Skip to content

Stryker global destructive cyberattack

Summary

Stryker Corporation logo

A March 11 destructive cyberattack wiped about 40,000 Stryker laptops and disrupted its Microsoft environment, global manufacturing, order processing, shipping and some customer procedures. Handala claimed the attack; federal authorities later said an Iran intelligence ministry-controlled Handala domain was used to claim the operation, supporting high-confidence attribution, while the actor’s 200,000-device and 50 TB theft assertions remain unverified. Stryker said its manufacturing, commercial, ordering and distribution systems were restored by April 9.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Credential compromise

    Theft, exposure, or abuse of user or administrator credentials.

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

Data impacts

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Manufacturing or production disruption

    Manufacturing, production, assembly, processing, or industrial operations were reduced, stopped, or impaired.

  • Supply chain disruption

    Procurement, inventory, warehousing, shipping, delivery, vendor, or other supply-chain processes were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Stryker identified a cyberattack March 11 that disrupted its global Microsoft environment and restricted access to systems and business applications. The company initially said it had no indication of ransomware or malware. In its March 23 customer update, Stryker said an unauthorized party had been removed and that investigators found a malicious file used to execute commands and conceal activity. Stryker described the file as non-self-spreading and continued to say the event was not ransomware.

The destructive effect is now supported by direct company statements. Stryker Chair and CEO Kevin Lobo said about 40,000 laptops were wiped and that phones also were affected, according to Becker’s Hospital Review. CISA-linked reporting said the attackers misused Stryker’s endpoint-management systems, while reporting based on a source familiar with the incident said a compromised administrator account was used to create a new global administrator account and issue Microsoft Intune wipe commands. The evidence supports unauthorized access, credential compromise, malicious code and data destruction, but not ransomware.

Operational significance

The incident disrupted electronic ordering, manufacturing, shipping, distribution, accounting and employees’ access to internal systems. Stryker used manual ordering through representatives and distributors, added production shifts to address a backlog and used local continuity procedures for some clinical workflows. The company said patient-specific procedures scheduled for the week of March 16 were rescheduled because of shipping delays, and customers using personalized implants experienced disruption. Connected products and product-facing systems were reported safe.

The downstream effects extended beyond Stryker. NHS England said production had halted and that orders placed from March 11 through March 16 could not be processed and would be canceled. It directed trusts to an interim NHS Supply Chain ordering channel, imposed clinical prioritization and demand controls, and required acute, community, mental health and ambulance trusts to report their stock position and dependency. The notice required nil returns, so it does not establish that every trust was affected.

Stryker later determined that the incident materially affected operations and first-quarter financial results. Company executives said manufacturing was paused for nearly three weeks, some procedures were deferred or rescheduled, and revenue recognition shifted because accounting systems were unavailable.

Attribution and claims

Handala claimed the attack March 11 and alleged that it wiped more than 200,000 systems, servers and mobile devices and stole 50 TB of data. The U.S. Department of Justice later said an Iran Ministry of Intelligence and Security-controlled Handala domain was used to claim a March 2026 destructive attack against a U.S.-based multinational medical technology company. The government linkage, the claim’s timing and the match between the actor’s destructive posture and confirmed device wiping support high-confidence Handala attribution. Stryker did not publicly name the actor, and neither the 200,000-device figure nor the alleged theft is verified.

A separate Ransomware.live entry says Qilin listed “Stryker” and stryker.com on July 24. The page contains no incident description or evidence and identifies the entry as a possible duplicate because the domain also appears in Handala’s March listing. No reviewed source links Qilin to the March attack or documents a later Stryker outage or confirmed intrusion. The Qilin entry is preserved as a caveated claim, not treated as attribution or evidence that the March incident remained active.

Disclosure posture

Handala’s claim was publicly reported by SecurityWeek at 12:18 p.m. Eastern time March 11. Stryker’s Form 8-K was accepted by the SEC at 1:24 p.m. Eastern time the same day and explicitly identified a cybersecurity incident. That external-first, organization-later sequence supports XC-OC. Stryker and direct authorities documented the material operational effects, supporting OD.

Response and recovery

A March 20 Unit 42 letter said known indicators had been addressed, accounts were being secured with Microsoft and affected systems were being rebuilt or restored from backups predating the known compromise window. Unit 42 found no incident-related unauthorized activity after March 11 and said the immediate operational risk had been mitigated, but Stryker still reported March 23 that manufacturing sites were stabilizing as plants and lines returned.

Stryker’s April 9 Form 8-K/A said the company was fully operational across its global manufacturing network and that commercial, ordering and distribution systems had been restored. The incident is therefore resolved. March 23 remains the last documented date of operational impact; April 9 is the authoritative recovery date and does not imply disruption continued until that day.

