Iran-Linked Hackers Target Stryker in First Major US Cyberattack Since War

0 comments

Stryker Hit by Iran-Linked Cyberattack, Disrupting Medical Device Operations

A significant cyberattack, attributed to an Iranian-linked hacking group, has crippled operations at Stryker, a leading U.S.-based medical device and services provider. The attack, which began on Wednesday, March 11, 2026, has caused widespread disruption, impacting thousands of workers and potentially affecting healthcare services globally.

Attack Details and Attribution

The hacking group, identified as Handala, claimed responsibility for the attack in social media posts, stating it was retaliation for the destruction of a school in Minab, Iran, and in response to ongoing cyber assaults against the “Axis of Resistance.” Reuters and The Independent reported on the claims. Handala also characterized Stryker as a “Zionist-rooted corporation” and a key component of a global lobby.

The group alleges to have wiped over 200,000 systems, servers, and mobile devices and extracted 50 terabytes of critical data. The Handala logo reportedly appeared on Stryker company login pages following the breach. The Independent reported this detail.

Impact on Stryker and Healthcare

Stryker, which reported $25 billion in global sales in 2025, SecurityWeek reports, has experienced a global network disruption, particularly affecting its Microsoft environment. Employees in 79 countries have been unable to access systems, and work-issued phones and laptops have been rendered unusable. SecurityWeek also noted the company employs approximately 56,000 people.

Stryker initially stated it had no indication of ransomware or malware and believed the incident was contained, but the extent of the disruption suggests a more significant impact. Reuters covered this initial statement.

Technical Details of the Attack

According to Rafe Pilling, director of threat intelligence at cybersecurity company Sophos, the hackers likely gained access to Stryker’s Microsoft Intune account. Cybersecurity News reported on this analysis. From there, they appear to have remotely wiped devices back to factory settings using the platform’s remote wipe feature, designed for lost or stolen devices. Microsoft’s website describes this feature as a tool for secure device erasure.

Historical Context and Iran’s Cyber Activity

This attack marks a potential shift in Iran’s cyber activity, moving beyond minor website alterations and espionage to a destructive wiper attack targeting a major U.S. Company. Historically, Iran has been linked to significant wiper attacks, including those targeting Saudi Aramco in 2012 and the Sands Casino in 2014. Reuters highlighted this historical pattern.

The Minab school attack, cited by Handala as a motivating factor, resulted in the deaths of at least 175 people, primarily children, following a U.S. And Israeli attack in Tehran. A U.S. Military investigation attributed the destruction to President Donald Trump, though he disputes responsibility.

Stryker’s Response

Stryker has advised workers not to turn on company devices and to disconnect from all networks. The company has not yet provided detailed information about the full extent of the damage or the recovery process.

Related Posts

Leave a Comment