Handala claimed a March 11 attack that disrupted Stryker's global Microsoft environment and impacted customer orders and logistics. Analysis of infostealer logs indicates Stryker administrator credentials were likely harvested and may have been used to abuse Microsoft Intune to wipe managed devices. Stryker says products remain safe and is restoring systems with external experts and authorities.
Part of the PlainSec briefing for 2026-03-22