Boston Scientific Cyberattack Disrupts Cork Operations as 7,000 Irish Staff Told to Work from Home
Boston Scientific has confirmed a significant cyberattack that has disrupted its global operations and forced the company to send staff home from its Irish facilities in Cork, Clonmel, and Galway, with the company's chief information officer issuing a work-from-home directive as third-party cybersecurity specialists were brought in to investigate and contain the breach.
Background
Boston Scientific is one of the largest employers in the Irish medtech sector, with more than 7,000 people working across its three Irish facilities. The company's Cork operations, centred on the Model Farm Road plant in the city's north-west, employ approximately 1,200 people and manufacture a range of medical devices including stents, catheters, and electrophysiology products. The Clonmel facility in County Tipperary and the Galway plant add further significant employment to the company's Irish footprint.
The medtech sector is one of Ireland's most important industrial clusters, accounting for a disproportionate share of the country's exports and employing tens of thousands of people directly and indirectly. Ireland is home to nine of the world's top ten medtech companies, and the sector's concentration in the south and west of the country — in Cork, Galway, Limerick, and Tipperary — makes it a critical component of regional economies that have fewer alternative employment options than Dublin.
Cyberattacks on manufacturing and healthcare companies have become increasingly common globally, with ransomware groups specifically targeting organisations whose operations are time-sensitive and whose disruption carries significant financial and reputational costs. The medtech sector is particularly vulnerable because its products are used in clinical settings where supply chain disruptions can have direct patient safety implications.
Key Developments
Boston Scientific detected the intrusion on 25 August and publicly disclosed the incident on 26 August through a newsroom statement and a Form 8-K filing with the US Securities and Exchange Commission. The company's chief information officer, Catherine Stoessel, issued an email to staff early on 26 August instructing employees to work from home where possible while recovery efforts were underway.
At the Model Farm Road plant in Cork, day-shift workers were sent home with pay on 25 August, and contract staff on the evening shift were compensated for partial shifts. Similar measures were reported at the company's other Irish plants, where staff were advised that on-site requirements would be managed on a case-by-case basis. The cyberattack primarily impacted the company's ability to process and ship customer orders, creating potential supply chain challenges for hospitals and health systems that rely on its medical devices.
As of the announcement, the full scope of the attack — including whether any sensitive data was accessed or exfiltrated — remained under investigation. Boston Scientific had not established a definitive timeline for full system restoration and had not yet determined whether the incident would have a material financial impact on its global business. The company adopted a phased approach to restoring its systems, prioritising areas based on business needs.
Why It Matters
The Boston Scientific cyberattack is the latest in a series of high-profile incidents affecting major employers in Ireland, and it raises important questions about the cybersecurity resilience of the country's industrial base. Ireland's concentration of multinational manufacturing — particularly in sectors like medtech and pharmaceuticals, where supply chain disruptions have direct patient safety implications — makes the country a potentially attractive target for ransomware groups seeking maximum leverage. The incident also comes at a sensitive time for Boston Scientific in Ireland: the company disclosed $700 to $800 million in restructuring charges in July 2026, and the cyberattack adds further operational uncertainty to an already complex period. For the 7,000 Irish employees, the immediate impact is disruption and uncertainty; for the broader Irish economy, the incident is a reminder that the country's dependence on a relatively small number of large multinational employers creates systemic vulnerabilities that require ongoing attention from both government and industry.
Local Impact
In Cork, the disruption to the Model Farm Road plant has had an immediate knock-on effect on the local economy, with contract workers and suppliers affected by the reduced activity. The plant is one of the largest single-site employers in Cork city, and its workforce includes a significant proportion of workers from the surrounding areas of Bishopstown, Wilton, and Ballincollig. The Cork Chamber of Commerce has indicated it is monitoring the situation and is in contact with Boston Scientific's Irish management team. IDA Ireland, which has a long-standing relationship with Boston Scientific as one of its flagship clients, has also been briefed on the incident and is understood to be offering support. The company's Clonmel facility, which employs several hundred people in County Tipperary, and its Galway plant have both been affected by the work-from-home directive.
What's Next
Boston Scientific has indicated it will provide further updates as its investigation progresses and as systems are restored. The company is working with third-party cybersecurity specialists and has not yet attributed the attack to any specific threat actor or group. The National Cyber Security Centre in Ireland has been notified of the incident and is understood to be in contact with the company. Boston Scientific has not indicated a timeline for the full restoration of operations at its Irish facilities, but has said it is prioritising the resumption of order processing and shipping to minimise the impact on hospital customers.
