Stryker Cyberattack: What You Need to Know
ID: 15e0c3c2-d650-5f72-bfcb-5a57370834db
STIX ID: report--15e0c3c2-d650-5f72-bfcb-5a57370834db
Feed Name: SOCRadar Blog
Threat Score
A March 11, 2026 incident at Stryker reportedly involved an identity compromise and abuse of Microsoft Intune administrative capabilities to remotely wipe tens of thousands of devices, causing widespread disruption to ordering, manufacturing, and shipping; the Handala group (an Iran-linked persona) claimed responsibility, IoCs and hashes have been published, and Stryker has stated there is no confirmed ransomware or data exfiltration while containment and recovery efforts continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
