Stryker Corporation confirmed a significant cyber incident affecting its global Microsoft environment, with the Iran-linked threat actor Handala claiming responsibility. Reporting indicates the operation was politically motivated and destructive rather than financially driven, with no clear signs of ransomware or conventional malware. The attackers are believed to have abused Microsoft Intune or related endpoint management capabilities to issue remote wipe actions across corporate devices, disrupting operations and reportedly impacting thousands of servers, laptops, and smartphones; Handala also claimed to have exfiltrated as much as 50 TB of corporate data.
In response, CISA warned that malicious actors are targeting endpoint management systems at U.S. organizations and tied its alert to the March 11 attack on Stryker. The agency said it is coordinating with the FBI and urged organizations to harden endpoint management platforms, especially Microsoft Intune, by applying least-privilege access, enforcing phishing-resistant MFA, using Microsoft Entra ID protections, and requiring Multi Admin Approval for sensitive actions such as device wipes, scripts, RBAC changes, and configuration changes. The incident underscores how legitimate administrative tooling can be turned into a destructive attack path when privileged access is compromised.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-02, Stryker said it was fully operational again following the March 11 destructive cyberattack. The company said manufacturing, commercial, ordering, and distribution systems had been sufficiently restored, production was moving toward peak capacity, and product supply remained healthy.
By 2026-03-25, Stryker disclosed that it had contained the cyber incident and was restoring operations, though recovery remained slow. The company said manufacturing disruption was still affecting its Cork, Ireland facilities and that the full financial impact had not yet been determined.
By 2026-03-20, follow-on reporting said the FBI and CISA were pushing U.S. organizations to strengthen Microsoft Intune security after the Stryker compromise, including second-admin approval for sensitive actions such as device wiping. The reporting also stated the attack reportedly wiped more than 200,000 devices.
On 2026-03-18, CISA published an alert after identifying malicious activity targeting endpoint management systems at U.S. organizations, citing the Stryker incident. The agency said it was coordinating with federal partners including the FBI and urged organizations to apply Microsoft Intune hardening measures and related zero-trust, RBAC, MFA, and privileged access protections.
On 2026-03-16, Stryker said the cyberattack was limited to its internal Microsoft corporate environment and did not affect its medical products, including connected and life-saving technologies. The company said the incident was not ransomware, found no evidence of data exfiltration, and confirmed major disruption from remote wiping of employee devices and electronic ordering systems.
On 2026-03-11, Stryker Corporation was hit by a cyberattack affecting its global Microsoft environment. Reporting tied the incident to Iran-linked actor Handala and described destructive activity including large-scale device wiping.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
huntress.com
Open sourcebleepingcomputer.com
Open sourcehealth-isac.org
Open sourcethecyberthrone.in
Open sourcescworld.com
Open sourcekaseya.com
Open sourcecisa.gov
Open sourceeur02.safelinks.protection.outlook.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.