Summary
- Boston Scientific has resumed shipping most products from its European distribution centre, although a backlog remains and manufacturing has not fully restarted.
- The cyber incident disrupted order processing, shipping, manufacturing systems, and access to business applications.
- NHS Supply Chain has activated incident-management and clinical-substitution processes as the digital outage works through the physical supply chain.
A cyberattack on medical-device manufacturer Boston Scientific is continuing to work through NHS logistics more than a week after the initial incident, with most European shipping restored but manufacturing still disrupted and hospitals being prepared to use alternative products where necessary.
Boston Scientific identified the cybersecurity incident on 25 August after unauthorised activity affected parts of its internal IT estate and caused a network outage. The disruption reached systems used to manufacture products, process customer orders, and ship them, turning an internal technology failure into a healthcare supply problem.
By 4 September, NHS Supply Chain said Boston Scientific had resumed processing and shipping the majority, but not all, of its products using stock in its European distribution centre. Extra shifts were being used to clear queued orders, although manufacturing had not yet restarted and the supplier remained unable to access the NHS Supply Chain Supplier Portal.
Orders can still be placed through the NHS catalogue and enter a queue for fulfilment, while Boston Scientific has established an emergency route for products required for procedures within the following 48 hours. NHS Supply Chain is also preparing clinical information and lists of alternatives where individual products remain constrained.
Cyber recovery has become a logistics problem
The response now extends beyond security teams. NHS Supply Chain established a Major Incident Team and has been working with NHS England, the Department of Health and Social Care, and the National Supply Disruption Response operation, while trusts were briefed through a customer webinar on 4 September.
Boston Scientific has brought in CrowdStrike to help investigate and restore affected systems. NHS Supply Chain said no further evidence of unauthorised activity had been found since the date of the attack, although forensic assurance and restoration work were continuing.
The operational damage has not depended on compromised medical devices. Enterprise systems that handle orders, warehouse operations, manufacturing, and distribution can interrupt healthcare delivery even when the clinical products themselves remain safe to use.
That distinction exposes a wider dependency created by highly integrated supply chains. Manufacturers automate ordering, picking, packing, production, and distribution because connected systems reduce inventory and speed fulfilment. Once those applications become unavailable, a warehouse can contain usable stock while the company loses its normal ability to allocate and move it.
Physical resilience inherits digital dependencies
Boston Scientific’s recovery illustrates the resulting lag. Electronic orders continued to arrive while automated fulfilment was unavailable, producing a backlog that must now be processed as systems return. NHS Supply Chain has meanwhile been managing delivery dates manually because the supplier still lacks access to the portal used to update order status.
The consequences are harder to absorb in healthcare than in many commodity supply chains. A medical device may be tied to a particular procedure, staff training, other equipment, or patient needs, so substitutions can require clinical assessment rather than a simple procurement switch.
Cyber resilience for strategically important suppliers consequently extends beyond restoring backups. Recovery plans also need to cover which orders receive priority, what happens when automated warehouse systems are unavailable, how manual processes operate, which products have clinically acceptable substitutes, and how customers receive reliable information when enterprise systems are only partly restored.
Boston Scientific’s partial restoration has reduced immediate pressure, although digital recovery and supply recovery are moving on different timelines. Applications can return while backlogged orders, delayed manufacturing, and substitutions continue to affect the physical network.
The ultimate operational and financial impact remains under investigation. NHS organisations are therefore watching a more immediate measure of recovery: whether restored distribution can clear outstanding orders before individual shortages translate into delayed procedures. The incident shows how quickly a cyber event inside a supplier can become an operational resilience problem for organisations that never connected directly to the compromised network.












