{"id":28096,"date":"2026-03-18T03:58:25","date_gmt":"2026-03-18T03:58:25","guid":{"rendered":"https:\/\/microvibenews.com\/?p=28096"},"modified":"2026-03-18T03:58:25","modified_gmt":"2026-03-18T03:58:25","slug":"stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=28096","title":{"rendered":"Stryker says it&#8217;s restoring systems after pro-Iran hackers wiped thousands of employee devices"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Medical tech giant Stryker said it\u2019s in the process of restoring its computers and internal network following a cyberattack that reportedly <a href=\"https:\/\/techcrunch.com\/2026\/03\/11\/stryker-hack-pro-iran-hacktivist-group-handala-says-it-is-behind-attack\/\">allowed pro-Iranian hackers<\/a> to remotely wipe tens of thousands of employee devices.<\/p>\n<p class=\"wp-block-paragraph\">The hack, which brought ongoing widespread disruption to the company\u2019s operations, is thought to be the first major cyberattack in the United States in response to the Trump administration\u2019s war in Iran.<\/p>\n<p class=\"wp-block-paragraph\">Stryker said in an <a href=\"https:\/\/www.stryker.com\/us\/en\/about\/news\/2026\/a-message-to-our-customers-03-2026.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">update over the weekend<\/a> that the March 11 cyberattack was contained to the company\u2019s internal Microsoft environment, and that its internet-connected medical products are \u201csafe to use.\u201d<\/p>\n<p class=\"wp-block-paragraph\">While the cause of the breach is still under investigation, the medical device tech maker said it has seen no indication of ransomware or malware. Stryker said its ability to process orders, manufacture, or ship devices continues to be disrupted.<\/p>\n<p class=\"wp-block-paragraph\">A pro-Iran hacking group called Handala <a href=\"https:\/\/techcrunch.com\/2026\/03\/11\/stryker-hack-pro-iran-hacktivist-group-handala-says-it-is-behind-attack\/\">took credit for the destructive breach<\/a>, claiming its hack was in response to <a href=\"https:\/\/apnews.com\/article\/iran-us-school-hegseth-trump-2ffff06808f7a584b0a03831897ab0b8\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a U.S. air strike on an Iranian school<\/a> that killed at least 175 people, mostly children. The hackers also defaced the company\u2019s login pages with its own logo.<\/p>\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Bleeping Computer<\/a>, the Handala hackers may have broken in using an internal Stryker administrator account that granted them <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/admin\/add-users\/about-admin-roles?view=o365-worldwide\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">near-unlimited access<\/a> to the company\u2019s Windows network. The hackers allegedly accessed the company\u2019s Microsoft Intune dashboards, which allows the remote management of employee laptops and mobile devices, such as deleting data in case an employee\u2019s device is lost or stolen.<\/p>\n<p class=\"wp-block-paragraph\">A successful compromise of the company\u2019s Intune dashboards would have allowed the hackers to remotely wipe employee phones and laptops, including personal devices, without using malware.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wsj.com\/politics\/national-security\/hack-on-u-s-medical-company-shows-reach-of-irans-cyber-capabilities-85999878\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Wall Street Journal<\/a> also reported that the hackers targeted Intune.<\/p>\n<p class=\"wp-block-paragraph\">A spokesperson for Stryker did not respond to a request for comment or questions about the breach, including whether the allegedly compromised account was protected with multi-factor authentication.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s unclear how the hackers obtained their access to Stryker\u2019s network to begin with. Security researchers with <a href=\"https:\/\/unit42.paloaltonetworks.com\/handala-hack-wiper-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Palo Alto Networks<\/a> said the Handala hackers may have relied on phishing to compromise Stryker\u2019s network. <a href=\"https:\/\/exchange.xforce.ibmcloud.com\/threat-group\/guid:791d811416a34f0793cc058d91190adf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">IBM<\/a> said the Iran-aligned hacking group is known for using phishing techniques and destructive attacks, including targeting the healthcare and energy sectors. <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#infostealers\">Infostealer malware<\/a>, which can steal a person\u2019s passwords and credentials, may also be to blame.<\/p>\n<p class=\"wp-block-paragraph\">Stryker has 56,000 staff around the world and operates in more than 60 countries, <a href=\"https:\/\/www.reuters.com\/technology\/stryker-says-cyberattack-its-network-contained-2026-03-17\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">according to Reuters<\/a>.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/17\/stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Medical tech giant Stryker sai&hellip; <\/p>\n","protected":false},"author":1,"featured_media":28097,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[10202,1662,6466,11080,10203],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/28096"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=28096"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/28096\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/28097"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=28096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=28096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=28096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}