Home Technology, networking, cybersecurity, AI Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
Technology, networking, cybersecurity, AI

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

Iran-Backed Hackers Claim - Iran-Backed Hackers Claim Wiper Attack On Medtech Firm Stryker

A hacktivist group with ties to Iran, known as Handala, claimed responsibility for a destructive wiper attack against Stryker, a major U.S. medical device manufacturer, on Wednesday, March 11, 2026. The group said it had wiped data from more than 200,000 systems, servers, and mobile devices across Stryker’s operations in 79 countries — one of the most significant destructive cyberattacks on a U.S. company to date.

Who’s behind the attack

Handala is believed to be linked to Iran’s Ministry of Intelligence and Security (MOIS). Security researchers at Palo Alto Networks have connected the group’s activity to a broader Iran-aligned actor tracked as Void Manticore. This kind of destructive, politically-motivated operation reflects a growing pattern in cybersecurity threats tied to nation-state actors — where the goal is disruption rather than financial gain.

The attack reportedly exploited Stryker’s Microsoft Intune device management platform, allowing attackers to remotely wipe enrolled devices without deploying traditional malware — a technique that highlights how administrative tools, if compromised, can be turned into destructive weapons at scale.

Stryker’s response

Stryker, headquartered in Michigan, confirmed it was responding to a cybersecurity incident affecting its Microsoft environment. The company said it had “no indication of ransomware or malware,” and that the incident was contained while teams worked to restore systems and resume normal operations. Stryker also said its internet-connected medical products remained safe to use, and that no patient data was affected — though the company later confirmed employee data had been compromised, which has since led to several lawsuits from affected staff.

The attack temporarily disrupted Stryker’s ordering, manufacturing, and shipping systems, though the company reported no material impact on patient care.

Formal attribution

On March 20, 2026, the U.S. Department of Justice formally attributed the attack to Iran’s MOIS and announced the seizure of several domains linked to Handala’s infrastructure. Stryker continues to work with third-party cybersecurity firms and government agencies, including the FBI and CISA, as the investigation proceeds. In a securities filing, the company noted the incident had a measurable impact on its first-quarter financial results.

For organizations looking to harden their own device management platforms against similar attacks, our cybersecurity fundamentals guide covers baseline practices like MFA enforcement and access monitoring. You can also browse more coverage in our Cybersecurity section.

Sources: Krebs on Security, TechCrunch

Avatar Of Asad Ijaz
Asad Ijaz

Editor & Founder

Lead Networking Architect and Editor at NetworkUstad. CCNP and CCNA certified, with 10+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.

Related Articles