HomeSecurityStryker: Cyberattack deleted data from thousands of devices (no malware)

Stryker: The cyberattack erased data from thousands of devices (without malware)

A widespread cyberattack hit medical equipment giant Stryker last week , causing severe disruptions to the company's internal operations . According to the official update, the incident was limited to Microsoft's corporate environment and resulted in the mass remote deletion of data from tens of thousands of employee devices , without affecting the medical products themselves.

Stryker

Stryker: Medical systems safe, problems with orders

The company has been quick to reassure customers and partners that all of its medical devices remain completely safe and operational. However, critical business services, such as online ordering systems, have been down. As a result, customers are temporarily forced to place orders manually through sales representatives, which adds to the burden and delays.

See also: UK Companies House: Security breach exposed business data

It is not ransomware – No indication of malware installation

Unlike many modern attacks, Stryker has made it clear that this is not a ransomware incident. The attackers did not install malware on the company's systems, nor did they appear to be attempting extortion. This differentiates the attack, as the main impact came from data destruction and disruption of operations, rather than file theft or encryption.

Assuming responsibility by the Handala team

The attack was claimed by the Handala, which is said to have links to Iran. The attackers claimed to have wiped out more than 200,000 systems, servers and mobile devices, while claiming to have accessed approximately 50 terabytes of data.

Stryker: The cyberattack erased data from thousands of devices (without malware)

Despite these claims, no evidence has been found to confirm data extraction from the company's systems so far. Experts remain cautious, as such statements are often used for sensationalism or psychological pressure.

Mass deletion of device data via Microsoft Intune

The attack appears to have been carried out in a highly targeted manner, leveraging Microsoft's own management tools. According to reports, the attackers used the remote wipe command via the Microsoft Intune, deleting data from approximately 80,000 devices within a few hours.

See also: Intuitive: Customer and employee data breach

The action was carried out after the perpetrators gained access to an administrator and then created a new account with Global Administrator privileges. This gave them full control over the management environment, allowing them to execute bulk commands without hindrance.

Impacts on employees and personal devices

The attack had an immediate impact on Stryker employees, with many reporting that their corporate devices were affected overnight. In some cases, personal devices connected to the corporate network were also affected, leading to the loss of personal data.

This incident highlights the risks associated with BYOD (Bring Your Own Device) policies, especially when strict separations between corporate and personal data are not implemented.

Research by Microsoft and cybersecurity experts

The investigation into the attack is ongoing, with the participation of the Microsoft Detection and Response Team (DART) and experts from Palo Alto Networks Unit 42.The goal is to identify the initial entry point of the attackers and prevent similar incidents in the future.

Stryker confirms that the attack was limited exclusively to Microsoft's internal cloud environment and did not impact its products or medical technologies, including systems used in critical healthcare applications.

Stryker: The cyberattack erased data from thousands of devices (without malware)

Restoring operations and next steps

Recovery efforts are focused on restoring core trading systems and the supply chain. The company assures that orders placed before the attack will be executed normally, while those placed during the outage will be processed once the systems are fully restored.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Loblaw Companies Limited: Customer data breach

In parallel, Stryker is cooperating with its production units worldwide to limit the impact and ensure the continuity of supplies.

This incident is yet another high-profile example of how access to management tools can become a powerful weapon in the hands of attackers, highlighting the need for tighter access controls and layered security in enterprise cloud environments.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS