Threats · 180 days ago
Handala claimed a March 11 attack that disrupted Stryker's global Microsoft environment and impacted customer orders and logistics. Analysis of infostealer logs indicates Stryker administrator credentials were likely harvested and may have been used to abuse Microsoft Intune to wipe managed devices. Stryker says products remain safe and is restoring systems with external experts and authorities.
6 sources covering this story
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Attack?A large-scale cyberattack against medical technology company Stryker resulted in widespread system outages.
The Record from Recorded Future
FBI, CISA warn on Microsoft Intune risks after Iran-linked cyberattack on Stryker
The attackers behind a recent attack on Stryker did not use malware, instead breaking into a legitimate Microsoft device management system called Intune and wiping the company’s data that way.
FBI seizes pro-Iranian hacking group's websites after destructive Stryker hack | TechCrunch
The FBI and the Justice Department took down two websites linked to the pro-Iranian hacktivist group Handala, which last week hacked medical tech giant Stryker.
cybersecurity agency urged companies to prevent access to systems used for remotely managing their fleets of employee devices after hackers broke into a major U.S.
FBI seizes Handala data leak site after Stryker cyberattack
The FBI has seized two websites used by the Handala hacktivist group after the threat actors conducted a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices.
Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach
The medtech giant has been working on restoring systems affected by the cyberattack conducted by the Handala hackers.
Stryker begins restoring ordering, shipping systems after cyberattack
The medtech company believes the cyberattack has been contained and is now bringing systems back online.
The hack, which brought ongoing widespread disruption to the company's operations, is thought to be the first major cyberattack in the United States in response to the Trump administration's war in Iran.
The Record from Recorded Future
Stryker says hospital tools are safe, but digital ordering systems still down after cyberattack
Electronic ordering systems belonging to the medical device company Stryker are still down a week after a cyberattack believed to have wiped thousands of company devices of all information.
Stryker attack wiped tens of thousands of devices, no malware needed
Last week's cyberattack on medical technology giant Stryker was limited to its internal Microsoft environment and remotely wiped tens of thousands of employee devices.
Part of the PlainSec briefing for 2026-03-22