US medical technology company Stryker suffered a destructive cyber attack claimed by Handala, a group that presents itself as pro-Palestinian hacktivists and that security researchers link to Iran’s Ministry of Intelligence and Security. The attack came amid US and Israeli military action against Iran.
What happened
- The attackers reportedly compromised an administrator account and used Microsoft Intune, Stryker’s own device management tool, to issue remote wipe commands.
- Around 80,000 devices were reported to have been wiped, including some personal devices enrolled in company management. Handala claimed a much higher figure.
- Stryker said it was restoring systems within days and later said the attack had a material impact on its first-quarter results.
- The FBI seized Handala’s websites, saying they supported malicious cyber activity on behalf of a foreign state actor.
Why it mattered
The attack showed that nation-state-linked groups can cause major disruption without malware by abusing legitimate administration tools.
Lessons for organisations
Treat privileged cloud and device management accounts as crown jewels: use phishing-resistant MFA, separate admin accounts, and approval controls for mass actions such as remote wipes. Monitor for new global administrator accounts.
Sources: TechCrunch, BleepingComputer
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.