Breach report
Stryker confirms global IT disruption; Handala claims wiping and data theft

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The medical device maker says a cyberattack disrupted its Microsoft and corporate network worldwide from 11 March. Pro-Iran group Handala claims it wiped devices and took 50 TB.
What happened
On 11 March 2026, Stryker, a US maker of medical devices and hospital equipment, identified a cyberattack that caused a global disruption to its Microsoft environment, according to its 8-K filing with the US Securities and Exchange Commission. A second filing said order processing, manufacturing and shipping were disrupted, but that patient-related services and connected products were not believed affected. TechCrunch reported that systems were wiped and some login pages showed the attacker's logo. The US Cybersecurity and Infrastructure Security Agency (CISA) said it was investigating.
Confirmed vs. claimed
Confirmed by Stryker: the disruption, which a 23 March filing said extended to its wider corporate network. Stryker first said there was no sign of ransomware or malware; it later said the attacker used a malicious file to run commands and hide its activity, but that the file could not spread. Its investigators had found no malicious activity aimed at customers, suppliers or partners.
Claimed: Handala, a pro-Iran hacktivist group, said it wiped more than 200,000 systems and devices, took 50 TB of data and forced offices in 79 countries to close. Stryker has not confirmed data theft or these figures in the filings we reviewed. Threat researchers quoted by TechCrunch note the group's record of inflated claims.
Who is affected
Stryker staff and operations worldwide, and hospital customers whose orders and deliveries were disrupted. Whether personal data of employees or patients was taken has not been confirmed.
What to do
- Stryker employees should watch for official company notices and be wary of emails or calls that use the incident as a pretext.
- Hospital procurement teams should confirm any change to payment or delivery details by phoning a known Stryker contact.
- Treat leaked files posted by the group as unverified.
- See our guide on what to do after a data breach notice.
Sources
- Stryker — Form 8-K, cybersecurity incident (11 Mar 2026) Primary
- Stryker — Form 8-K, update on cybersecurity incident (12 Mar 2026) Primary
- Stryker — Form 8-K, investigation update (23 Mar 2026) Primary
- TechCrunch — Pro-Iran hacktivist group says it is behind attack on medical tech giant Stryker (11 Mar 2026) Secondary
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- Aesto Health — 14 Aug 2026
- DentaQuest — 17 Jul 2026