Severity Daily

IT and AI security incidents, checked against the primary source

Tag: 8-K

  • Two 10.0s drew a Friday federal deadline, and in half of today’s stories the vendor contradicts its own record

    Two 10.0s drew a Friday federal deadline, and in half of today’s stories the vendor contradicts its own record

    The most important thing today is a date: Friday, September 11, 2026. CISA added two flaws scoring 10.0 to the Known Exploited Vulnerabilities catalog on September 8 and put the same three-day due date on both. Adobe Commerce is exploited in the wild by Adobe’s own statement, needs no authentication, and affects every supported branch of Commerce, B2B, and Magento Open Source. N-able N-central is pre-authentication remote code execution in the platform managed service providers point at their clients’ networks.

    The biggest-sounding story of the day is neither of them. Veradigm told the SEC that an attacker took credentials from a third-party vendor, used them against a Veradigm API, and downloaded patient data including Social Security numbers. For the people in that file it is the worst thing on the page. For anyone deciding what to do before Friday it is inert: the filing names no vendor, no date, and no count. The two KEV entries come with a deadline inside the week and something to install. That is why they lead.

    The thread

    Six of today’s twelve stories — exactly half — are a vendor’s own record disagreeing with itself. N-able’s status page says there are no confirmations of exploitation while its blog says the opposite, on the CVE CISA has now listed as exploited. Microsoft marks both of today’s Windows zero-days exploited, then ships a temporal vector on one of them reading E:U, exploit code unproven. SAP scores a flaw its record describes as a crash at 10.0 and one describing a rogue application server at 9.8, and the entire gap is one scope metric. Siemens splits one broken session token in the Reyrolle 7SR5 into three CVEs, and its own v3.1 and v4.0 vectors disagree on how hard one of them is to attack. Ivanti published three ITSM records with byte-identical descriptions and the same weakness class, two scored 8.8 and the third 9.9. Adobe stamps its ColdFusion bulletin Priority 1 and says in the same document that it is aware of no exploits.

    The score, the severity label, and the exploitation status are produced by different processes inside the same organization, and today six of them shipped out of step. The consequence is the same every time: the number you sort your queue on is not the number that tells you what to do.

    The rest, in the order it deserves attention

    Behind Friday, the same Microsoft release carries two Windows local privilege escalations at 7.8 with a September 22 federal deadline. The ColdFusion bulletin covers nine CVEs across both shipping releases. Ivanti Neurons for ITSM shipped eight CVEs, two of them unauthenticated deserialization at 9.8. Snowflake’s drivers attached a cloud workload-identity token to the login request before checking the host was Snowflake, across eight driver lines. Siemens Siveillance Control fixes a root-level file upload in which each of four editions has a different build number meaning “fixed.” On the filings side, Boston Scientific escalated to Item 1.05 and named the 2026 guidance it will miss, and United Natural Foods booked its June 2025 attack as a $21 million credit, because $45 million of insurance arrived a fiscal year after the costs it covers.

    Still open

    Adobe’s remediation for the Commerce 10.0 is a composer patch, and the bulletin’s solution column still carries no version number: agencies have until Friday to apply something they cannot cite by version. N-able has not reconciled its two live statements, and NVD’s affected list includes Hotfix 3, the build N-able told on-premises customers on September 5 to install immediately. Fourteen days after the attack, Boston Scientific still has not said whether anything was taken. Veradigm has not named the vendor whose credentials were stolen, or how many people are in the file.

    Sourcing note: this page adds no facts to the stories it links; each carries its own primary source. The September 11 and September 22 deadlines were re-confirmed tonight against NVD, which republishes CISA’s cisaExploitAdd and cisaActionDue verbatim. NVD was inconsistent while that was done: within one hour the same API returned a stale copy of CVE-2026-75650 with no CISA fields and then the current record at lastModified 2026-09-08T19:29:17.803 carrying them, and returned totalResults of 0 for both Windows CVE IDs on two query forms before returning the full records on a third. All four deadlines are confirmed. The lesson for anyone checking these dates themselves is that a single empty NVD response is not evidence of anything — query again before concluding a record is missing. cisa.gov blocks automated fetching directly.

    Correction, September 8, 2026: an earlier version of this sourcing note, live for roughly three minutes after publication, said NVD “returned no record at all for either Windows CVE at the time of writing.” That described two failed queries, not the state of the catalog. Both records were retrieved in full on a retry and carry a cisaActionDue of 2026-09-22. The note above has been rewritten.

  • Veradigm discloses a breach that reached patient Social Security numbers through API credentials stolen from a third-party vendor

    Veradigm discloses a breach that reached patient Social Security numbers through API credentials stolen from a third-party vendor

    Veradigm told the SEC on September 8, 2026 that an unauthorized party took credentials from a third-party vendor’s environment, used them against a Veradigm application programming interface, and downloaded patient personal data including Social Security numbers.

    What happened

    Veradigm Inc. — the healthcare information technology company formerly called Allscripts, listed as MDRX — filed a Form 8-K on Tuesday, September 8, 2026 under Item 8.01, Other Events. The filing is short, and its substantive text is worth reading in full rather than in summary. It says:

    “Veradigm Inc. (the ‘Company’) recently learned that one of its third-party vendors experienced a cybersecurity incident that impacted certain data associated with a small number of the Company’s customers. Based on the Company’s investigation to date, an unauthorized party obtained credentials from the vendor’s environment to a Company application programming interface used by the vendor to provide services on behalf of the Company’s customers. The unauthorized party used these credentials to download copies of certain personal data of patients, including, in some instances, Social Security numbers; no clinical or medical data was involved. The vendor’s compromised credentials provided access only through that limited interface and did not provide access to any other part of the Company’s environment, including the Company’s broader network, servers, databases, or other systems. The incident did not result in any operational disruptions.”

    The filing adds that Veradigm “promptly initiated its cybersecurity incident response protocols upon learning of the incident and has notified law enforcement,” that the investigation is ongoing, and that “affected customers and individuals are being notified, with credit monitoring services being offered where applicable.” On impact it states that the company “has not yet determined the extent of any potential liabilities associated with this matter” but does not believe the incident is “reasonably likely to have a material impact on the Company’s business, operations, financial condition, or results of operations.”

    That is the entire public record from the company. The filing does not name the vendor. It does not say when the incident occurred, when the vendor learned of it, or when Veradigm learned of it — “recently learned” is the only timing given. It does not say how many individuals are affected, or which of Veradigm’s product lines the interface belongs to. It does not mention ransomware, extortion, or any threat actor.

    Separately, and unconfirmed, a ransomware leak site operated under the name TheGentlemen listed Veradigm as a victim on September 5, 2026, three days before the filing. The listing is an attacker claim. As reported by the threat-intelligence aggregator that carries it, it comes with no stated data volume, no sample files, and no deadline, and the aggregator itself notes that such listings “cannot always be independently verified and may not reflect confirmed breaches.” Veradigm has not connected the two, and nothing in the 8-K describes an extortion event. The listing and the filing may concern the same incident or may not; on what is public, that is not established either way.

    Why it matters

    Start with the Item number, because it is a choice and it was made deliberately. Item 1.05 of Form 8-K is the mandatory cybersecurity disclosure, triggered within four business days of a company determining that an incident is material. Item 8.01 is the voluntary catch-all. Veradigm filed under 8.01 and wrote its materiality conclusion into the body: not reasonably likely to have a material impact. That is the form working the way the SEC has repeatedly said it should — 1.05 reserved for material incidents, 8.01 available for everything a company decides to disclose anyway.

    It is the second time in two days this publication has had cause to note the distinction. Boston Scientific moved the other direction on September 7, escalating from an Item 8.01 filing to Item 1.05 and withdrawing its guidance for the year. Read together, the two filings show the mechanism doing its job in both directions inside one week: an incident that grew into materiality was reclassified upward, and an incident judged immaterial was disclosed voluntarily rather than dressed as mandatory. The useful reading habit is the opposite of the intuitive one. An 8.01 cyber filing is not a smaller story than a 1.05; it is a company telling you about something it has concluded it did not have to tell you about, which is often where the operational detail is.

    Then the mechanism, which is the part worth carrying into your own environment. Nobody broke into Veradigm. An attacker got into a vendor’s environment, found credentials that vendor held to a Veradigm API, and used them exactly as the vendor was entitled to use them. From the API’s point of view, every request was authenticated and authorized. The only thing that bounded the damage was the scope of the interface itself — and Veradigm’s filing makes that boundary its central reassurance: access “only through that limited interface,” not to “the Company’s broader network, servers, databases, or other systems.”

    That is a real control and it evidently held. It is also a claim only Veradigm can see the evidence for, and it is doing a lot of work in a filing that otherwise gives no numbers. What the limited interface was still permitted to hand out, according to the same paragraph, was copies of patient personal data including Social Security numbers. A scoped integration is a smaller blast radius, not a small one. The question every integration owner should take from this is not whether a vendor’s credentials are scoped, but what the scoped thing is allowed to return in bulk, and whether anyone would notice it returning a lot of it at once.

    The unit of counting deserves attention too. The filing says “a small number of the Company’s customers.” Veradigm’s customers are physician practices, health systems, and payers. A small number of those can sit on top of a large number of patients, and the filing gives no individual count at all. Anyone repeating “small” about this incident should be clear that the adjective attaches to organizations, not people.

    The SSN detail is what determines where the real numbers will surface. No clinical or medical data was involved, so the HIPAA breach reporting most healthcare stories run through is not the primary channel here; Social Security numbers put this squarely inside state breach-notification statutes. Those require notice to state attorneys general with resident counts attached. Expect the individual totals to appear on state AG portals over the coming weeks, and expect them to be the first hard figure anyone gets. The 8-K is the announcement; the AG filings will be the measurement.

    Finally, the unnamed vendor is a gap with a cost. Third-party vendors serve more than one client. Every other healthcare organization whose integrator holds API credentials on their behalf has the same question tonight and no way to answer it, because the company that knows which vendor it was has not said. That is a defensible choice while an investigation is open. It also means the population at risk from this vendor’s compromise is, for now, larger than the population anyone can identify.

    What to do

    If you are a Veradigm customer, ask two specific questions rather than a general one: which interface was involved, and whether your organization’s data moved through it. Veradigm says affected customers are being notified; absence of a notice is not the same as confirmation you were unaffected, and it is reasonable to ask for that confirmation in writing.

    More broadly, treat this as an inventory prompt for credentials that exist outside your perimeter. Enumerate every API key, service account, and integration token issued to a third party. For each, record what data the interface can return, at what volume, and whether bulk retrieval through it would generate an alert or pass unnoticed. Rotate credentials held by vendors on a schedule you set rather than one they set, and make sure you can revoke a single vendor’s access without taking down the integration for everyone else.

    Where a scoped interface can return Social Security numbers, apply rate limiting and volume alerting to it specifically. The failure mode in this incident was not privilege escalation; it was legitimate access used at scale by the wrong party. Detection has to sit on the volume, because the authentication looked correct.

    Watch the state attorney general breach portals for Veradigm entries, which will carry the resident counts the filing omits.

    Sourcing note

    The quotations here are transcribed from Veradigm’s Form 8-K as filed, read directly at sec.gov: accession 0001193125-26-385249, CIK 0001124804, period of report September 8, 2026, Item 8.01, signature block dated September 8, 2026. The document was located through EDGAR full-text search; the browse-edgar interface is disallowed to automated clients, so the filing index was used to resolve the CIK.

    The ransomware leak-site listing is reported as an attacker claim and nothing more. It was not read on the leak site itself — one aggregator carrying it returned 403 to this container — and the listing date of September 5, 2026 and the absence of stated volume, samples, or deadline come from a second threat-intelligence aggregator’s page. No connection between that listing and the filing has been asserted by Veradigm or established publicly.

    Maine’s attorney general breach portal was checked and returned entries no more recent than June 11, 2026 to this container, so no state-level filing for this incident could be confirmed. Unresolved: the vendor’s identity, the number of individuals affected, the date of the incident, the date Veradigm learned of it, and whether the September 5 listing concerns this event.

  • United Natural Foods books its cyberattack as a $21 million credit — insurance recoveries beat costs, and the two-year total is $5 million

    United Natural Foods books its cyberattack as a $21 million credit — insurance recoveries beat costs, and the two-year total is $5 million

    The June 2025 attack that halted a $31 billion food distributor now shows up in its annual results as a negative adjustment, because $45 million of insurance arrived in a later fiscal year than the costs it covers.

    What happened

    United Natural Foods, Inc. filed a Form 8-K under Items 2.02, 8.01, and 9.01 on Tuesday, September 8, 2026, accession number 0001020859-26-000022, accepted by EDGAR at 7:02:12 a.m. ET. The Item 8.01 is a $200 million share repurchase authorization and has nothing to do with security. The security content is in the Item 2.02 exhibit: the fourth-quarter and full-year earnings release for the fiscal year ended August 1, 2026.

    UNFI is the largest publicly traded grocery wholesaler in North America and reported full-year net sales of $31,152 million. It disclosed a cybersecurity incident in June 2025, in the fourth quarter of its fiscal 2025, that disrupted ordering and distribution across its network. Today’s release carries the first full fiscal year of that incident’s accounting tail, and the shape of it is worth reading closely.

    In the reconciliation from net income to Adjusted EBITDA, the line is labeled “Cybersecurity incident.” For fiscal 2025 it carried $26 million, all of it in the fourth quarter. For fiscal 2026 it carries $(3) million in the fourth quarter and $(21) million for the full year, shown in parentheses. The sign is not a typo. Footnote 5 explains it, and the wording is the story:

    “Fiscal 2026 includes $45 million of insurance recoveries, which are included within Operating expenses in the Consolidated Statements of Operations, partially offset by $24 million of costs and charges related to the June 2025 cybersecurity incident, of which $20 million is included within Gross profit and $4 million is included within Operating expenses in the Consolidated Statements of Operations. Fiscal 2025 includes costs and charges related to the cybersecurity incident, of which $15 million is included within Gross profit and $11 million is included within Operating expenses in the Consolidated Statements of Operations.”

    So: $26 million added back in fiscal 2025, $21 million subtracted out in fiscal 2026. Across the two fiscal years the “Cybersecurity incident” line nets to roughly $5 million. Full-year Adjusted EBITDA was $701 million in fiscal 2026 against $552 million in fiscal 2025, and GAAP net income was $84 million.

    On sales, the release says only this: “Sales in the fourth quarter of fiscal 2025 were impacted by the previously disclosed cybersecurity incident experienced in the fourth quarter of fiscal 2025,” and elsewhere refers to “lapping last year’s cybersecurity event.” No dollar figure is attached to that impact anywhere in the document. Fourth-quarter fiscal 2026 net sales were $7,642 million, down 0.7 percent against the quarter the incident depressed. The release states no cumulative cost of the incident, and the fiscal 2027 outlook does not mention it.

    Why it matters

    Severity Daily reported yesterday on Ardent Health’s ransomware carve-out, where a 2023 incident’s financial consequence surfaced thirty-four months later inside a non-GAAP definition. UNFI is the same mechanism running faster, and it exposes the part that a single-year read gets wrong: the sign.

    Anyone who pulls UNFI’s fiscal 2026 results and looks for the cyber line finds a negative number. Read alone, that number says the incident helped. Anyone who pulled fiscal 2025 found $26 million of pure cost. Neither year is the answer, and neither year is wrong — they are two halves of one event separated by an accounting boundary, because insurance claims settle on a slower clock than the costs they reimburse. A screen, a model, or a peer comparison that samples one fiscal year of a multi-year incident will get a number whose sign depends entirely on which year it sampled. That is not a UNFI problem. It is the structural shape of every cyber incident large enough to trigger a material insurance claim.

