Stryker Corporation, one of the world’s largest medical technology companies, said it has returned to full operations three weeks after a devastating cyberattack that wiped data from thousands of systems. The attack was carried out by the Iranian-based Handala, which managed to wipe approximately 80,000 employee worldwide. The incident highlights the growing threat to critical healthcare infrastructure from state-sponsored cyberattacks.

The company, which employs over 53,000 people in 61 countries, produces a wide range of medical products, including neurotechnology and surgical equipment, serving more than 150 million patients annually.
The attackers began wiping Stryker on March 11, claiming to have stolen 50 terabytes of data before wiping nearly 80,000 devices early in the morning. The attack was carried out using a new Global Administrator account created after a Windows domain admin account was compromised.
See also: CISA recommends strengthening endpoint management after Stryker attack
The Handala group exploited Microsoft Intune 's remote wipe feature by sending factory reset commands to all enrolled devices. This tactic allowed attackers to cause mass destruction without having to deploy sophisticated malware on each target individually.
The attack caused immediate and widespread disruptions to health services in multiple countries.
Technical details of the Stryker attack
According to security researchers, the attack represented a new and disturbing approach to destructive cyberattacks. Instead of using traditional malware or ransomware, the attackers exploited legitimate management tools, adopting a “living-off-the-land”.
Check Point Research and Sergey Shykevich called the attack worrisome for the healthcare sector, as it jeopardizes patient safety through disruption of critical infrastructure. Palo Alto Networks Unit 42 and Stryker 's investigation ruled out the use of ransomware or malware , but identified a malicious file that was used to execute hidden commands on the company's network.
See also: Iranian hackers claim responsibility for wiper attack on Stryker

Following the disclosure of the attack, CISA and Microsoft issued urgent guidance on securing Intune and hardening Windows domains to block similar attacks. Recommendations include implementing least-privilege access, using phishing-resistant MFA , and monitoring changes to Global Admin accounts.
At the same time, the FBI seized two websites that the Handala hackers to coordinate their activities.
The Handala Group and its Connections to Iran
Handala emerged in December 2023 as an Iranian and pro-Palestinian hacktivist group that initially targeted Israeli organizations with Windows and Linux data-wiping malware . The group has been linked to Iran's Ministry of Intelligence and Security (MOIS) and is also known for leaking sensitive data from compromised victim systems. Its past activities include phishing campaigns, data theft, extortion, and destructive attacks primarily against targets in the Middle East.

The attack on Stryker marked the group's first major targeting of an American company, expanding its operations beyond traditional Israeli targets. Security experts believe the choice of Stryker as a target may be related to the company's global reach and critical role in healthcare.
See also: Stryker: Iranian hackers used stolen credentials
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Security recommendations and lessons from the attack
The Stryker attack highlights the need for enhanced security measures in Mobile Device Management (MDM) systems. Companies should implement stricter access controls for Global Administrator accounts, separate corporate from personal BYOD , and avoid over-reliance on individual tools like Intune. In addition, enabling wipe confirmations and regularly auditing remote commands can limit the devastating consequences of such attacks.
On Wednesday, Stryker announced that it had restored enough systems to return to pre-attack operating levels. According to BleepingComputer, the company said: “As of this week, we are fully operational across our global manufacturing network. Production is moving rapidly towards maximum capacity with discipline and consistency.”
