Boston Scientific (NYSE: BSX) shares are down more than 5% today after the minimally invasive medtech company said a cybersecurity incident will make it unlikely to meet previously set full-year guidance.
On July 29, the company reduced its full-year sales growth outlook to 5.5%–6.5% from the previous 7%–8.5% range. (A few months before, the company cut its guidance from 10.5%–11.5% growth.) It also lowered its adjusted earnings per share (EPS) guidance to $3.28–$3.22 from $3.34–$3.41 .
Now, it seems sales growth and EPS could be even lower after the global network communications outage that hit Boston Scientific in late August.
In a Form 8-K filed with the SEC yesterday, Marlborough, Massachusetts–based Boston Scientific said it is continuing to restore many of the affected systems, including substantial restoration of its distribution network. According to the company, its major distribution centers are now processing and shipping customer orders at or above normal operating levels.
Boston Scientific is working with third-party cybersecurity experts to investigate the outage, which it says involved unauthorized activity that affected access to certain operating systems and business applications, disrupting manufacturing, order processing and shipping. It’s still uncertain when operations will be fully restored.
Because of the cybersecurity incident, Boston Scientific officials now think that it is unlikely that the company will meet its previously provided guidance, with a material impact on operations likely for the third quarter and full year. The Form 8-K said: “The company anticipates recovering some portion of the impacted revenue as it continues to ramp operations globally, fulfill customer orders and reduce remaining backlogs; however, the full impacts are not yet known.”
The cybersecurity incident is the latest in a string of cybersecurity incidents that medical device companies have disclosed this year. Earlier this year, an Iran-backed cyberattack effectively wiped out data on Stryker’s Microsoft-based IT system. Medtronic, Intuitive, Novocure, and iRhythm have also reported cybersecurity incidents.
