Cyber Attacks

Stryker hit by massive Wiper cyberattack

0

Medical technology giant Stryker Corporation confirmed on March 11, 2026, that it suffered a major cyberattack that disrupted its global Microsoft environment. The Iran-linked threat group Handala claimed responsibility, describing the incident as a politically motivated, destructive operation.

Unlike typical cyberattacks driven by financial gain, this incident shows clear signs of a wiper campaign. Stryker stated there is “no indication of ransomware or malware,” suggesting the attackers aimed to destroy data rather than extort the company.

Handala claimed it wiped thousands of servers and endpoint devices, including Windows laptops and smartphones, and also alleged the theft of 50 terabytes of corporate data.

Cybersecurity researchers, including Arctic Wolf, believe the attackers may have exploited Microsoft Intune to remotely trigger mass device resets across Stryker’s global network.

Employees reported seeing devices wiped in real time, with some login screens defaced with the group’s branding. Offices in multiple countries were evacuated, and staff were instructed to disconnect from company systems and avoid using corporate devices.

Handala, widely described as a pro-Iran hacktivist group, has been assessed by Palo Alto Networks Unit 42 as being linked to Iran’s Ministry of Intelligence and Security, indicating possible state-backed involvement.

The group framed the attack as retaliation for a reported U.S. military strike in Minab, Iran, calling it “the start of a new era in cyber warfare.”

Operational Impact

The attack significantly disrupted Stryker’s order processing, manufacturing, and global shipping operations. The company filed an 8-K report with the SEC and has not provided a timeline for full recovery. Its stock fell more than 3% following public disclosure.

Despite the disruption, Stryker confirmed that all medical products—including LIFEPAK defibrillators, Mako surgical systems, and platforms like Vocera and care.ai—remain safe and unaffected. These systems run on separate, isolated infrastructures, including cloud platforms such as Amazon Web Services and Google Cloud Platform.

Stryker has activated its incident response plan, working with external cybersecurity experts and U.S. authorities. Restoration efforts are currently focused on customer-facing systems, with recovery progress underway.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Crunchyroll breach exposes 100GB user data

Previous article

Dutch Finance Ministry hit by cyberattack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *