A cyberattack targeting Stryker, a medical technology company, caused widespread device failures affecting tens of thousands of units. The incident did not involve any malicious software.
Mar 17, 2026 // 21:14 - Niko Dunn


The recent cyberattack on Stryker, a large medical device company, affected only its internal Microsoft systems and remotely erased data from tens of thousands of employee devices.

The company announced on Sunday that its medical devices are still safe to use, but online ordering is still down, requiring customers to order through sales representatives.

Stryker clarified that the event was not a ransomware attack, and no malicious software was installed on their systems.

Last week, Stryker experienced a cyberattack claimed by the Handala group, which is suspected of having connections to Iran.

The attacker claimed to have wiped data from “over 200,000 systems, servers, and mobile devices” and stolen 50 terabytes of data, but investigators found no evidence of data theft.

Following the intrusion, Stryker employees across different countries reported that their company-managed devices had their data erased remotely overnight.

Some employees who had personal devices connected to the company network also lost personal information during the data wiping.

A source familiar with the incident informed BleepingComputer that the attacker used the Intune wipe command, a Microsoft cloud-based endpoint management tool, to delete data from approximately 80,000 devices between 5:00 and 8:00 a.m. UTC on March 11.

The attacker performed this action after gaining access to an administrator account and creating a new Global Administrator account.

The investigation is being carried out by the Microsoft Detection and Response Team (DART) in partnership with cybersecurity specialists from Palo Alto Unit 42.

Stryker emphasized that the attack did not affect any of its products, whether connected or not, and was limited to its internal Microsoft corporate environment.

“All Stryker products globally, including connected, digital, and life-saving technologies, remain safe for use,” the company stated.

Recovery efforts are underway, with a primary focus on restoring shipping and order processing services. Customers are asked to maintain usual communication with company personnel during the infrastructure recovery.

Orders made before the cyberattack will be fulfilled as systems are restored, while orders made during the disruption will be processed once systems are back online, and the supply chain returns to normal.

The company is cooperating with its global manufacturing sites to mitigate any potential operational effects.

Stryker’s immediate priority is to restore the supply chain and resume customer orders and shipping. “Our main order processing systems are well on the way to full recovery,” the company stated.

#affecting  #any  #caused  #company  #cyberattack  #device  #did  #failures  #incident  #involve  #malicious  #medical  #news  #not  #software  #stryker  #targeting  #technology  #tens  #the  #thousands  #units.  #widespread   —   News