    The second thing to hold onto is what the line is and is not. It is incremental costs and charges, net of insurance recoveries. It is not the cost of the incident. Three categories sit outside it and are visible nowhere in this document. Lost sales, which the company says occurred and does not quantify. Security spending that became ordinary course after the incident and therefore stopped being an adjustment. And customer and contract effects that show up, if at all, in the top line rather than in an add-back. The fourth-quarter number makes the point: net sales fell 0.7 percent against a quarter the company itself describes as depressed by the attack. That is a comparison flattered by a weak base and still down, and no line in the reconciliation captures whatever explains it.

    Third, the disclosure is complete on its own terms and thin on the one number a reader most wants. UNFI names the incident, names its month, splits the costs between gross profit and operating expenses, and states the insurance figure. That is more granularity than most registrants give. It still does not say what the incident cost in total, and because the two fiscal years point in opposite directions, the cumulative figure is the only one that means anything — and the reader has to build it themselves from two documents filed a year apart. There is no rule requiring a cumulative disclosure, which is precisely why the absence is worth naming.

    Finally, the insurance number deserves its own attention: $45 million recovered against $24 million of same-year costs and $26 million the year before. Recoveries of that size, arriving roughly a year after the event, are the strongest public evidence to date on what a large cyber policy actually pays and when. It is one data point, and the policy terms, retention, and sublimits are not public. But it is a real number attached to a named incident at a named company, which is rarer in this field than it should be, and it is a better input to a cyber-insurance conversation than any vendor survey.

    What to do

    If you model or benchmark cyber incident costs, take the cumulative, never the annual. For UNFI that is $26 million in fiscal 2025 less $21 million in fiscal 2026, or about $5 million net, and it is net of $45 million in insurance rather than gross of it. Any benchmark built from single-year add-backs is measuring the timing of insurance settlements, not the severity of incidents.

    If you are building a business case for cyber insurance, this is a usable data point. A distribution-halting incident at a $31 billion wholesaler produced $45 million in recoveries booked in the following fiscal year. Note the lag as carefully as the amount: the costs hit one year and the recoveries the next, so the cash-flow and covenant picture in the incident year is the gross number, not the net.

    If you sit in finance or FP&A at a company that has had an incident, decide now how you will present year two. The reversal in year two is arithmetically correct and reads badly if it arrives without explanation. A single sentence giving the cumulative figure costs nothing and removes the ambiguity that this filing leaves open.

    If you are a UNFI customer or supplier, the operational story is over and the disclosure story is not. There is nothing to patch and nothing to act on defensively here. The open item is what the incident actually cost, which remains unstated and is not derivable from any single filing.

    Sourcing note

    Checked. United Natural Foods’ Form 8-K, accession number 0001020859-26-000022, read from SEC EDGAR; the acceptance timestamp of 7:02:12 a.m. ET and the item designations come from the filing index and directory. All quoted language and every figure above come from the exhibit filed with it, the fourth-quarter and fiscal-year 2026 earnings release, including footnote 5 to the non-GAAP reconciliation, quoted in full. Fiscal 2026 is the 52 weeks ended August 1, 2026; fiscal 2025 is the 52 weeks ended August 2, 2025. The Item 8.01 in this filing concerns a $200 million share repurchase authorization and is unrelated to the incident.

    Could not reach. cisa.gov returns HTTP 403 to automated fetching. No agency advisory relates to this filing and none was sought beyond that.

    Unresolved. The total cost of the June 2025 incident, which the company has not stated and which cannot be derived from this release alone. The dollar value of sales lost in fiscal 2025, which the release says occurred and does not quantify. The terms, retention, and limits of the insurance that produced the $45 million recovery. Whether further recoveries are expected. And whether the 0.7 percent fourth-quarter sales decline against a cyber-depressed prior-year quarter reflects any residual effect of the incident — the release does not say, and this page does not assert that it does. The $5 million two-year net figure above is arithmetic performed by this publication on the company’s two reported annual figures, not a number the company has published.

