systems that have the greatest impact on customers and product delivery and will issue further updates as functionality is restored. The company's newsroom has publicly posted updates on the incident for stakeholders. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world. Hot this week
Healthcare cyberattacks hit pacemakers and millions of patient records. McKesson admits breach as ShinyHunters demands $55.2M Published Mon 31 Aug 2026 // 22:10 UTC Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. "New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated," the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients' heart rhythms, the company added. Because of the cyberattack, "new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app," according to the update. The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the "interrogate" button, according to the company. Once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment, they will again transmit recorded data to the remote systems. However, the company does not have a timeline for full restoration. "We are currently working on restoring affected functions and systems access," Boston Scientific said on Saturday. The digital intrusion also affected the firm's manufacturing, shipping, and ordering, it noted. "We are expeditiously working towards partial restoration for the shipping of some products this week," according to a Sunday update. "Once we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity." Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps - just "certain on-premise systems" - and added that it has seen no indication of unauthorized IT activity since August 25. The firm has repeatedly declined to answer The Register's questions about the compromise, including whether it was a ransomware infection and which criminal crew is responsible. McKesson confirms breach as ShinyHunters claims responsibility. Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company's Snowflake and Salesforce instances and stole millions of patients' data. "Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we've confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units," Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement. The medical firm did not immediately respond to The Register's questions, including how many patients were affected and what "certain data" was stolen. McKesson supports about 3,300 oncology providers in 29 states, according to its website. Fraga's statement noted that distribution centers remain operational and McKesson continues to ship products. The firm has "reasonable assurance" that the digital intruders have been kicked out of the third-party environments and aren't lurking around McKesson's systems, he added. A ShinyHunters spokesperson told Hypriot that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data. However, as Have I Been Pwned boss Troy Hunt recently reminded everyone: Don't confuse criminals' claims with gospel truth, and "take headline numbers with a grain of salt unless you're confident in the processes of those making the claims." This was after Hunt's HIBP service reported 12.9 million individuals affected by retailer Carhartt's alleged breach. This number was around half of what ShinyHunters claimed when they leaked the company's data earlier this month. The McKesson records, according to the ShinyHunters spokesperson, include patients' full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people's bodies. The group also claims to have swiped emails containing private information from doctors to patients. The spokesperson told Hypriot they accessed the company's Snowflake and Salesforce instances by voice phishing "multiple employees." This is a tried-and-true method popularized by the data-theft-and-extortion gang, which has victimized other medical providers in recent months. These include pacemaker manufacturer Medtronic in April, and cancer diagnostics business Exact Sciences in July.(R)
COGNOSCERE Daily Tech Review - Issue T222 · Saturday, August 29, 2026. Curated by COGNOSCERE Editorial Team · Daily Tech Review · August 29, 2026 Saturday, August 29, 2026 · Issue #T222 | 7 ARTICLES | 1 ACT | 1 PREPARE | Information Technology · 4 articles. Ubiquiti released Security Advisory Bulletin 067 patching 22 vulnerabilities across its UniFi product line, including three CVSS 10.0 flaws enabling unauthenticated command injection and authentication bypass across UniFi Protect (camera surveillance), UniFi Talk (VoIP), and UniFi OS (network management). No active exploitation has been confirmed, but prior Ubiquiti CVSS 10 flaws were weaponized within days of disclosure. CyberScoop · Cybersecurity / Network Security · Relevance: 0.9 · Source vulnerability, network security, Ubiquiti, UniFi, patch, authentication bypass, command injection, enterprise networking Boston Scientific disclosed via an SEC 8-K filing that a cyberattack detected August 25 is causing a global disruption to its operations, impairing its ability to process and ship customer orders for medical devices including pacemakers and defibrillators across 127 countries. The company engaged third-party cybersecurity experts; the attacker, attack type, and data impact remain undisclosed. TechCrunch · Cybersecurity / Incident Response · Relevance: 0.9 · Source cyberattack, healthcare, medical devices, supply chain disruption, SEC disclosure, incident response, OT security AWS announced it will deploy an additional 2 million Nvidia GPUs - including Blackwell Ultra, Rubin, and Rubin Ultra systems - in 2027-2028, tripling a prior commitment of over 1 million chips, and expanding collaboration to include Nvidia Vera CPUs, Nemotron open models on Bedrock and SageMaker, and joint AI factory builds for the US government. TechCrunch · Cloud Computing / AI Infrastructure · Relevance: 0.9 · Source cloud infrastructure, GPU, AI hardware, AWS, Nvidia, data center expansion, AI factories, government AI Meta settled a landmark multi-state federal lawsuit alleging its platforms harmed young users, agreeing to pay up to $18 billion and implement sweeping changes to Facebook and Instagram for users under 18 - including a default 2-hour daily limit, midnight-to-6am lockout, and tighter age verification. About $5.3 billion of the settlement is contingent on TikTok and YouTube adopting comparable restrictions and paying equivalent sums. CNN · Regulation / Platform Policy · Relevance: 0.8 · Source Artificial Intelligence · 2 articles. Chinese AI lab Z.AI (Zhipu AI) confirmed that Ox Alpha - the anonymous model that led OpenRouter's leaderboards for a week - is GLM-5.3-Flash, a 320B-parameter MoE model with 18B active parameters, native multimodality, and a 1M-token context window, now released under an MIT license at roughly one-tenth the cost of comparable frontier models. The entire preview period was served on Chinese-made AI chips, raising competitive significance in the AI infrastructure supply chain. SiliconANGLE · AI Model Releases / Open Source AI · Relevance: 0.9 · Source open-source AI, model release, China AI, MoE, multimodal, cost efficiency, Chinese chips, AI competition Barret Zoph, a co-founder of Thinking Machines Lab who had recently joined OpenAI following a leadership dispute, is leaving OpenAI to become Google's Vice President of Research. The move arrives as Google restructures its AI development efforts to accelerate AI coding capabilities and compete with rivals. TLDR AI · AI Leadership / Executive Moves · Relevance: 0.8 · Source executive move, AI talent, Google, OpenAI, AI research, AI leadership Decision Support · 1 article. Dun & Bradstreet is integrating its D&B Commercial Graph and risk analytics into Perplexity and its Computer agent platform via Model Context Protocol servers, giving business users direct access to verified company identities, ownership relationships, and risk intelligence for workflows including KYC/KYB, procurement, finance, compliance, and sales - without leaving the AI interface. Digital IT News · Business Intelligence / Risk Analytics · Relevance: 0.8 · Source business intelligence, risk analytics, KYC, KYB, MCP, agentic AI, compliance, decision support, data integration Entity watch (7-day). | Entity | Type | Mentions | Active | Domains | | Nvidia | company | 11 | 5d | AI,IT | | OpenAI | company | 10 | 6d | AI,IT | | Anthropic | company | 10 | 5d | AI,DS,IT | | Microsoft | company | 9 | 6d | AI,IT | | Hugging Face | company | 5 | 4d | AI,IT | | Claude | product | 5 | 4d | AI,DS | | Amazon Web Services | company | 5 | 4d | AI,DS,IT | | Google | company | 5 | 3d | AI,IT | | Ox Alpha | product | 4 | 4d | AI | | OpenRouter | company | 4 | 4d | AI | Domain pulse (7-day). Artificial Intelligence 27 articles · Avg relevance: 0.87 · ACT: 4 · PREPARE: 4 Decision Support 10 articles · Avg relevance: 0.81 · ACT: 0 · PREPARE: 4 Information Technology 40 articles · Avg relevance: 0.86 · ACT: 10 · PREPARE: 13 | | BEYOND THE BRIEF | COGNOSCERE | Intelligence is leverage - but only when you act on it. CIFaaS turns the signals in today's brief into tracked, attributable decisions for your business. Sources preserved. Reasoning shown. Audit trail intact. Free to start · No card required · 60-second signup or engage COGNOSCERE directly | [01] ADVISORY Decision support for boards, leadership, and ops teams. Services | | [02] LIBRARY Past briefs and the CIF intelligence archive. Intelligence | | [03] NEWSLETTERS Add to your morning inbox. News pre-selected, Tech optional. Subscribe | | COGNOSCERE Daily Tech Review · Issue #T222 · Saturday, August 29, 2026
The new cyber math for CFOs: one attack, hundreds of disclosures. By PYMNTS | August 28, 2026 Highlights One cyberattack can now trigger hundreds of overlapping regulatory, contractual and operational responses across customers, vendors, insurers and jurisdictions. Every API, SaaS tool, payment system and counterparty an agent can access creates another potential liability. CFOs need a new cyber metric: obligation density. There's a new number in cybersecurity for CFOs to track, and it's not the list of what was stolen. It's the number of obligations created. Headlines this week offered a glimpse of what that new cyber math looks like. Manchester Airports Group disclosed that an unauthorized third party accessed information associated with roughly 8.7 million customers across Manchester, London Stansted and East Midlands airports. The compromised information included contact, vehicle and booking-related data, although the company said payment information and aviation security were not affected. In Australia, a cyberattack against Alliance Distribution Services, owned by Hachette Australia, has disrupted book distribution for roughly six weeks, demonstrating how an IT incident at an intermediary can become an inventory, revenue and working-capital problem for businesses down the line. Boston Scientific disclosed Wednesday (Aug. 26) that an incident detected the previous day caused a network outage affecting operating systems and business applications, including its ability to process and ship customer orders. The company filed an 8-K and said it could not yet estimate when full operations would be restored. And perhaps most consequentially, investigations into OpenAI's July security incident showed how experimental AI agents escaped their intended boundaries and reached real external infrastructure, including Hugging Face. OpenAI has described the episode as unprecedented and said it has tightened infrastructure controls while conducting further investigation. Taken together, these incidents expose the same underlying corporate vulnerability. Companies have built interconnected enterprises. Their incident-response models still largely assume discrete incidents. The Cyberattack blast radius is becoming the business graph. Traditional cyber planning tended to begin with infrastructure: What systems could be compromised? What data could be stolen? How quickly can the attacker be contained? But the architecture of the modern enterprise has changed faster than the architecture of incident response. Companies have spent years connecting cloud environments, APIs, SaaS applications, payment systems, data platforms, suppliers and customers. Agentic AI promises to make those connections more productive by allowing software to move across them and take action autonomously. The emerging risk for CFOs and CISOs is therefore not simply a larger attack surface. It is a larger obligation surface: every system an autonomous process touches can potentially bring another customer agreement, regulator, insurer, jurisdiction, disclosure requirement or business dependency into an incident. The administrative cost of a cyberattack correlates not only with the amount of data compromised, but with the connectivity of the company experiencing it. Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks! PYMNTS covered on Thursday (Aug. 27) how the rise of artificial intelligence-powered hacks already has cyber insurance firms rethinking their policies. A conventional software application generally performs predetermined functions inside relatively stable boundaries. An enterprise AI agent is valuable precisely because those boundaries are more permeable. Give an AI agent access to email, CRM, ERP software, cloud storage, payment infrastructure and procurement systems, and it can potentially complete an entire workflow without requiring a person to move information between applications. The PYMNTS Intelligence report "Vendors and Vulnerabilities: The Cyberattack Squeeze on Mid-Market Firms" found that hackers increasingly target middle market firms. These companies depend on third-party cloud providers, software-as-a-service platforms and managed service providers, which can leave them exposed. Agentic AI turns permissions into potential liabilities. Every permission also represents another possible path through which an incident can acquire financial, regulatory or contractual significance. During OpenAI's cybersecurity evaluations, models found and chained vulnerabilities across OpenAI's research environment and Hugging Face's production infrastructure. OpenAI said it subsequently imposed stricter infrastructure controls, accepting an impact on research velocity while vulnerabilities were addressed. The broader lesson for companies deploying agents is that agent permissions need to be understood as financial exposures, not merely technical configurations. Depending on the incident, companies can simultaneously face state privacy requirements, international data-protection rules, sector-specific regulators, customers, cyber insurers, lenders, payment networks, vendors and contractual notification clauses. A company that tells a customer one version of an incident, an insurer another and investors a third has created a second-order governance problem even if each individual disclosure was produced in good faith as the investigation evolved. A payment orchestration platform touching thousands of merchants may carry a radically different exposure from an internal application containing a comparable amount of data. A SaaS administrator credential connected to dozens of applications may create more consequential downstream obligations than a much larger isolated database. IBM said last month that a higher percentage of companies were planning to up their security spending after finding out about the cyber capabilities of frontier AI models, and 68% of financial institutions increased their fraud-detection budgets year over year, according to the "2025 State of Fraud and Financial Crime in the United States," a PYMNTS Intelligence report produced in collaboration with Block. That spending comes as 46% of institutions report increasingly sophisticated fraud schemes, up from 35% a year earlier.
Cyberattack disrupts Boston Scientific network, global operations halted. Post Views: 10 Medical technology firm Boston Scientific experienced a cybersecurity incident that led to a network failure, affecting its operational capabilities across multiple regions. Incident overview. The company, which specializes in minimally invasive medical devices such as stents, catheters, pacemakers, and defibrillators, reported the breach on August 25. It immediately initiated incident response procedures and engaged external cybersecurity professionals to investigate and mitigate the threat. Impact on operations. The company confirmed that the incident has impaired access to critical systems and applications essential for business operations, including order processing and shipment functions. While efforts to restore affected services are ongoing, no timeline for full recovery has been established. Financial and security status. Boston Scientific has not classified the event as material, stating that it has not yet determined if the incident could significantly impact financial performance. Details about the attack remain limited, and no entity has publicly claimed responsibility. Broader implications. This incident adds to a series of cyberattacks targeting medical technology firms this year, including Stryker, iRhythm Holdings, Novo Nordisk, and Xsolis. The breach highlights growing vulnerabilities in the healthcare sector's digital infrastructure.