HomeSecurityStryker: Iranian hackers used stolen credentials

Stryker: Iranian hackers used stolen credentials

Stryker , one of the world’s largest medical technology companies, has been the victim of a cyberattack by the Iranian-based Handala group , which appears to have used stolen credentials to infiltrate the company’s systems. The attack, discovered on March 18, 2026 , caused a global outage of Stryker ’s networks and forced the company to send home more than 5,000 employees from its headquarters in Cork, Ireland.

See also: Iranian hackers claim responsibility for wiper attack on Stryker

Stryker

According to an analysis by cybersecurity experts, attackers exploited Microsoft Intune to execute remote wipe commands on connected Windows, including laptops and mobile phones. The Handala, which is linked to the Iranian Ministry of Intelligence and Security, claimed to have wiped more than 200,000 devices and stolen approximately 50TB of data from the company.

The attack comes amid rising geopolitical tensions between the US and Iran, which began in February 2026. Handala justified the attack as retaliation for a US strike on a school in Minab and for alleged cyberattacks against the Iranian “Axis of Resistance.” The group described Stryker as a “Zionist company” due to its acquisition of Israeli OrthoSpace in 2019.

Stryker companythat specializes in orthopedic products, surgical robots and medical equipment, immediately activated its incident response protocol with the help of external experts. The company, which employs 56,000 people worldwide and had revenue of $25.1 billion in 2025, is facing significant disruptions to operations in 79 countries.

See also: LexisNexis: Hackers leaked stolen data

Stryker: Iranian hackers used stolen credentials

Technical details of the attack on Stryker

According to KrebsOnSecurity, the attackers did not use traditional wiper malware, but instead exploited stolen credentials to gain access to Microsoft Intune. Through this device management platform, they were able to send remote wipe commands to thousands of connected devices. They also spoofed the company’s login pages with the Handala.

The attack had an immediate impact on the healthcare sector, as hospitals were forced to disconnect from services such as LifeNet, which is used to transmit electrocardiograms and speed up treatment for heart attacks. The Maryland Institute for Emergency Medical Services Systems reported a “global network outage” of Stryker on March 11, 2026.

Experts from Check Point Research and Palo Alto Networks Unit 42 confirmed Handala 's connection to Iranian intelligence. The group operates as a hacktivist organization, but is actually part of Iran's state cyber strategy. Similar groups such as Seedworm (MuddyWater) have been targeting American companies since early February 2026, deploying backdoors that were detected by Symantec and Carbon Black .

The cyberattack caused significant disruptions to Stryker 's operations , with repercussions that extend beyond the company's borders. Universities in the US experienced difficulties ordering surgical supplies, while production and shipping of products were disrupted worldwide. Despite the extensive disruptions, the company assured that products such as its Mako robots, Vocera communication system and LifePak35 defibrillators remain safe and operational.

See also: Stryker: Cyberattack deleted data from thousands of devices (no malware)

Stryker: Iranian hackers used stolen credentials

To protect against similar attacks, experts recommend disconnecting and isolating corporate devices from networks, strengthening the security of MDM tools like Microsoft Intune with strong credential hygiene and multi-factor authentication, and continuously monitoring for Iranian groups through threat intelligence.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS