Boston Scientific is heading into one of the more closely watched earnings calls of the quarter. The cardiac and medical device maker confirmed it will report third-quarter 2026 results on October 28, 2026, before an 8:00 a.m. ET conference call, according to the company’s own investor-relations listing. That date now carries extra weight because of what happened in the weeks before it.
On September 8, 2026, Boston Scientific told investors it was unlikely to hit the third-quarter and full-year net-sales and adjusted-earnings guidance it had issued earlier in the year. The company pointed to a cybersecurity incident that disrupted manufacturing, order fulfillment and global operations. It did not attach a dollar figure to the damage, and it said a revised outlook would arrive alongside the October 28 results.
That combination, a confirmed earnings date, a confirmed guidance warning, and an unconfirmed price tag, is why this story keeps circulating under headlines calling it an “outlook reset.” Boston Scientific has not used that phrase itself. What the company has put on the record is narrower, and this piece sticks to that record while explaining why the gap between what’s confirmed and what’s rumored matters for anyone tracking the stock, the sector, or the broader pattern of cyberattacks hitting medical device makers in 2026.
The October 28 Call Investors Are Bracing For
Boston Scientific’s investor-relations page lists the event plainly: a conference call discussing third-quarter financial results, covering the quarter that ended September 30, 2026. There’s no ambiguity about the date or the time. What’s unresolved is the content. Boston Scientific said in September that it would use this call to lay out an updated operational and financial outlook, which means October 28 is less a routine quarterly check-in and more a referendum on how deep the cyberattack’s financial wound actually runs.
For a company the size of Boston Scientific, with a device portfolio touching roughly a fifth of the world’s cardiac implants, guidance updates tend to move the stock quickly. Markets had already reacted once, when the company first disclosed the incident over the summer, as shattered.io reported at the time. The October 28 call is where the company has to put real numbers next to that earlier warning.
Timeline: From an August Breach to a September Warning
The sequence of confirmed events, stripped of speculation, reads like this. Boston Scientific disclosed a cybersecurity incident that hit manufacturing, order fulfillment and global operations. By September 8, 2026, the company told investors it was unlikely to meet the third-quarter and full-year guidance it had previously issued. It committed to a full, revised outlook on October 28, 2026, timed to the Q3 earnings release.
Aug 2026 : Cybersecurity incident disrupts manufacturing,
order fulfillment, and global operations
Sep 08 : Company says it's unlikely to meet Q3/FY26
net-sales and adjusted-EPS guidance
Sep 30 : Fiscal quarter closes
Oct 28 : Q3 2026 results + revised outlook,
8:00 a.m. ET conference call
Two gaps stand out in that timeline. First, roughly seven weeks passed between the September warning and the October 28 results, meaning investors have been operating on an “unlikely to meet guidance” statement with no specifics for that entire stretch. Second, Boston Scientific has not published a precise estimate of lost sales or earnings tied to the incident, an unusually conservative stance next to how some other breached companies have handled disclosure. The timing gap between hack and detail is a recurring theme this year. EY’s own breach disclosure took 81 days after a 15-day intrusion, and regulators have increasingly flagged that lag as a problem in its own right.
The Guidance Boston Scientific Built Before the Hack
To understand what’s at stake on October 28, it helps to see what Boston Scientific was promising before the incident forced a rethink. Heading into 2026, the company had guided to full-year adjusted earnings per share of $3.28 to $3.32, with net sales growth of 5.5% to 6.5%. For the third quarter specifically, the range was tighter: adjusted EPS of $0.80 to $0.82, with net sales growth of 3% to 5%.
Those weren’t stretch targets. They reflected a company executing on steady growth in cardiology and device volumes, the kind of guidance that usually gets a passing mention on an earnings call rather than a dedicated warning. The September 8 statement changed that calculus by putting both the quarterly and annual numbers in doubt at once, without saying which end of the range, or how far below it, the actual results might land.
Boston Scientific’s 2026 Guidance at a Glance
| Metric | Full-Year 2026 Guidance | Q3 2026 Guidance | Status as of Oct. 8, 2026 |
|---|---|---|---|
| Adjusted EPS | $3.28–$3.32 | $0.80–$0.82 | Unlikely to be met, per Sept. 8 statement |
| Net sales growth | 5.5%–6.5% | 3%–5% | Unlikely to be met, per Sept. 8 statement |
| Quarter covered | Jan 1 – Dec 31, 2026 | Jul 1 – Sep 30, 2026 | Fiscal quarter closed Sept. 30 |
| Revised outlook | To be issued with Q3 results | Due Oct. 28, 2026, 8:00 a.m. ET | |
The table makes the shape of the problem obvious. Every figure Boston Scientific published before the attack is now effectively frozen in place, a snapshot of where the business expected to land before a cyber incident rerouted its manufacturing and order pipelines. Nothing in that snapshot has been formally revised yet. That revision is the entire reason October 28 matters more than a typical earnings date.
