logo

Exposure Brief: Iranian-Linked Wiper Attack on Global Medtech Firm Stryker

ID: 572be43a-830f-592c-940a-3c1a7e12f436

STIX ID: report--572be43a-830f-592c-940a-3c1a7e12f436

Feed Name: Censys Blog

Threat Score
90/100

Date Published: 2026-03-17

Date Updated: 2026-04-27

...
...

On March 11, 2026, Stryker Corporation was hit by a destructive wiper attack attributed to Handala (an Iranian-linked actor) that erased data across its global Windows environment—likely via compromise of Microsoft Intune administrative access—disrupting manufacturing and wiping laptops, servers, and mobile devices; the report describes impact, Censys findings about exposed Internet-facing assets, and recommends mitigations such as phishing‑resistant MFA, conditional access, monitoring for anomalous MDM activity, and tested incident response plans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.