• Wion
  • /Photos
  • /‘Stryker cyber attack’: What the Handala wiper means for the 56,000 employees of the US giant

‘Stryker cyber attack’: What the Handala wiper means for the 56,000 employees of the US giant

Medtech giant Stryker faces a global crisis after an Iran-linked group wiped 200,000 devices on March 11, 2026. The attack impacts 56,000 staff and medical supply chains.

Global system shutdown
1 / 10
(Photograph: Unsplash)

Global system shutdown

Stryker confirmed a "global network disruption" impacting its Microsoft environment on March 11, 2026. The Michigan-based company, which earned $25 billion in revenue in 2025, saw its IT infrastructure go dark across dozens of countries simultaneously.

56,000 staff hit
2 / 10

56,000 staff hit

The company's 56,000 employees found their corporate laptops and phones completely inoperational. In Ireland, over 5,000 workers were sent home after the network outage paralyzed manufacturing and innovation hubs.

Handala claims strike
3 / 10

Handala claims strike

The Iran-linked hacktivist collective Handala claimed credit for the operation via social media and Telegram. Security experts link the group to Void Manticore, an actor affiliated with Iran’s Ministry of Intelligence and Security.

200,000 devices erased
4 / 10

200,000 devices erased

Handala asserted it wiped data from more than 200,000 servers, laptops, and mobile devices across 79 countries. Employees reported that login screens were replaced with the group's logo before systems were factory reset.

50TB data theft
5 / 10
(Photograph: AI)

50TB data theft

The hackers claimed to have exfiltrated 50 terabytes of critical corporate data before initiating the destructive wipe. This massive breach poses a significant risk to the company's intellectual property and sensitive partner information.

Motive for the attack
6 / 10
(Photograph: AI)

Motive for the attack

Handala described the hack as retaliation for a military strike on a school in Minab, Iran. They also cited Stryker’s 2019 acquisition of Israeli firm OrthoSpace and its contracts with the US Department of Defense as reasons for targeting the giant.

Abuse of Microsoft Intune
7 / 10
(Photograph: Army.mil)

Abuse of Microsoft Intune

Investigators believe the attackers hijacked Microsoft Intune, a cloud management tool, to issue a global remote wipe command. This allowed them to factory reset thousands of enrolled devices at once without needing custom malware.

Not a ransom demand
8 / 10
(Photograph: AI)

Not a ransom demand

Stryker stated there is no indication that ransomware or traditional malware was used in the incident. Unlike extortion-based crimes, this campaign was designed for permanent data destruction and maximum operational sabotage.

Supply chain impact
9 / 10
(Photograph: Unsplash)

Supply chain impact

As a major supplier for surgeries worldwide, Stryker’s downtime has sparked fears of hospital inventory shortages. While the firm says it has business continuity plans, the scale of the disruption is impacting medical supply chains.

Investigation underway
10 / 10
(Photograph: Unsplash)

Investigation underway

Stryker says the incident is contained but expects disruptions to continue for an undetermined period. CISA and other agencies are investigating the breach, while the company’s share price fell roughly 3 per cent following the news.