Inside the Disruption: Manufacturing, Orders and Global Operations
Boston Scientific described the incident’s reach in three buckets: manufacturing, order fulfillment, and global operations. That phrasing suggests the disruption wasn’t confined to a single back-office system. Manufacturing delays at a device maker ripple into hospital inventories fast, because cardiac implants, stents and related hardware are typically stocked lean rather than warehoused in bulk. A pause in shipping or order processing doesn’t just dent a quarterly revenue line, it can leave hospitals scrambling for devices tied to scheduled procedures.
That operational angle is also why this incident reads differently from a typical customer-data breach. Boston Scientific hasn’t described this as primarily a data-theft event. It’s described as an operational one, closer in character to the cyberattacks that have hit hospital IT systems directly, such as the month-long disruption that knocked Luminis Health’s MyChart patient portal offline earlier this year. In both cases, the financial and reputational cost comes less from stolen records and more from the business simply not being able to operate at normal speed.
What’s Confirmed and What Isn’t
Some figures attached to this story in online chatter and aggregator headlines go well beyond what Boston Scientific has confirmed. A widely repeated estimate puts the third-quarter sales hit at roughly $300 million. Separately, some analyst models have penciled in third-quarter revenue near $5.12 billion with normalized EPS around $0.76. Neither figure comes from Boston Scientific itself. The $300 million number has not been validated against any company filing, and the analyst projections are, by definition, estimates rather than confirmed results.
The “outlook reset” framing attached to this story is similarly informal. It’s a useful shorthand for what investors expect to happen on October 28, but it isn’t a term Boston Scientific has used in its own disclosures. Readers should treat it as a description of the moment, not a quote from the company.
Confirmed vs. Unconfirmed Claims in the Boston Scientific Story
| Claim | Status | Basis |
|---|---|---|
| Q3 2026 results and call on Oct. 28, 8 a.m. ET | Confirmed | Boston Scientific investor-relations listing |
| Company says it’s unlikely to meet Q3/FY26 guidance | Confirmed | Company statement, Sept. 8, 2026 |
| Cyber incident hit manufacturing, orders, global ops | Confirmed | Company statement |
| Original FY26 guidance ($3.28–$3.32 EPS, 5.5–6.5% sales) | Confirmed (pre-warning figures) | Earlier company guidance |
| ~$300 million Q3 sales impact | Unconfirmed | Circulating estimate, not company-verified |
| ~$5.12B revenue / ~$0.76 normalized EPS forecast | Unconfirmed | Analyst estimate, not a company figure |
| “Outlook reset” as an official designation | Unconfirmed | Not company terminology |
Laying the claims out this way isn’t just caution for its own sake. Earnings-season coverage of breached companies tends to blur the line between what a company has said and what the market has assumed, and that blur is exactly what moves share prices on rumor rather than substance.
Market Impact: How Investors Have Repriced the Risk
Boston Scientific isn’t the only company this year where a breach disclosure turned into a stock story in its own right. When ASOS acknowledged a hacker’s breach claim, its shares slid roughly 10% within days, showing how quickly equity markets price in operational uncertainty even before a company quantifies the damage. Boston Scientific’s situation differs in one important way: it isn’t disputing that an incident occurred or that it’s affecting the business. The open question is purely about magnitude, and magnitude is exactly what’s missing until October 28.
That gap creates an unusual setup heading into earnings. Analysts covering medical devices now have to model a quarter where the company itself has told them not to trust its own prior guidance, without giving them a replacement number to anchor to. Options markets and short-term trading desks tend to treat that kind of vacuum as a volatility event on its own, separate from whatever the eventual results actually say.
Competitive Comparison: Stryker, Medtronic and a Pattern in Medtech
Boston Scientific’s August disruption didn’t happen in isolation. As shattered.io covered when the incident first surfaced, Boston Scientific became the third major device manufacturer in roughly six months to disclose a cyberattack serious enough to disrupt core operations, following Stryker in March 2026 and Medtronic in April 2026. Three large, independent medtech manufacturers hitting operational disruption inside half a year is a pattern, not a coincidence, and it has shifted how the sector gets discussed by security researchers and investors alike.
What makes medtech different from, say, retail or media breaches is the physical supply chain sitting behind the software. A breach at a streaming service costs subscriptions. A breach that halts stent or pacemaker shipments touches scheduled hospital procedures. That distinction is part of why cybersecurity researchers increasingly treat device manufacturers as a higher-consequence target class, even when the attackers’ financial motives look identical to any other ransomware or extortion operation.
Historical Context: Why Hospitals Make Soft Targets
Hospitals have operated on just-in-time device inventory for years, a practice driven by cost control and shelf-life limits on sterile stock. That efficiency becomes a liability the moment a supplier’s shipping and order systems go down. Unlike a retailer that can absorb a week of fulfillment delays, a hospital managing scheduled cardiac procedures has far less slack to work with.
