Stryker Cyber Attack: Limerick Plant Affected by Iran-Linked Hackers

by Marcus Liu - Business Editor
0 comments

Stryker Hit by Pro-Iran Hackers, Disrupting Operations Globally

Medical device manufacturer Stryker is working to restore its systems after a cyberattack carried out by a pro-Iran hacking group called Handala, resulting in widespread disruption to the company’s operations. The attack, which began on March 11, 2026, involved the wiping of data from tens of thousands of employee devices.

Attack Details and Impact

Handala claimed responsibility for the destructive breach, stating it was in retaliation for a U.S. Airstrike on an Iranian school that killed at least 175 people, mostly children. The hackers defaced Stryker’s login pages with their logo. According to initial reports, the attack targeted Stryker’s internal Microsoft environment, but internet-connected medical products remain safe to use [TechCrunch].

Stryker’s ability to process orders, manufacture, and ship devices continues to be disrupted. The company has not indicated a timeline for full restoration of its systems [TechCrunch]. The attack is believed to be the first major cyberattack in the United States in response to escalating tensions with Iran.

How the Hackers Gained Access

The hackers reportedly gained access through an internal Stryker administrator account, granting them near-unlimited access to the company’s Windows network. They exploited vulnerabilities in Stryker’s Microsoft Intune dashboards, which are used for remote management of employee devices, allowing them to remotely wipe devices – including personal devices – without using malware [TechCrunch].

Handala: A Rising Threat

Handala, a politically motivated hacking group, has been increasingly active in recent weeks, claiming responsibility for a string of cyberattacks on Israeli companies [The Guardian]. Cybersecurity experts believe the group may be a front for Iran’s Ministry of Intelligence (MOIS) [Wired]. They are described as seeking to inflict “noisy, often politically motivated chaos” on adversaries [Wired].

Stryker’s Response and Future Outlook

Stryker CEO Kevin Lobo stated that the attack did not involve ransomware or malware, and that employees, sites, products, and customers are safe [TechCrunch]. The company is working with government partners and third-party experts to maintain business continuity. Lee Sult, chief investigator at cybersecurity firm Binalyze, called the attack “the first drop of blood in the water” as the Iran conflict spreads to US cyber targets, predicting further attacks [The Guardian].

Key Takeaways

  • A pro-Iran hacking group, Handala, successfully breached Stryker’s systems, wiping data from thousands of devices.
  • The attack is believed to be in retaliation for a U.S. Airstrike in Iran.
  • Stryker’s operations are significantly disrupted, with no clear timeline for full restoration.
  • Handala is emerging as a prominent player in Iranian cyber warfare efforts.
  • The incident highlights the growing risk of cyberattacks as geopolitical tensions escalate.

Related Posts

Leave a Comment