A hacker group with ties to Iranian intelligence is claiming responsibility for a wiper-style attack on Stryker, a global medical technology company based in Michigan. Reports from Ireland, Stryker’s largest center outside the United States, indicated that the company had sent more than 5,000 employees home. A voicemail message at Stryker’s U.S. headquarters said the company was currently dealing with a building emergency.
See also: Iranian Cyber Front: Increased activity by hacktivists

In a statement posted on Telegram, the Iranian hacker group known as Handala (also known as the Handala Hack Team) claimed that Stryker offices in 79 countries were forced to close after the group deleted data from more than 200,000 systems, servers, and mobile devices.
The team said that the wiper-type attack was retaliation for a missile attack on February 28 that hit an Iranian school and killed at least 175 people, most of whom were children. The New York Times reported that an ongoing military investigation has determined that the United States is responsible for the missile attack.
Palo Alto Networks, a cybersecurity firm, has linked Handala to Iran's Ministry of Intelligence and Security (MOIS). Palo Alto says Handala emerged in late 2023 and is believed to be one of several online personalities maintained by Void Manticore, an actor linked to MOIS.
See also: Infy team restarts its operations with new C2 servers

Stryker’s website says the company has 56,000 employees in 61 countries. A report by the Irish Examiner noted that Stryker staff are now communicating via WhatsApp for updates on when they can return to work. An anonymous employee reported that everything connected to the network is down and that “anyone who has Microsoft Outlook on their personal phones has had their devices wiped.”
The Examiner reported that the systems at the Cork headquarters have “closed” and that the Stryker devices owned by the employees have been deleted, with the login pages on those devices having been altered with the Handala logo.
Wiper attacks typically involve malware designed to overwrite existing data on infected devices. However, a reliable source with knowledge of the attack said the perpetrators appear to have used a Microsoft service called Microsoft Intune to issue a “remote wipe” command to all connected devices.
Intune is a cloud‑based solution for IT teams to enforce security policies and data compliance, providing a unified, web‑based management console for monitoring and controlling devices regardless of location. This connection is supported by Reddit discussions about the shutdown of Stryker, where users claiming to be Stryker employees reported that they were asked to urgently uninstall Intune.
See also: MuddyWater uses malicious Word documents to distribute RustyWater

The Palo Alto noted that Handala's hack-and-leak activity primarily targets Israel, with occasional attacks outside this scope when serving a specific agenda. The security firm stated that Handala has also taken responsibility for recent attacks on fuel systems in Jordan and on an Israeli energy exploration company.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
