Boston Scientific Frozen by Hackers, Microsoft Wipes 171,000 Nonprofits, ATF Ransomed
Your business can be taken down in three completely different ways, and only one involves a hacker. This week, a cyberattack froze Boston Scientific, the company that ships pacemakers and defibrillators to hospitals worldwide. Microsoft ended a free program, and roughly 171,000 nonprofits lost everything in their cloud storage. And a ransomware gang breached a federal agency that kept running. *Control what a disaster can reach, before it reaches everything.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week’s stories for executives, owners, and operators who don’t have time to follow cyber news but can’t afford to be blindsided. Start with Boston Scientific. On August 25th, a cyberattack knocked out the systems this medical-device giant uses to process and ship orders worldwide, sending thousands of staff in Ireland home. The factories were never the problem. The systems that take and fulfill orders were, leaving hospitals waiting on pacemakers and stents. A group called ShinyHunters claims it stole more than 9 million records of personal data. Boston Scientific now faces two disasters: an outage it can fix and stolen data it cannot un-steal. Then there is Microsoft, where nobody got hacked. Microsoft ended a free software grant that about 400,000 nonprofits relied on. During the transition, roughly 171,000 of them lost everything in their OneDrive. One nonprofit leader had a paid renewal good through October 2026, and his data was deleted anyway. Here is what every owner needs to hear: Microsoft 365 does not back up your data. Microsoft keeps the service online, but protecting the actual files is entirely on you. Most people have that exactly backwards. We close with the ATF. The federal agency over firearms and explosives confirmed the Qilin ransomware gang hit a system holding information about the targets of its investigations, and the Department of Justice called it a “major incident.” Yet the agency kept running because that sensitive system was deliberately walled off from everything else. One box got hit instead of the whole agency. Qilin is the most active ransomware brand of 2026, with victim counts up around 443 percent and North America accounting for more than half its targets. This is the playbook coming for businesses of every size. Three different villains. One lesson: you don’t control when trouble arrives, only how far it gets once it does. In this episode, we discuss: • How a cyberattack froze Boston Scientific and stalled hospital device shipments worldwide • Why 171,000 nonprofits lost their data when Microsoft ended a grant, no hacker required • How the ATF survived a Qilin ransomware breach because one system was walled off • Why your cloud provider is not your backup, and what that means for your files • The one idea connecting all three: control what a disaster can reach before it reaches everything • Practical moves owners can make this week on backups, segmentation, and vendor notices Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #BostonScientific #Microsoft #Ransomware #DataBreach #Qilin #ShinyHunters #VendorRisk #BackupStrategy #BusinessRisk #MSP