Stryker Global Network Cyberattack (Handala Attack)

Healthcare Sector Wiper Attack Hacktivism
Overview
U.S.-based medical technology company Stryker experienced a major cyberattack that disrupted global internal IT infrastructure. The incident impacted corporate systems, manufacturing workflows, and order processing operations.
The pro-Iran hacktivist group Handala claimed responsibility, framing the operation as retaliation for geopolitical events involving U.S. and Israeli actions in Iran. Stryker reported a widespread outage in its Microsoft enterprise environment while indicating that patient-facing systems and medical devices were not affected.

Technical Specifications
| Field | Details |
|---|---|
| Incident Type | Destructive cyberattack (suspected wiper operation) |
| Primary Target | Stryker global corporate IT environment |
| Attack Surface | Microsoft-based enterprise systems and endpoint/device management infrastructure |
| Observed Effects | Account/device lockouts, endpoint disruption, business process outage |
| Claimed Threat Actor | Handala (pro-Iran hacktivist group) |
| Data Theft Claim | Up to 50 TB claimed by attackers (unverified) |
Affected Products
- Global Microsoft-based internal enterprise systems.
- Corporate endpoints including laptops and mobile devices.
- Device-management-controlled assets (reported Intune-related abuse).
- Manufacturing and order processing systems.
Technical Details
- Attack activity targeted Stryker's global Microsoft IT environment.
- Employees were reportedly locked out of corporate systems and managed devices.
- Affected login pages allegedly displayed Handala branding.
- Public reporting indicates possible abuse of device management tooling (for example, remote wipe actions through endpoint management channels).
- Attackers claimed to have wiped more than 200,000 servers, laptops, and mobile devices and exfiltrated approximately 50 TB of data; these figures are not independently verified.
- The campaign characteristics align with a destructive operation focused on disruption and data destruction rather than ransomware monetization.
Attack Scenario
- Threat actors gained access to Stryker's corporate network.
- Attackers moved toward enterprise device-management infrastructure.
- A destructive workflow (wiper payload and/or remote wipe commands) was triggered across managed endpoints.
- Large numbers of systems became wiped, disabled, or inaccessible.
- Employees lost access to laptops, phones, and internal enterprise services.
- Manufacturing, shipping, and order operations were disrupted across multiple regions.
Impact Assessment
A global outage across internal systems disrupted corporate operations, manufacturing, and order processing.
Attackers claimed exfiltration of up to 50 TB of data, but this remains unverified; Stryker reported that hospital-used medical devices were not affected.
Shipping delays and internal workflow interruptions were reported across operations in 61 countries, alongside short-term financial pressure and recovery costs.
Mitigation Strategies
- Harden endpoint and mobile device management security controls (MDM/Intune).
- Apply Zero Trust principles to enterprise identity, device, and network access.
- Enforce MFA for all administrative and privileged accounts.
- Monitor and tightly restrict privileged actions within device-management platforms.
- Maintain tested offline backups and disaster recovery procedures for destructive attack recovery.
- Deploy EDR/XDR telemetry and alerting tuned for destructive behavior patterns.
- Segment corporate networks to reduce blast radius and prevent large-scale wipe propagation.
Resources
Open-Source Reporting
- Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping - SecurityWeek
- Pro-Palestinian hacktivist group Handala targets Stryker in global disruption
- Stryker attack highlights nebulous nature of Iranian cyber activity amid joint U.S.-Israel conflict | CyberScoop
- Stryker flags disruption to orders, manufacturing a day after cyberattack | Reuters
- Iran-linked group says it hacked US company in retaliation for Minab school bombing | The Guardian
- Stryker hit by global cyberattack linked to pro-Iran group
- Medical equipment company Stryker reports cyberattack | AP News
- Iran-Linked Hacking group Handala Claims Cyberattack On US Medical Giant Stryker
- Iran-Linked Hackers Claim Cyberattack on U.S. Company
- Stryker cyber attack: message reportedly left by Handala after destructive endpoint impact | Times of India
Last Updated: March 15, 2026