Confidence and uncertainty

Confidence is high that a destructive cyberattack caused material global operational disruption because Stryker confirmed the event, device wiping and recovery, while its SEC filing established materiality. Handala attribution is high confidence but not confirmed because Stryker did not identify the actor and the Justice Department described the Handala domain’s claim rather than publishing Stryker’s full forensic attribution.

Confirmed data impact is limited to deletion or destruction. Handala’s 50 TB exfiltration allegation remains a claim, and Stryker has not publicly confirmed theft or disclosed affected data categories, people or records. The July Qilin listing adds an unresolved later claim but does not alter the March incident’s non-ransomware assessment.

Analytic gaps

The public record does not establish the precise initial-access path, compromised account, dwell time, complete affected-system inventory, authoritative endpoint total, verified data theft, affected data categories, notification population, full financial cost or final investigative findings. It also does not establish whether Qilin’s July listing was a duplicate, a misattribution or a separate later intrusion.

Threat actors and claims

Listed as: StrykerSource: ransomware.livePublished: Discovered:

Claim details

Qilin listed Stryker and stryker.com July 24. The monitored page contains no description, alleged data volume, deadline, sample or other supporting detail and marks the entry as a possible duplicate because the same domain appears in Handala’s March listing. No reviewed source ties Qilin to the March disruption or documents a later confirmed Stryker intrusion or outage. The entry may be a duplicate, misattribution or separate unconfirmed claim.

Listed as: Stryker CorporationSource: ransomware.livePublished: Discovered:

Claim details

Handala listed Stryker Corporation March 11 and claimed it wiped more than 200,000 systems, servers and mobile devices and stole 50 TB of data, framing the operation as retaliation. Stryker later confirmed unauthorized access and global destructive effects, and its CEO said about 40,000 laptops were wiped, but the company did not validate Handala’s device count, alleged theft or attribution. The Justice Department later said an Iran Ministry of Intelligence and Security-controlled Handala domain was used to claim the destructive attack. The evidence supports a high-confidence connection to the intrusion, not every claim assertion.

Organizations involved

Impacted locations

  • Chandler, Arizona

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Chandler as a manufacturing and production operation; no site-by-site impact inventory was published.

  • Tempe, Arizona

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Tempe as a sustainability solutions reprocessing and remanufacturing; no site-by-site impact inventory was published.

  • Fremont, California

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Fremont as a neurovascular division; no site-by-site impact inventory was published.

  • Irvine, California

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Irvine as a peripheral vascular division; no site-by-site impact inventory was published.

  • San Jose, California

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies San Jose as a endoscopy division; no site-by-site impact inventory was published.

  • Ventura, California

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Ventura as a medical-device manufacturing operation; no site-by-site impact inventory was published.

  • Greenwood Village, Colorado

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Greenwood Village as a sports medicine engineering operation; no site-by-site impact inventory was published.

  • Fort Lauderdale, Florida

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Fort Lauderdale as a mako education center and manufacturing; no site-by-site impact inventory was published.

  • Lakeland, Florida

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Lakeland as a sustainability solutions production facility; no site-by-site impact inventory was published.

  • Weston, Florida

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Weston as a robotics innovation center for r&d, engineering and production; no site-by-site impact inventory was published.

  • Cary, Illinois

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Cary as a sage business unit and manufacturing operation; no site-by-site impact inventory was published.

  • Fort Wayne, Indiana

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Fort Wayne as a vocera-derived innovation office; no site-by-site impact inventory was published.

  • Plainfield, Indiana

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Plainfield as a supply-chain and returns operation; no site-by-site impact inventory was published.

  • Kalamazoo, Michigan

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Kalamazoo as a global headquarters, instruments and medical divisions, manufacturing, logistics and engineering; no site-by-site impact inventory was published.

  • Bloomington, Minnesota

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Bloomington as a upper extremities business unit, distribution center and corporate functions; no site-by-site impact inventory was published.

  • Mahwah, New Jersey

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Mahwah as a orthopaedics operation; no site-by-site impact inventory was published.

  • Arroyo, Puerto Rico

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Arroyo as a endoscopy and instruments manufacturing; no site-by-site impact inventory was published.

  • Arlington, Tennessee

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Arlington as a trauma and extremities manufacturing plant; no site-by-site impact inventory was published.

  • Memphis, Tennessee

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Memphis as a foot and ankle business and production; no site-by-site impact inventory was published.

  • Flower Mound, Texas

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Flower Mound as a communications office and warehouse; no site-by-site impact inventory was published.

  • Salt Lake City, Utah

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Salt Lake City as a physician training center and neurovascular operations; no site-by-site impact inventory was published.

  • Leesburg, Virginia

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Leesburg as a spine headquarters and bioskills laboratory; no site-by-site impact inventory was published.

