Pelarys Intelligence · BSX · Boston Scientific Corporation
The cybersecurity item code arrived thirteen days after the cybersecurity disclosure
Boston Scientific disclosed a cybersecurity incident that had already caused a global disruption to its operations on August 26, 2026, filing it under Item 8.01 — Other Events, as the only item on the filing. Item 1.05 — Material Cybersecurity Incidents, the code written for this exact category, was not used until September 8, thirteen days later, in the filing that also disclosed the company no longer expected to meet the 2026 guidance ranges it had given on July 29.
What changed
The disclosed terms
- Incident identified
- August 25, 2026
- First disclosed
- August 26, 2026, under Item 8.01 — Other Events, the only item reported on that filing
- Exhibits filed with the August 26 disclosure
- None — the filing carries no exhibit documents, and reports no Item 9.01
- Item 1.05 first used
- September 8, 2026 — 8-K 0000885725-26-000059, with Item 1.05 as the only item reported
- Elapsed between the two filings
- 13 calendar days
- Stated on September 8
- The company “has determined that the incident is likely to have a material impact on the Company’s results of operations for the third quarter and full year 2026” (8-K 0000885725-26-000059)
- Guidance the September 8 filing addresses
- The net sales growth and adjusted EPS ranges for the third quarter and full year 2026 that the company provided on July 29, 2026 (8-K 0000885725-26-000051, Items 2.02 and 9.01)
The evidence
Read it in the filing
Boston Scientific Corporation · Form 8-K · filed August 26, 2026
Accession 0000885725-26-000056 · Item 8.01 — Other Events (the only item on the filing)
“identified a cybersecurity incident affecting certain of its information technology systems that has resulted in a global disruption to the Company’s operations”
“including the ability to process and ship customer orders”
“the Company has not yet determined whether the incident is reasonably likely to have a material impact on the Company”Read BSX's filings on SEC EDGAR
Every figure above is a disclosed term and every quotation is verbatim. Verified against the primary source on 2026-09-23.
Why it matters
What a screen missed, and what it costs
Item 1.05 — Material Cybersecurity Incidents exists so that this one category of event is findable by item code. On August 26 it was not used, and monitoring keyed to that code recorded nothing, even though the filing in front of it said in plain language that a global disruption was already affecting the company’s ability to process and ship customer orders. A screen that reads the narrative text of every 8-K would have caught the August 26 filing; a screen that reads item codes would not, and would first see this incident on September 8. What makes the gap worth recording here is that it is measurable. In the catch-all cases Pelarys has documented before, no correct code existed for the event. Here the correct code existed, the company used it, and the interval between the disclosure and the code is thirteen days of public record.
The same incident was disclosed twice under two different codes, and only the second disclosure carried a financial consequence. The August 26 filing stated the impact had not yet been determined. The September 8 filing stated the company believed it was unlikely to meet the net sales growth and adjusted EPS ranges for the third quarter and full year 2026 that it had provided on July 29. Anyone whose record of this company is assembled from item codes holds a file in which the incident begins on September 8 and arrives already attached to a guidance shortfall, with nothing recorded for the thirteen days in between.
What Pelarys remembered
The pattern behind it
This is the third entry Pelarys has recorded in the same gap, and the first that can be counted in days. NVIDIA disclosed an approximately $11.9 billion acquisition agreement under Item 8.01, the catch-all, as the only item on the filing. Qualcomm disclosed an acquisition under Item 3.02, a code that is precise and correctly chosen but describes how the deal was paid for rather than that a deal happened. In both, no code in the taxonomy named the event. Here one does: Item 1.05 was written for material cybersecurity incidents, and Boston Scientific used it — thirteen days after the incident was already public in its own filing. The pattern is no longer only that a filing taxonomy is not an event taxonomy. It is that the taxonomy can lag the event it was written to classify.
What Pelarys is watching next
Still open
- Whether the third-quarter results filing quantifies the revenue impact that the September 8 filing left unquantified
- Whether a further 8-K updates the Item 1.05 disclosure before the third-quarter results are reported
- Whether the incident appears as a new or modified risk factor in the next 10-Q
- Whether the company restates its third-quarter and full-year 2026 ranges or withdraws them
This is one finding. Pelarys keeps watching.
Add BSX to Pelarys and it keeps reading the filings — new disclosures, changed financials, the item codes nobody screens for — and tells you what changed since you last looked.