U.S. medical device manufacturer Stryker reported a severe, global disruption to its Microsoft/Windows environment following a cyberattack that left employees unable to access corporate systems. Staff reported corporate laptops and phones being wiped, widespread outages of work applications and email, and some login pages displaying the Handala logo; the company also routed calls to an automated message citing a “building emergency.” Stryker said it is experiencing a “global network disruption,” believes the incident is contained, and stated it has no indication of ransomware while working to restore operations using business continuity measures.
A pro-Iran hacktivist group calling itself Handala publicly claimed responsibility, framing the attack as retaliation tied to the U.S.-Iran conflict and citing a reported U.S. strike on a girls’ school in Tehran. The group alleged it wiped large numbers of systems and exfiltrated significant data, and reporting indicated at least partial corroboration of system wiping and defacement across Stryker’s global environment. The incident appears to have caused broad operational impact across Stryker’s international footprint, with claims and employee reports indicating both destructive activity (device/server wiping) and potential data theft, though Stryker’s public statement did not confirm exfiltration.

See attribution, scope, and your downstream exposure.
19 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-29, Judge Hala Jarbou dismissed without prejudice the consolidated class action lawsuit brought by eight current and former Stryker employees over the March cyberattack. The dismissal followed Stryker's argument that the plaintiffs lacked standing because its forensic investigation found no evidence their personally identifiable information was compromised, aside from two business email addresses appearing in compromised files.
On 2026-04-16, Stryker disclosed to the SEC that the March 11 cyberattack would materially affect its first-quarter results due to the scope and duration of the disruption and related customer and regulatory consequences. The company said manufacturing, ordering, and distribution operations had been restored and that it did not expect the incident to materially affect its full-year 2026 guidance.
On 2026-04-02, Stryker said it had returned to full operations roughly three weeks after the March 11 attack. The company said commercial, ordering, and distribution systems had been restored and production was moving back toward peak capacity while the investigation continued.
On 2026-03-24, Stryker said the attackers not only abused Microsoft Intune’s wipe function but also used a malicious file to conceal their activity, contradicting its earlier statements that no malware was involved. The company also said Palo Alto Networks Unit 42 confirmed the threat actors had been removed and that production and other customer-supporting systems were being restored as manufacturing sites stabilized.
By March 19, U.S. officials said the FBI and Justice Department had reportedly taken down two websites linked to Handala. At the same time, CISA highlighted the Stryker incident in guidance focused on strengthening endpoint-management defenses, including Microsoft Intune protections.
By March 18, multiple proposed class action lawsuits had been filed against Stryker by current and former employees over the breach and alleged security failures. Reporting also said electronic ordering systems were still disrupted, increasing concern about delayed shipments and product shortages.
By March 17, U.S. officials said both CISA and the FBI were engaged with Stryker staff in response to the attack. Federal officials continued monitoring the incident as a significant Iran-linked cyber event affecting a major U.S. medtech supplier.
On March 17, Stryker said it was restoring computers and internal network systems following the March 11 attack. The company reiterated that the incident was contained to its internal Microsoft environment and that internet-connected medical products remained safe to use.
Subsequent disclosures and reporting by March 13 indicated the attack was affecting order processing, manufacturing, and shipping operations, raising concerns about prolonged supply-chain disruption for hospitals and healthcare providers. Analysts warned that loss of records and traceability data could delay shipments for weeks or longer.
By March 12, Stryker told customers that it had no indication the incident involved malware or ransomware and that the impact was contained to its internal Microsoft environment. The company said products and platforms such as Mako, Vocera, LIFEPAK35, and other customer-connected medical systems remained safe to use.
CISA announced on March 12 that it had launched an investigation into the Stryker incident and was working with public- and private-sector partners to gather information and provide technical assistance. The move marked the first explicit federal investigative response disclosed in the reporting.
On March 12, reporting and expert analysis increasingly converged on the view that attackers likely obtained privileged access, possibly through Active Directory or admin accounts, and abused Microsoft Intune's native remote wipe capabilities. This suggested a living-off-the-land destructive technique rather than custom malware deployment.
By March 11-12, multiple security researchers and outlets assessed Handala as a front or proxy for Iranian state-linked actors, including MOIS-linked Void Manticore and in some reporting overlap with APT34. This sharpened attribution from a nominal hacktivist claim to a likely state-aligned retaliatory operation.
As the outage unfolded on March 11, employees in Ireland, the U.S., and other countries were sent home or forced onto manual processes because they could not access corporate systems. Hospitals and healthcare providers reported downstream issues, including disconnecting from some Stryker services and difficulty ordering surgical supplies.
In a March 11 SEC filing, Stryker disclosed that the incident disrupted operations and limited access to some systems and business applications. The company said the timeline for full restoration was not yet known and that it was still assessing the impact.
Stryker confirmed on March 11 that it was experiencing a global network disruption caused by a cyberattack affecting its Microsoft environment. The company said it had no indication of ransomware or malware, believed the incident was contained, and activated business continuity measures while working to restore operations.
On March 11, the Handala group claimed via X, Telegram, and related channels that it had attacked Stryker in retaliation for recent events involving Iran. The group alleged it exfiltrated about 50 TB of data and wiped more than 200,000 systems, servers, and mobile devices across 79 countries, though those figures were not independently verified.
Shortly after midnight U.S. East Coast time on March 11, Stryker suffered a cyberattack that disrupted its internal Microsoft environment worldwide. Employees in multiple countries reported being locked out of systems as Windows devices and some mobile phones were remotely reset or wiped and login pages were defaced with Handala branding.
Security firms and later reporting described Handala as active since at least 2023, linking the persona to Iranian state-aligned operations such as Void Manticore/Banished Kitten and to destructive, hack-and-leak, and influence campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
50 references tracked. Mallory keeps watching after this page renders.
emsisoft.com
Open sourcehipaajournal.com
Open sourcegovinfosecurity.com
Open sourceitpro.com
Open sourceirishmirror.ie
Open sourcetimesofisrael.com
Open source7ai.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.