  • Redmond, Washington

    Medium Confidence

    Stryker described a global corporate-network disruption affecting manufacturing, ordering and shipping. Stryker identifies Redmond as a physio-control operation and manufacturing; no site-by-site impact inventory was published.

Sources

Stryker cyber incident disrupts global operations

A cyberattack disrupted Stryker’s global Microsoft environment and affected employees and business operations.

MedTech giant Stryker crippled by Iran-linked hacker attack

SecurityWeek reported Handala’s claim at 12:18 p.m. ET March 11, before Stryker’s SEC disclosure was accepted. Handala alleged more than 200,000 systems, servers and mobile devices were wiped and 50 TB of data was stolen; the figures were not independently verified.

Stryker Corporation — claimed by Handala

Ransomware.live preserves Handala’s March 11 listing for Stryker Corporation and the actor’s politically framed claim. The listing substantiates the existence and wording of the claim, not responsibility, the alleged 200,000-device scope or 50 TB of theft.

Stryker Corporation Form 8-K

Stryker disclosed a March 11 cybersecurity incident that globally disrupted its Microsoft environment, limited access to systems and business applications, and had an unknown restoration timeline. It said it had no indication of ransomware or malware.

CISA urges US orgs to secure Microsoft Intune systems after Stryker breach

CISA linked its endpoint-management hardening alert to the Stryker attack. A source familiar with the incident said an administrator account was compromised, a new global administrator account was created and Microsoft Intune wipe commands were issued; those technical details were not confirmed by Stryker.

Justice Department disrupts Iranian cyber enabled psychological operations

The Justice Department said four seized domains were controlled by Iran’s Ministry of Intelligence and Security. It said the Handala-hack.to domain was used March 11 to claim a destructive attack against a U.S.-based multinational medical technology company.

Stryker Corporation partner and customer connections to the Stryker environment

Unit 42 said the compromise affected Stryker’s Entra ID environment, servers and workstations. It reported that known indicators were addressed, no persistent unauthorized access remained, affected systems were being rebuilt or restored from pre-compromise backups and no incident-related activity had been identified after March 11.

Stryker Medical – cyber-attack and associated disruption to supply of medical equipment and consumables

NHS England said the attack halted production and disrupted shipping and distribution. Orders placed March 11-16 would be canceled, trusts were redirected to an interim ordering channel with clinical prioritization and all acute, community, mental health and ambulance trusts had to report stock and dependency, including nil returns.

Customer updates: Stryker network disruption

Stryker’s dated updates document the March 11 global Microsoft-environment disruption; electronic-ordering, manufacturing, shipping and patient-specific procedure effects; manual continuity measures; a malicious file used for command execution and concealment; and continuing manufacturing stabilization March 23. Stryker said the incident was not ransomware.

Stryker Corporation Form 8-K/A

Stryker determined that the incident materially affected operations and first-quarter financial results. As of April 9, it said the company was fully operational across its global manufacturing network and that commercial, ordering and distribution systems had been restored.

Stryker takes temporary financial hit from cyberattack

Reporting on Stryker’s April 30 earnings call said manufacturing paused for nearly three weeks, accounting systems were unavailable and some hospitals delayed procedures. CEO Kevin Lobo said about 40,000 laptops were wiped and phones also were affected.

Staff Electrical Engineer, Embedded Systems

The official onsite job posting identifies Stryker’s Sports Medicine engineering operation in Greenwood Village, Colorado.

Stryker — claimed by Qilin

Ransomware.live records a July 24 Qilin listing for Stryker and stryker.com but provides no incident description or supporting evidence. The page identifies the entry as a possible duplicate because the same domain appears in another claim; no evidence links it to the March attack.

Associate Manufacturing Supervisor

The official onsite job posting identifies a Stryker production operation in Chandler, Arizona, with a manufacturing supervisor responsible for production-area activities.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

Our offices

Stryker’s official location directory identifies operating sites and functions in Kalamazoo, Tempe, Irvine, Fremont, San Jose, Weston, Fort Lauderdale, Cary, Fort Wayne, Memphis, Arlington, Flower Mound, Bloomington, Salt Lake City, Mahwah, Redmond and Arroyo.

Returns Associate

The official onsite job posting identifies Stryker supply-chain and returns operations in Plainfield, Indiana.

Senior Manufacturing Engineer

The official onsite job posting identifies a Stryker medical-device manufacturing operation in Ventura, California.

Spine medical education resources

Stryker identifies a headquarters and 1,484-square-foot bioskills lab in Leesburg, Virginia, used for training and research and development.

Stryker Corporation official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Sustainability Solutions contact information

Stryker identifies a Florida production facility at 5307 Great Oak Drive in Lakeland.

See something that needs correction?

Signed-in members can report an error, update, or missing source.