logo

Stryker says malware was involved in recent cyberattack as production lines reopen

ID: ed844537-0781-5f3a-a49b-3ce2bb881c2d

STIX ID: report--ed844537-0781-5f3a-a49b-3ce2bb881c2d

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-03-24

Date Updated: 2026-05-01

...
...

Stryker disclosed that alleged Iranian cyber actors wiped more than 200,000 company devices using Microsoft Intune’s device-wipe feature and a malicious file, causing disruptions to hospital communication systems and prompting some hospitals to suspend connections; Palo Alto Networks Unit 42 helped remove unauthorized persistence, Stryker is rebuilding or restoring systems from backups and isolating unresolved systems, and there is no current evidence of customer system compromise though surgeries and operations were impacted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.