Threats · 186 days ago
Pro‑Iranian group Handala claims it wiped devices and exfiltrated data from medical device maker Stryker. Stryker reports widespread disruption to its Microsoft environment, ongoing recovery, and no indication of ransomware or malware. Immediately audit and lock down Microsoft Entra/Intune admin accounts, enforce MFA on privileged and break‑glass accounts, review recent Intune commands, isolate suspected endpoints, and verify immutable offline backups.
13 sources covering this story
Stryker’s manufacturing, shipping disrupted after cyberattack
The medtech company says it's still experiencing issues with order processing, manufacturing and shipping.
Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping
Evidence indicates that the attackers leveraged existing endpoint management software rather than malware to wipe devices.
The who, what, and why of the attack that has shut down Stryker's Windows network
Company says it doesn't know how long it will take to restore its Microsoft environment.
Stryker attack highlights nebulous nature of Iranian cyber activity amid joint U.S.-Israel conflict
The Iranian-linked hacking group Handala has claimed credit for a major cyberattack on medical device giant Stryker, signaling a potential escalation in Tehran’s digital operations during the current U.S.-Israel conflict.
Why Stryker's Outage Is a Disaster Recovery Wake-Up Call
The Iranian cyberattack on Stryker is the kind of stress test that business continuity and disaster recovery programs often do not plan for.
Medical giant Stryker crippled after Iranian hackers remotely wipe computers
A nation-state group claims to have wiped 200,000 devices in 79 countries after a possible Microsoft Intune compromise.
The Record from Recorded Future
Stryker tells SEC that timeline for recovery from cyberattack unknown
In an 8-K filing with the SEC, Stryker confirmed that the cyberattack caused a global disruption to the company’s Microsoft environment and said external cybersecurity experts were brought in to “assess and to contain the threat.”
War spreads into cyberspace after Iran-linked hackers hit medtech giant Stryker - Help Net Security
An Iran-linked hacking group has claimed responsibility for a cyberattack on U.S. medical device giant Stryker.
Iran Claims Massive Cyber-Attack on MedTech Firm Stryker
The pro-Iran Handala group claims to have wiped 200,000 systems in destructive cyber-attack on US firm Stryker
The Record from Recorded Future
Medical device giant Stryker confirms cyberattack as employees say devices were wiped
The medical device manufacturer Stryker confirmed reports Wednesday that a cyberattack has disrupted operations after a hacker group claimed to have targeted the company in retaliation for U.S.
Pro-Iran hacktivist group says it is behind attack on medical tech giant Stryker | TechCrunch
The hacktivist group claimed the attack was in retaliation for a U.S. strike on a Tehran school that killed more than 175 people, most of them children.
Stryker investigating cyberattack that caused widespread outage
The full scope of the impact on the medical equipment firm, including operational and financial effects, remains unclear.
Part of the PlainSec briefing for 2026-03-15