Monday, August 3, 2026

Chips & Hardware

Stryker restores systems after pro-Iran hacking group breach

Stryker is restoring systems after a cyberattack reportedly allowed pro-Iran hackers to remotely wipe tens of thousands of employee devices, disrupting global operations.

Stryker restores systems after pro-Iran hacking group breach
Photo: Stryker press kit

Medical technology company Stryker is in the process of restoring its computers and internal network following a March 11 cyberattack. The incident reportedly allowed pro-Iranian hackers to remotely wipe tens of thousands of employee devices. Stryker asserted that the cyberattack was contained to its internal Microsoft environment and that its internet-connected medical products are “safe to use.” While the cause of the breach is still under investigation, the company stated it has seen no indication of ransomware or malware. However, the company’s ability to process orders, manufacture, and ship devices continues to be disrupted.

A pro-Iran hacking group called Handala claimed responsibility for the destructive breach, defacing the company’s login pages with its own logo. The group stated the hack was in response to a U.S. air strike on an Iranian school that killed at least 175 people, mostly children. The incident is thought to be the first major cyberattack in the United States in response to the Trump administration’s war in Iran.

The exact method of entry remains under investigation, but security researchers have pointed to potential vectors. According to Palo Alto Networks, the hackers may have relied on phishing—a technique used to compromise networks via deceptive communications—to gain initial access. Bleeping Computer reported that the hackers may have broken in using an internal Stryker administrator account, which would have granted them near-unlimited access to the company’s Windows network. The hackers allegedly targeted Microsoft Intune dashboards, which are used for the remote management of employee devices. Microsoft Intune is a cloud-based endpoint management service that allows administrators to delete data in case an employee’s device is lost or stolen. A successful compromise of these dashboards would have allowed the hackers to remotely wipe employee phones and laptops, including personal devices, without using malware. The Wall Street Journal also reported that the hackers targeted Intune. A spokesperson for Stryker did not respond to questions about the breach, including whether the allegedly compromised account was protected with multi-factor authentication.

The operational fallout is significant given Stryker’s footprint. According to Reuters, the company has 56,000 staff and operates in more than 60 countries. The ongoing disruption continues to impact Stryker’s ability to process orders, manufacture, and ship medical devices. IBM noted that the Handala group is known for using phishing techniques and destructive attacks, including targeting the healthcare and energy sectors.

Why it matters

The cyberattack has caused widespread disruption to Stryker’s operations, including its ability to process orders, manufacture, and ship medical devices, highlighting the vulnerability of global corporate infrastructure to geopolitical conflict.