Remote monitoring for newly implanted cardiac devices and the privacy of millions of patient records are immediately at stake after two separate intrusions: Boston Scientific’s IT environment was hacked on or after August 25, and McKesson confirmed unauthorized access to third‑party applications after a claim by the extortion group ShinyHunters.
Boston Scientific: new implants cannot transmit remotely
Boston Scientific said the intrusion “remains ongoing” and that pacemakers and other heart devices implanted after the August 25 breach “cannot provide remote monitoring and data transmission as intended.” In a late‑Friday update the company warned: “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated.”
The company specified this applies to “all new cardiac rhythm management implants other than insertable cardiac monitors (ICM).” For ICM devices, Boston Scientific said they “must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms,” and added that, because of the attack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app.”
Boston Scientific emphasized that the devices will still record episodes and that patients can transmit recordings by an in‑person transmission using the Clinic Assistant app’s “interrogate” button. The company said recorded data will transmit again “once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment,” but it offered no timeline for full restoration.
Operational impacts, remediation steps, and visibility
The digital intrusion also affected Boston Scientific’s manufacturing, shipping, and ordering operations, the company said. In a Sunday update it said it was “expeditiously working towards partial restoration for the shipping of some products this week” and that “once we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity.”
Boston Scientific has engaged CrowdStrike to assist with investigation and restoration. The firm told reporters the attack did not affect its cloud‑based systems and apps but did affect “certain on‑premise systems,” and that it has “seen no indication of unauthorized IT activity since August 25.” The company has repeatedly declined to answer questions about whether the intrusion was a ransomware infection or which criminal crew is responsible.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMcKesson confirms intrusion as ShinyHunters claims massive haul
Pharmaceutical and medical‑supply giant McKesson confirmed an intrusion after ShinyHunters told The Register it had broken into the company’s Snowflake and Salesforce instances and stolen millions of patients’ records. McKesson executive vice president Francisco Fraga said on Saturday: “Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third‑party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical‑Surgical business units.”
Fraga did not answer follow‑up questions asking how many patients were affected or what “certain data” was stolen. McKesson’s website says the firm supports about 3,300 oncology providers in 29 states. Fraga added that distribution centers “remain operational and McKesson continues to ship products,” and that the company has “reasonable assurance” that the digital intruders have been kicked out of the third‑party environments and aren’t lurking in McKesson’s systems.
ShinyHunters’ spokesperson claimed the group compromised “more than 284 million records” and demanded $55.2 million, asserting the haul included “patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies,” as well as emails between doctors and patients. The spokesperson said the group accessed Snowflake and Salesforce by voice phishing “multiple employees.”
The Register also quoted Troy Hunt of Have I Been Pwned, who urged caution with criminal claims: “take headline numbers with a grain of salt unless you're confident in the processes of those making the claims.”
How oncology providers, Boston Scientific patients, and security teams are responding
- Oncology & Multispecialty providers: Providers supported by McKesson will need to watch communications from McKesson about which customers and patient records were affected; McKesson said the exfiltration was tied to a subset of customers within specific business units.
- Patients with newly implanted Boston Scientific devices: Those implanted after August 25 cannot rely on remote monitoring to transmit episode data automatically; patients were told episodes are still recorded and can be transmitted in person using the Clinic Assistant app’s “interrogate” function until systems are restored.
- Security teams and incident responders: Both companies have engaged outside expertise—Boston Scientific with CrowdStrike and McKesson with “leading cybersecurity industry experts”—and will be focused on restoring on‑premise functionality, confirming eradication of intruders from third‑party environments, and assessing the scope of any data exfiltration.
Conclusion: unresolved scale and timelines
The two incidents underscore different but overlapping harms: Boston Scientific’s breach has immediate medical‑device availability consequences for patients implanted after August 25, while McKesson’s confirmed intrusion centers on alleged mass data exfiltration tied to oncology and medical‑surgical customers. Key facts remain unresolved in public statements — notably how many patients’ records were taken in the McKesson incident and when Boston Scientific will fully restore on‑premise systems and remote monitoring functions. Boston Scientific has declined to say whether the intrusion involved ransomware, and McKesson has not published a patient‑count or a full data inventory; investigators and customers await clearer timelines and disclosure from both firms.
Source: The Register — Healthcare cyberattacks hit pacemakers and millions of patient records




