Don’t do SECURITY. Do business SECURELY.

Iran-linked hackers wipe devices at medical technology firm Stryker

A pro-Iran group claims a destructive attack on Stryker that wiped tens of thousands of company devices and disrupted operations worldwide.

US medical technology company Stryker suffered a destructive cyber attack claimed by Handala, a group that presents itself as pro-Palestinian hacktivists and that security researchers link to Iran’s Ministry of Intelligence and Security. The attack came amid US and Israeli military action against Iran.

What happened

  • The attackers reportedly compromised an administrator account and used Microsoft Intune, Stryker’s own device management tool, to issue remote wipe commands.
  • Around 80,000 devices were reported to have been wiped, including some personal devices enrolled in company management. Handala claimed a much higher figure.
  • Stryker said it was restoring systems within days and later said the attack had a material impact on its first-quarter results.
  • The FBI seized Handala’s websites, saying they supported malicious cyber activity on behalf of a foreign state actor.

Why it mattered

The attack showed that nation-state-linked groups can cause major disruption without malware by abusing legitimate administration tools.

Lessons for organisations

Treat privileged cloud and device management accounts as crown jewels: use phishing-resistant MFA, separate admin accounts, and approval controls for mass actions such as remote wipes. Monitor for new global administrator accounts.

Sources: TechCrunch, BleepingComputer

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights