Medical device makers have faced several cyberattacks in 2026, disrupting manufacturing, shipping and order processing for hospitals nationwide. Here’s where four significant incidents stand now.
- Boston Scientific — Hackers hit Boston Scientific’s IT systems Aug. 25, triggering a global network outage that disrupted order processing and shipping for pacemakers, stents, defibrillators and Watchman implants. The company said the incident did not affect the function or remote monitoring of implanted cardiac devices. By early September, Boston Scientific had resumed shipping the majority of its products from its major distribution centers and later fully restored operations.
- Abbott — Abbott disclosed July 16 that legacy Exact Sciences cancer diagnostics systems it acquired through its purchase of the company were hit by a cyber incident. Abbott said the incident did not affect business operations, product availability, manufacturing or lab operations and that no other Abbott systems were affected because the legacy Exact Sciences infrastructure remained separate. The company said it does not expect a material impact on its business or financial results.
- Medtronic — The ShinyHunters extortion group claimed to have stolen more than 9 million records from Medtronic’s corporate IT systems after gaining access April 13-19. The company disclosed the breach April 24. State attorney general filings later confirmed the exposure of Social Security numbers and health information belonging to at least 72,000 residents of Massachusetts and Vermont. Medtronic began notifying individuals in late June, offering two years of credit and dark web monitoring, and said the breach did not affect systems supporting its products, manufacturing or hospital customers.
- Stryker — Hackers disrupted Stryker’s internal Microsoft environment March 11, wiping roughly 40,000 employee laptops and phones and delaying some patient-specific surgical cases. An Iran-linked group known as Handala claimed responsibility, though Stryker did not confirm the attribution and said no ransomware or malware was deployed. The company returned to full operations by April 1 and told investors on an April 30 earnings call that the roughly three-week manufacturing pause pushed some revenue recognition into later quarters. CEO Kevin Lobo said he was not aware of the company losing any business because of the incident. Stryker is now fighting a class-action lawsuit tied to the incident, arguing plaintiffs’ data had already appeared in previous breaches unrelated to Stryker.