Analyst assessment
Stryker identified a cyberattack March 11 that disrupted its global Microsoft environment and restricted access to systems and business applications. The company initially said it had no indication of ransomware or malware. In its March 23 customer update, Stryker said an unauthorized party had been removed and that investigators found a malicious file used to execute commands and conceal activity. Stryker described the file as non-self-spreading and continued to say the event was not ransomware.
The destructive effect is now supported by direct company statements. Stryker Chair and CEO Kevin Lobo said about 40,000 laptops were wiped and that phones also were affected, according to Becker’s Hospital Review. CISA-linked reporting said the attackers misused Stryker’s endpoint-management systems, while reporting based on a source familiar with the incident said a compromised administrator account was used to create a new global administrator account and issue Microsoft Intune wipe commands. The evidence supports unauthorized access, credential compromise, malicious code and data destruction, but not ransomware.
Operational significance
The incident disrupted electronic ordering, manufacturing, shipping, distribution, accounting and employees’ access to internal systems. Stryker used manual ordering through representatives and distributors, added production shifts to address a backlog and used local continuity procedures for some clinical workflows. The company said patient-specific procedures scheduled for the week of March 16 were rescheduled because of shipping delays, and customers using personalized implants experienced disruption. Connected products and product-facing systems were reported safe.
The downstream effects extended beyond Stryker. NHS England said production had halted and that orders placed from March 11 through March 16 could not be processed and would be canceled. It directed trusts to an interim NHS Supply Chain ordering channel, imposed clinical prioritization and demand controls, and required acute, community, mental health and ambulance trusts to report their stock position and dependency. The notice required nil returns, so it does not establish that every trust was affected.
Stryker later determined that the incident materially affected operations and first-quarter financial results. Company executives said manufacturing was paused for nearly three weeks, some procedures were deferred or rescheduled, and revenue recognition shifted because accounting systems were unavailable.
Attribution and claims
Handala claimed the attack March 11 and alleged that it wiped more than 200,000 systems, servers and mobile devices and stole 50 TB of data. The U.S. Department of Justice later said an Iran Ministry of Intelligence and Security-controlled Handala domain was used to claim a March 2026 destructive attack against a U.S.-based multinational medical technology company. The government linkage, the claim’s timing and the match between the actor’s destructive posture and confirmed device wiping support high-confidence Handala attribution. Stryker did not publicly name the actor, and neither the 200,000-device figure nor the alleged theft is verified.
A separate Ransomware.live entry says Qilin listed “Stryker” and stryker.com on July 24. The page contains no incident description or evidence and identifies the entry as a possible duplicate because the domain also appears in Handala’s March listing. No reviewed source links Qilin to the March attack or documents a later Stryker outage or confirmed intrusion. The Qilin entry is preserved as a caveated claim, not treated as attribution or evidence that the March incident remained active.
Disclosure posture
Handala’s claim was publicly reported by SecurityWeek at 12:18 p.m. Eastern time March 11. Stryker’s Form 8-K was accepted by the SEC at 1:24 p.m. Eastern time the same day and explicitly identified a cybersecurity incident. That external-first, organization-later sequence supports XC-OC. Stryker and direct authorities documented the material operational effects, supporting OD.
Response and recovery
A March 20 Unit 42 letter said known indicators had been addressed, accounts were being secured with Microsoft and affected systems were being rebuilt or restored from backups predating the known compromise window. Unit 42 found no incident-related unauthorized activity after March 11 and said the immediate operational risk had been mitigated, but Stryker still reported March 23 that manufacturing sites were stabilizing as plants and lines returned.
Stryker’s April 9 Form 8-K/A said the company was fully operational across its global manufacturing network and that commercial, ordering and distribution systems had been restored. The incident is therefore resolved. March 23 remains the last documented date of operational impact; April 9 is the authoritative recovery date and does not imply disruption continued until that day.
Confidence and uncertainty
Confidence is high that a destructive cyberattack caused material global operational disruption because Stryker confirmed the event, device wiping and recovery, while its SEC filing established materiality. Handala attribution is high confidence but not confirmed because Stryker did not identify the actor and the Justice Department described the Handala domain’s claim rather than publishing Stryker’s full forensic attribution.
Confirmed data impact is limited to deletion or destruction. Handala’s 50 TB exfiltration allegation remains a claim, and Stryker has not publicly confirmed theft or disclosed affected data categories, people or records. The July Qilin listing adds an unresolved later claim but does not alter the March incident’s non-ransomware assessment.
Analytic gaps
The public record does not establish the precise initial-access path, compromised account, dwell time, complete affected-system inventory, authoritative endpoint total, verified data theft, affected data categories, notification population, full financial cost or final investigative findings. It also does not establish whether Qilin’s July listing was a duplicate, a misattribution or a separate later intrusion.