logo

Attack on Stryker’s Microsoft environment wiped employee devices without malware

ID: 575ebd4d-69c5-5cd3-8b54-b2b714a1bc2f

STIX ID: report--575ebd4d-69c5-5cd3-8b54-b2b714a1bc2f

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Stryker experienced a large-scale destructive cyberattack that targeted its internal Microsoft corporate environment: attackers compromised an administrator account, created a Global Administrator, and executed Microsoft Intune wipe commands that erased nearly 80,000 devices; the hacktivist group Handala (reported as linked to Iran-backed Void Manticore) claimed responsibility and alleged additional mass exfiltration, while Stryker and Microsoft-led investigators state the incident did not affect medical devices but has disrupted corporate systems globally.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.