Cyber Incident Victim: Stryker
Date:
Mar 2026
Location:
United States of America
Summary
Stryker, a medical technology company, was targeted by an Iran‑linked hacktivist group that claimed responsibility for wiping tens of thousands of its internal Microsoft‑managed devices and disrupting order processing, manufacturing and shipping. The attackers used compromised administrator credentials to access the Intune endpoint management platform and execute a mass wipe, asserting they had also exfiltrated large volumes of data, although investigators found no evidence of data theft. The incident caused operational delays that affected product deliveries and led to short‑term financial impacts, but the company reported that its systems were restored to pre‑attack levels within weeks and that its connected medical products remained unaffected. U.S. cybersecurity agencies issued advisories urging organizations to harden Intune configurations and enforce least‑privilege access controls in response to the attack.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 2 actors | Available to members | Available to members |
Description
On March 11 2026, the medical technology company Stryker experienced a cyberattack that targeted its internal Microsoft environment. The Iran‑linked hacking group Handala claimed responsibility, stating the operation was retaliation for a U.S. strike on a girls’ school in Minab, southern Iran. According to Handala’s claims, the attackers stole approximately 50 terabytes of data before using a newly created Global Administrator account to execute the built‑in wipe command in Microsoft Intune, erasing data from tens of thousands of employee devices. Stryker’s own statements confirmed that the attack disrupted order processing, manufacturing, and shipping operations across its global network, while emphasizing that no patient‑related services or connected medical products were affected. Employees reported that work‑issued phones and laptops were wiped, leaving many unable to perform their duties for several days. The company noted that the incident was contained to its Microsoft corporate environment and that no ransomware or malware was detected on its systems.

The disruption had measurable consequences for Stryker’s business. In the first quarter of 2026, the company reported sales of $6 billion, representing a 2.6 percent year‑over‑year increase, with its MedSurg and Neurotechnology segment growing 5 percent and its Orthopedics segment remaining roughly flat. CEO Kevin Lobo described the cyberattack as having a “big impact” on first‑quarter results, noting that the effects varied across business lines due to differing go‑to‑market models and revenue‑recognition processes, but he affirmed that no overall business was lost and that full‑year guidance of 8 to 9.5 percent organic sales growth and adjusted earnings per share of $14.90 to $15.10 was maintained. Stryker did not disclose a specific financial figure for the quarterly impact, and external analysts observed that any revenue lost during the quarter was expected to be recovered later in the year. Throughout the incident, Stryker reiterated that its products remained safe to use and that patient care was not compromised.
In response, Stryker activated its incident response plan and began restoring systems that directly support customers, ordering, and shipping. The company collaborated with external cybersecurity experts, the FBI, CISA, the White House National Cyber Director, and the Department of Health and Human Services. CISA issued an advisory urging organizations to harden Microsoft Intune configurations, enforce least‑privilege access, require phishing‑resistant multi‑factor authentication, and implement multi‑admin approval for sensitive actions. The FBI seized two websites associated with Handala, and Microsoft released guidance on strengthening Intune administrative controls. Stryker reported that most manufacturing sites and critical lines were restored roughly two weeks after the attack, and by the first week of April the company announced it had returned to pre‑attack operational levels, with production moving toward full capacity across its global manufacturing network. The investigation remained ongoing, with Stryker stating that no malicious activity directed at customers, suppliers, vendors, or partners had been identified.
