Minidoka Memorial Hospital in Rupert, Idaho, said a cyber incident on Easter morning temporarily affected internal systems, limited imaging services, and forced some emergency patient transfers, though the hospital and its clinics continued treating patients safely. Separately, medical technology company Stryker disclosed a March cyberattack that disrupted ordering, manufacturing, and shipping across parts of its business; Reuters and other public reporting said some patient-specific procedures were rescheduled because personalized inventory could not be delivered on time, even as Stryker said patient-related services and connected medical products were not directly affected.
Threat actors quickly tried to exploit both incidents for leverage. A newly emerged ransomware group, Blackwater, added Minidoka to its leak site and claimed it stole about 577 GB of data, but provided no proof and did not clarify whether systems were encrypted. In the Stryker case, public reporting tied the attack to the Iran-linked Handala persona, while U.S. authorities seized four domains allegedly used by Iran's Ministry of Intelligence and Security to host stolen data, issue threats, and support Handala operations; prosecutors said attackers abused Microsoft Intune's native wipe capability on more than 200,000 employee devices, highlighting how attacks on healthcare providers and suppliers can ripple into hospital operations and patient care.
See attribution, scope, and your downstream exposure.
15 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-04, Straumann disclosed a cybersecurity incident affecting a legacy system. This introduces a new victim and a separate incident not previously captured in the timeline.
On 2026-04-27, Medtronic disclosed a cyberattack involving unauthorized access to portions of its IT systems. The company said it had not identified impacts to products, patient safety, manufacturing and distribution operations, financial reporting systems, or its ability to meet patient needs, and that it was investigating whether personal information was accessed.
By 2026-04-19, Minidoka Memorial Hospital expected imaging access to be fully restored following the April 5 cyber incident. This marked a recovery milestone after temporary service limitations and patient transfers.
Also on 2026-04-17, Minidoka Memorial Hospital publicly updated patients about the Easter weekend cyber incident. The hospital said certain systems were temporarily affected, imaging services were limited, and full imaging access was expected to be restored by April 19.
On 2026-04-17, Blackwater added Minidoka Memorial Hospital to its leak site and claimed to have stolen roughly 577 GB of data, or more than 2.3 million files. The group threatened to leak the data after April 24 and demanded an undisclosed ransom, but provided no proof and did not clarify whether systems were encrypted.
On 2026-04-05, Minidoka Memorial Hospital in Rupert, Idaho, experienced a cyber incident that temporarily affected internal systems. The disruption limited imaging services and led to some emergency patient transfers, though the hospital and its clinics continued treating patients safely.
In March 2026, Blackwater appeared as a new ransomware or leak-site brand and began posting victims online. Reporting noted it had claimed at least three attacks, including one against Medical Park Hospitals Group that was denied.
On 2026-03-23, Stryker told the SEC it was working with Unit 42 and law enforcement to contain the incident and restore operations. The company said the malicious file used by the threat actor was not capable of spreading and that its investigation had found no malicious activity directed at customers, suppliers, vendors, or partners, nor evidence their systems were accessed through the incident.
By 2026-03-23, the FBI warned that Handala-linked actors were using Telegram in activity targeting dissidents and journalists. The warning highlighted the group's continued operational presence despite the prior domain seizure.
Reporting on the March 20 seizure said prosecutors alleged attackers abused Microsoft Intune's native wipe capability to destroy data on more than 200,000 employee devices and disrupt hospital operations in Maryland. This added significant technical and impact details to the known Stryker incident.
On 2026-03-20, the U.S. Department of Justice and FBI seized four domains allegedly used by the Iran-linked Handala Hack Team or MOIS-linked operators. Authorities said the infrastructure supported stolen-data hosting, extortion-style messaging, doxxing, and public claims tied to incidents including the Stryker attack.
On 2026-03-18, CISA issued guidance urging organizations to secure endpoint management systems in the wake of a major U.S. cyberattack. Reporting linked the warning to concerns raised by the Stryker incident and broader risks to identity and device-management platforms.
On 2026-03-12, CISA launched an investigation into the cyberattack disclosed by Stryker the previous day. The move marked a formal federal response to the incident before CISA later issued broader defensive guidance.
Around the time of Stryker's disclosure, public reporting tied the incident to Handala, an Iran-linked persona that framed the operation as retaliation for wartime events in Minab, Iran. The claim marked an attribution development beyond Stryker's initial disclosure.
On 2026-03-11, Stryker disclosed a cyberattack affecting parts of its global Microsoft environment. The incident disrupted ordering, manufacturing, and shipment operations, while the company said patient-related services and connected medical products were not affected.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
25 references tracked. Mallory keeps watching after this page renders.
upguard.com
Open sourcemarketscreener.com
Open sourcecomparitech.com
Open sourcedatabreaches.net
Open sourcecnn.com
Open sourcewwmt.com
Open sourcestryker.com
Open sourcealjazeera.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.