  • Boston Scientific escalates to Item 1.05 and says it will miss its 2026 guidance — the filing still says nothing about data

    Boston Scientific escalates to Item 1.05 and says it will miss its 2026 guidance — the filing still says nothing about data

    Fourteen days after the August 25 attack, the company has made the materiality determination it expressly withheld in August and named the guidance it will miss — and still has not said whether anything was taken.

    What happened

    Boston Scientific Corporation filed a Form 8-K under Item 1.05, Material Cybersecurity Incidents, accession number 0000885725-26-000059. EDGAR accepted it at 6:15:57 a.m. ET on Tuesday, September 8, 2026, with a period of report of Monday, September 7 — Labor Day. The cover-page XBRL amendment flag reads false: a new 8-K, not an amendment.

    The earlier filing, accession number 0000885725-26-000056, was accepted at 6:06:57 a.m. ET on Wednesday, August 26, under Item 8.01, Other Events. It said the company “has not yet determined whether the incident is reasonably likely to have a material impact on the Company.” Severity Daily covered it on August 30 and wrote that the thing to watch was what came next. This is it.

    The determination, verbatim: “Based on the information currently available as of the date of this Current Report on Form 8-K, the Company has determined that the incident is likely to have a material impact on the Company’s results of operations for the third quarter and full year 2026.” The consequence: “As a result, the Company believes that it is unlikely to meet the net sales growth and adjusted EPS guidance ranges for the third quarter and full year 2026 that the Company previously provided on July 29, 2026.”

    Those ranges come from the second-quarter earnings release filed on July 29, accession number 0000885725-26-000051: full-year net sales growth of “approximately 5.5 to 6.5 percent on a reported basis and 5 to 6 percent on an organic basis,” full-year adjusted earnings per share of “$3.28 to $3.32,” and third-quarter adjusted EPS of “$0.80 to $0.82.” Today’s filing withdraws confidence in them and replaces none. New figures are promised for the third-quarter call on Wednesday, October 28, 2026.

    The incident “involved unauthorized activity on certain of the Company’s systems that resulted in a network outage affecting access to certain operating systems and business applications, which impacted the Company’s ability to manufacture as well as process and ship customer orders.” On containment: “the Company has not identified evidence of ongoing unauthorized access to its systems.” On recovery: major distribution centers are “now processing and shipping customer orders at or above normal operating levels” and “manufacturing has resumed across most facilities globally.” On the long horizon: “the Company does not expect the incident will have a material impact on its long-term financial condition.”

    The word “data” appears once in the document, and not in the Item 1.05 narrative. It sits in the cautionary-statement section, in a list introduced by “Factors that may cause such differences include, among other things:”, and reads: “The unauthorized release of any confidential data or information of the Company, including third party data held by the Company, and the use of any such data for any fraudulent or criminal purposes;”. That is a hypothetical risk factor in the conditional, not a finding. Nowhere does the filing say whether data was accessed, copied, viewed, or removed. It names no threat actor, no access vector, no ransom demand, no dollar figure, and does not mention notifying law enforcement or any regulator.

    The company’s most recent newsroom update, dated Saturday, September 5, 2026, at 8:04 p.m. ET, says “product quality analyses indicate no impairment to product function beyond the previously communicated disruption to new LATITUDE remote monitoring activations.” It carries no financial-impact statement and no data statement.

    Why it matters

    Start with the part this publication is obliged to say plainly, having spent three weeks saying the opposite about other registrants. Boston Scientific ran the sequence in the order the rule contemplates: Item 8.01 while the materiality determination was open, saying in the filing that it was open, then Item 1.05 when it made the call, with a checkable consequence. Compare the recent run: Nutex Health moved the same disclosure from 8.01 to 1.05 while still saying there was no material impact, and Park Dental Partners filed 1.05 on day two and disclaimed material impact in the same sentence. Those used the item heading to signal a seriousness the body then withdrew. Here heading and body agree, and the body carries a number the market can price.

    The calendar rewards close reading, because two clocks run here and get conflated. Fourteen days separate identification on August 25 from this filing, and that is not the Item 1.05 deadline. The four-business-day clock runs from the materiality determination, not discovery, and the determination itself is governed by a standard, not a deadline: without unreasonable delay. As filed, the period of report puts the determination on September 7, a federal holiday, with disclosure before the opening bell on the next trading day — roughly one business day against four available. That date is the registrant’s own designation, not verifiable from outside. Taken as filed, it is a company using the short end of its clock.

    Now the part none of that resolves. The materiality determination attaches to results of operations; it says nothing about information. Read the two disclosed conclusions together — a material hit to the quarter, no material hit to long-term financial condition — and the filing is complete on the axis a securities regulator cares about and silent on the axis that matters to a patient, a hospital privacy officer, or a state attorney general. Those regimes share neither a clock nor a trigger: HIPAA breach notification and the state breach statutes run from discovery of a breach of protected information, and a securities materiality determination neither starts nor satisfies them. After fourteen days and two filings, the company has not said there was such a breach and has not said there was not. Silence is not a denial, and it is the most consequential open item here.

    The recovery language deserves the same care. “At or above normal operating levels” is a throughput statement, and above-normal throughput is what clearing a two-week backlog looks like — evidence of the disruption, not evidence against it. A hospital reading it as “back to normal” will schedule against a supply position that has not caught up. And “most facilities globally” is not all of them.

    On the cost that has not been named: there is no dollar figure anywhere in the filing, and the guidance-miss framing is a statement about ranges the company expects not to hit, not an accounting of what the incident cost. Severity Daily reported yesterday on Ardent Health’s 2023 ransomware incident, whose financial consequence surfaced thirty-four months later in a non-GAAP footnote after an SEC review. That is the normal shape: disclosure arrives quickly and the arithmetic slowly, in accounting definitions rather than incident reports. October 28 is an outlook, not a total.

    What to do

    If you are a customer, put the data question in writing. It has been open fourteen days across two SEC filings and every update. Ask the account team whether customer, patient, or employee information held by Boston Scientific was accessed or removed, and ask for a dated answer. Do not read the absence of a statement as an assurance.

    Materials management: reconcile, do not relax. Read “at or above normal operating levels” as backlog clearing. Pull every order submitted through EDI or the Global Health Exchange since August 25 and confirm which shipped, not which were taken. Check consignment against scheduled cases.

    Cardiology and electrophysiology: the monitoring gap is still open. The September 5 update confirms the LATITUDE activation disruption is unresolved. Patients implanted on or after August 25 whose communicators could not be activated never enrolled, so they do not show on a monitoring dashboard as a gap. Work from the implant log, not the monitoring console, and schedule in-office interrogation for anyone in that window who should not wait.

    Finance: there are no replacement ranges until October 28, 2026. The July 29 guidance is withdrawn in substance but not in figures, so any model still carrying $3.28 to $3.32 for full-year adjusted EPS holds a number the company says it does not expect to meet.

    Sourcing note

    Checked. Boston Scientific’s Form 8-K, accession number 0000885725-26-000059, read from SEC EDGAR. The acceptance timestamp and period of report come from the filing index; the amendment flag and document type from the cover-page XBRL. All quoted filing language is verbatim. Also checked: the August 26 Item 8.01 filing, accession number 0000885725-26-000056, accepted at 6:06:57 a.m. ET; the July 29 earnings 8-K, accession number 0000885725-26-000051, for the guidance ranges; and the newsroom update dated September 5, 2026 at 8:04 p.m. ET. Item designations were confirmed through SEC full-text search, which returns the items field directly.

    Could not reach. cisa.gov returns HTTP 403 to automated fetching, so no CISA or health-sector advisory could be checked; none surfaced through search. No FDA safety communication was found, and no attacker claim on any leak site. Neither the company nor any agency has named a group, so this page names none.

    Unresolved. Whether any data was accessed, copied, or removed — unaddressed in both filings and in every company update to date. Its single appearance in today’s filing is in a conditional risk-factor list, which this page does not treat as a statement about the incident. Also unresolved: the access vector; the cost in dollars; which manufacturing facilities remain offline; whether the determination was in fact made on September 7 as the period of report designates; whether law enforcement or any regulator was notified; and the revised guidance, deferred to October 28, 2026.