Ransomware economics have followed that vulnerability. Attackers increasingly target sectors where downtime carries outsized leverage over the victim, which is part of why healthcare-adjacent targets keep showing up in annual ransomware tallies. The broader numbers back that shift: data-theft-driven extortion has been climbing even as straight ransom payments decline, a trend shattered.io detailed in its look at 2026’s 275% surge in ransomware data theft. Medical device makers sit squarely inside that higher-leverage category.
The Disclosure Gap: SEC Filings and Why Timing Matters
Public companies face SEC rules requiring timely disclosure of material cybersecurity incidents, typically through an 8-K filing. Boston Scientific’s path, disclosing the incident, then following up roughly five weeks later with a guidance warning, then promising full detail another seven weeks after that, illustrates how multi-stage disclosure has become the norm for breached companies rather than the exception.
That staggered pattern isn’t unique to Boston Scientific. Healthcare-adjacent breaches this year have repeatedly shown long gaps between initial detection and full public accounting, a dynamic Astrana Health’s own SEC filing timeline illustrated after its breach disclosure. Regulators and investors alike have started treating the length of that gap as a signal worth watching in its own right, independent of the breach’s eventual severity.
What to Watch For on the October 28 Earnings Call
Several specific items should resolve the uncertainty once Boston Scientific actually reports. The company is expected to disclose actual third-quarter net sales and adjusted EPS against its prior $0.80–$0.82 guidance, along with a revised full-year outlook replacing the $3.28–$3.32 range. Management will likely face direct questions about whether the disruption is fully resolved or still affecting fourth-quarter shipping and manufacturing capacity.
Investors will also be listening for any quantified cost estimate tied directly to the cyber incident itself, separate from normal quarter-to-quarter sales variance, since Boston Scientific has not yet broken that figure out on its own. Until the company does, every number attached to the incident’s cost remains an outside estimate rather than a disclosed fact.
Predictions: Where the Boston Scientific Story Goes Next
- Boston Scientific’s October 28 release will almost certainly include a formally revised full-year guidance range, replacing the $3.28–$3.32 EPS figure rather than simply reaffirming or withdrawing it outright.
- Expect sell-side analysts to adjust price targets within days of the call, once they can model against disclosed numbers instead of the September warning alone.
- Regulatory attention to disclosure timing in medtech cyber incidents is likely to grow, given the Boston Scientific, Stryker and Medtronic cluster inside a single year.
- Hospital systems and group purchasing organizations will likely push device manufacturers toward contractual language addressing supply continuity after a cyber incident, mirroring supply-chain protections already common in other industries.
- Medtech manufacturers broadly should expect continued targeting by ransomware and extortion actors in 2026 and into 2027, given how effectively downtime leverage has worked against three major players already this year.
None of these are guarantees. They’re reasonable expectations based on how similar situations have played out elsewhere in 2026, and they’ll be tested directly once Boston Scientific actually reports.
Frequently Asked Questions
When will Boston Scientific report Q3 2026 earnings?
October 28, 2026, with a conference call starting at 8:00 a.m. ET, covering the quarter that ended September 30, 2026.
Why did Boston Scientific warn about missing its guidance?
On September 8, 2026, the company said a cybersecurity incident disrupting manufacturing, order fulfillment and global operations made it unlikely to meet its previously issued third-quarter and full-year net-sales and adjusted-earnings guidance.
What was Boston Scientific’s original 2026 guidance?
Full-year adjusted EPS of $3.28 to $3.32 with net sales growth of 5.5% to 6.5%. The third-quarter-specific guidance was adjusted EPS of $0.80 to $0.82 with net sales growth of 3% to 5%.
Has Boston Scientific confirmed how much the cyberattack cost the company?
No. Figures circulating online, including an estimated $300 million third-quarter sales impact, have not been confirmed by the company. Boston Scientific has said a revised outlook will arrive with its October 28 results.
Is this Boston Scientific’s only cybersecurity incident in 2026?
The incident referenced here is the one Boston Scientific disclosed earlier in 2026, which shattered.io covered when it first disrupted the company’s cardiac device operations and manufacturing.
Is “outlook reset” an official Boston Scientific term?
No. It’s a description used by outlets covering the story to describe the expected guidance revision. Boston Scientific itself has referred to it as providing an updated operational and financial outlook alongside its Q3 results.
Does this affect other medical device makers?
Boston Scientific is the third major device manufacturer to disclose a disruptive cyberattack within about six months, following Stryker and Medtronic earlier in 2026, a pattern that has drawn broader attention to cybersecurity risk across the medtech supply chain.
Where can investors find official updates?
Boston Scientific publishes earnings schedules and investor materials directly on its investor-relations site, with corporate announcements also posted to its newsroom.
Related Coverage
- Double Counter Breach Exposes 1M Discord User Emails [2026]
- PoeLLM Hits 3,400 AI Servers, Hides C2 Inside a Poem [2026]
- BYOD Claims Trump Mobile Hack, Leaks 3,615 Records [2026]
- Aon Ransomware Claim Reopens Cleo CVE-2024-50623 [2026]
- Gentlemen Ransomware Affiliate Steals GitLab Secrets, Hits 24+ Orgs [2026]




