Pelarys Intelligence · BSX · Boston Scientific Corporation

The cybersecurity item code arrived thirteen days after the cybersecurity disclosure

Boston Scientific disclosed a cybersecurity incident that had already caused a global disruption to its operations on August 26, 2026, filing it under Item 8.01 — Other Events, as the only item on the filing. Item 1.05 — Material Cybersecurity Incidents, the code written for this exact category, was not used until September 8, thirteen days later, in the filing that also disclosed the company no longer expected to meet the 2026 guidance ranges it had given on July 29.

What changed

The disclosed terms

Incident identified
August 25, 2026
First disclosed
August 26, 2026, under Item 8.01 — Other Events, the only item reported on that filing
Exhibits filed with the August 26 disclosure
None — the filing carries no exhibit documents, and reports no Item 9.01
Item 1.05 first used
September 8, 2026 — 8-K 0000885725-26-000059, with Item 1.05 as the only item reported
Elapsed between the two filings
13 calendar days
Stated on September 8
The company “has determined that the incident is likely to have a material impact on the Company’s results of operations for the third quarter and full year 2026” (8-K 0000885725-26-000059)
Guidance the September 8 filing addresses
The net sales growth and adjusted EPS ranges for the third quarter and full year 2026 that the company provided on July 29, 2026 (8-K 0000885725-26-000051, Items 2.02 and 9.01)

The evidence

Read it in the filing

Boston Scientific Corporation · Form 8-K · filed August 26, 2026

Accession 0000885725-26-000056 · Item 8.01 — Other Events (the only item on the filing)

identified a cybersecurity incident affecting certain of its information technology systems that has resulted in a global disruption to the Company’s operations
including the ability to process and ship customer orders
the Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company
Read BSX's filings on SEC EDGAR

Every figure above is a disclosed term and every quotation is verbatim. Verified against the primary source on 2026-09-23.

Why it matters

What a screen missed, and what it costs

Item 1.05 — Material Cybersecurity Incidents exists so that this one category of event is findable by item code. On August 26 it was not used, and monitoring keyed to that code recorded nothing, even though the filing in front of it said in plain language that a global disruption was already affecting the company’s ability to process and ship customer orders. A screen that reads the narrative text of every 8-K would have caught the August 26 filing; a screen that reads item codes would not, and would first see this incident on September 8. What makes the gap worth recording here is that it is measurable. In the catch-all cases Pelarys has documented before, no correct code existed for the event. Here the correct code existed, the company used it, and the interval between the disclosure and the code is thirteen days of public record.

The same incident was disclosed twice under two different codes, and only the second disclosure carried a financial consequence. The August 26 filing stated the impact had not yet been determined. The September 8 filing stated the company believed it was unlikely to meet the net sales growth and adjusted EPS ranges for the third quarter and full year 2026 that it had provided on July 29. Anyone whose record of this company is assembled from item codes holds a file in which the incident begins on September 8 and arrives already attached to a guidance shortfall, with nothing recorded for the thirteen days in between.

What Pelarys remembered

The pattern behind it

This is the third entry Pelarys has recorded in the same gap, and the first that can be counted in days. NVIDIA disclosed an approximately $11.9 billion acquisition agreement under Item 8.01, the catch-all, as the only item on the filing. Qualcomm disclosed an acquisition under Item 3.02, a code that is precise and correctly chosen but describes how the deal was paid for rather than that a deal happened. In both, no code in the taxonomy named the event. Here one does: Item 1.05 was written for material cybersecurity incidents, and Boston Scientific used it — thirteen days after the incident was already public in its own filing. The pattern is no longer only that a filing taxonomy is not an event taxonomy. It is that the taxonomy can lag the event it was written to classify.

What Pelarys is watching next

Still open

  • Whether the third-quarter results filing quantifies the revenue impact that the September 8 filing left unquantified
  • Whether a further 8-K updates the Item 1.05 disclosure before the third-quarter results are reported
  • Whether the incident appears as a new or modified risk factor in the next 10-Q
  • Whether the company restates its third-quarter and full-year 2026 ranges or withdraws them

This is one finding. Pelarys keeps watching.

Add BSX to Pelarys and it keeps reading the filings — new disclosures, changed financials, the item codes nobody screens for — and tells you what changed since you last looked.

Not investment advice. Pelarys is an investment research and analytics platform. This page reports what Boston Scientific Corporation disclosed to the SEC and what Pelarys will continue to watch. It contains no recommendation, no rating, no price target, and no view on whether any security is suitable for you. See our Investment Research Disclaimer.