The Brief
The pro-Iranian hacker group Handala claimed responsibility for a destructive cyberattack against Stryker Corporation, the $25 billion medical device manufacturer, wiping systems across the company’s global operations and forcing 56,000 employees offline. The attack disabled Stryker’s Microsoft environment, knocked out the Lifenet EMS transmission system used by emergency responders in Maryland and other states, and prompted the Cybersecurity and Infrastructure Security Agency to open a federal investigation. Handala stated the attack was retaliation for the February 28 missile strike on a girls’ school in Minab, Iran, that killed approximately 165 people, most of them children.
The Report
An Iran-linked hacking group has carried out the most significant cyberattack against an American company since the start of the 2026 Iran conflict, crippling the global operations of medical technology manufacturer Stryker Corporation.
The attack, which began around 3:30 AM Eastern on Wednesday, targeted Stryker’s Microsoft Intune environment — the cloud-based platform the company uses to manage its corporate devices. Cybersecurity experts determined that the attackers gained access to high-privilege administrative credentials and used Intune’s own remote wipe feature to issue factory-reset commands across the company’s enrolled devices. Because the wipe commands came through a trusted management channel, traditional endpoint detection tools likely did not flag the initial phase. The result was immediate and comprehensive: employee laptops, phones, and systems connected to the Stryker network were wiped clean, login pages replaced with the Handala group’s logo.
The operational impact has been severe. More than 5,000 workers were sent home from Stryker’s Irish headquarters in Cork, where the company runs six manufacturing facilities and three innovation centres. Across 61 countries, the company’s 56,000 employees lost access to internal communications and systems. Healthcare providers reported being unable to order surgical supplies. In Maryland, the Lifenet system — which transmits electrocardiogram data from ambulances to emergency physicians treating heart attack patients — went non-functional across most of the state. The Maryland Institute for Emergency Medical Services instructed paramedics to relay patient information by radio. A spokesperson said no effect on patient care had been reported.
Handala, which cybersecurity firms Palo Alto Networks and Flashpoint link to Iran’s intelligence apparatus, claimed to have wiped more than 200,000 systems and exfiltrated 50 terabytes of data. The group framed the attack as retaliation for the Minab school strike and called it “the beginning of a new chapter in cyber warfare.” Stryker holds significant contracts with the US Department of Defence and Veterans Affairs, valued at up to $450 million, and acquired Israeli medical technology firm OrthoSpace in 2019.
In an SEC 8-K filing, Stryker described a “severe, global disruption” but stated it found no evidence of ransomware or malware — consistent with the Intune-based attack vector. The company acknowledged that “the timeline for a full restoration is not yet known.” CISA Acting Director Nick Andersen confirmed the agency was investigating, stating it was “working shoulder-to-shoulder with our public- and private-sector partners.”
Stryker’s stock fell approximately 3.6 percent following the disclosure, extending a 9.5 percent decline over the past week. Check Point Research’s Sergey Shykevich called the attack “a significant escalation,” noting it was “the first time this Iranian-backed threat actor has disruptively targeted a major US enterprise.” Threat intelligence analysts at Flashpoint assessed that Handala’s tactics are “far more consistent with activity linked to Iranian state actors than with independent hacktivism.”
The Angle
The technical detail worth pausing on is not the scale of the attack — 200,000 devices, 56,000 workers, 61 countries — but the mechanism. Handala did not deploy malware. They did not encrypt files for ransom. They logged into Stryker’s own device management console and pressed the button that Stryker’s IT administrators press when a laptop is lost or an employee leaves the company. The wipe command was legitimate. The system obeyed because the system was designed to obey.
This is what makes the Intune vector different from the wiper attacks Iran has conducted before — Shamoon against Saudi Aramco in 2012, the Sands Casino hit in 2014. Those required custom-built destructive code. This required a stolen password and a dashboard that already had the capability built in. The attack surface was not a vulnerability in the conventional sense. It was a feature, used as intended, by someone who was not supposed to have the keys.
The implications run well past Stryker. Every large organisation that manages its devices through a centralised cloud platform — which is to say, nearly every large organisation — has built the same capability into its own infrastructure. The remote wipe function exists because it is genuinely useful: lost devices, departing employees, compliance requirements. It also means that a single compromised administrative account can brick an entire enterprise’s hardware fleet in minutes, through channels that the devices themselves trust implicitly. The tool was designed for a world where the administrator is always friendly. That assumption held until it didn’t.
Stryker’s SEC filing calls the incident “contained.” The word is doing more work than it can support. The company’s own employees describe operations at a complete stop. Emergency responders in Maryland reverted to voice communication because the cardiac monitoring relay went dark. Surgical supply chains froze. The distance between “contained” and “the timeline for a full restoration is not yet known” — filed in the same document — is the distance between what a publicly traded company needs its investors to hear and what is actually happening on the floor.
The broader pattern is harder to manage than the specific incident. Iran’s cyber operations since the start of the war had been limited to espionage and minor disruption — cautious, deniable, well below the threshold that would demand a response. The Stryker attack crosses that threshold. A state-linked actor turned a US defence contractor’s own infrastructure against it, disabled medical systems that serve civilian patients, and announced it publicly as the opening move of a campaign. The question now is not whether the capability exists. It is whether the architecture of every major enterprise’s device management — built for convenience, secured by credentials, trusted by design — is a liability that no one priced in until someone demonstrated it at scale.
The first significant Iranian cyberattack of this war did not exploit a software flaw — it used the software exactly as designed.