Dramatic illustration of Stryker's operations center disrupted by Iran-linked cyberattack, with error-filled screens and intact medical devices.
Dramatic illustration of Stryker's operations center disrupted by Iran-linked cyberattack, with error-filled screens and intact medical devices.
Picha iliyoundwa na AI

Iran-linked hackers disrupt Stryker's network in apparent retaliation

Picha iliyoundwa na AI

A cyberattack attributed to the Iran-aligned Handala Hack group has disrupted the Microsoft environment of medical device maker Stryker, paralyzing much of its global operations. The incident, which emerged shortly after US and Israeli airstrikes on Iran, involved data wiping across tens of thousands of computers. Stryker confirmed the attack is contained, with no impact on its critical medical devices.

The cyberattack on Stryker, a multinational producer of medical equipment, surfaced on March 11, 2026, amid warnings of retaliatory hacks following US and Israeli airstrikes on Iran in late February. Initial reports came from social media posts by purported Stryker employees and a story in the Irish Examiner, describing wiped phones and computers displaying the Handala Hack logo. The group, active since at least 2023 and named after a Palestinian cartoon character symbolizing resistance, claimed responsibility on its Telegram channel and website. Handala cited the killing of 165 civilians at a girls' school in Iran by a US Tomahawk missile and prior US-Israeli operations against Iran as motivations.

Stryker acknowledged the incident on March 12, stating it faced a "global network disruption to our Microsoft environment as a result of a cyber attack." The company reported no evidence of ransomware or malware, and responders believe the disruption is contained to its internal Microsoft systems. Critical devices such as Lifepak for heart monitoring, Lifenet for patient data management, and Mako for surgeries continue to function normally. In a US Securities and Exchange Commission filing, Stryker noted it has no timeline for restoring normal operations.

Security researchers from Check Point, who track Handala as "Void Manticore," describe the group as affiliated with Iran's Ministry of Intelligence and Security. It has a history of destructive wiping attacks using custom tools, public software, and manual methods, often gaining access via underground services. Analysts suggest the attackers may have exploited Stryker's Microsoft InTune tool to issue deletion commands across its Windows network. Flashpoint researchers highlighted the symbolic targeting of Stryker, a key supplier of lifesaving devices to the US and allies, as a low-cost way for pro-Iranian actors to demonstrate reach while maintaining plausible deniability under a pro-Palestinian persona.

The breach, which reportedly affected tens of thousands of computers, underscores Iran's use of hacker groups for psychological retaliation when military options are limited.

Watu wanasema nini

Discussions on X highlight the Iran-linked Handala group's claimed wiper cyberattack on Stryker as retaliation for US-Israeli strikes, disrupting global operations but not critical medical devices. Sentiments include alarm over healthcare vulnerabilities and data destruction, geopolitical concerns, calls for bolstered US cybersecurity, and criticisms of escalating conflict. Technical analyses emphasize destructive intent via malware like Intune abuse over ransomware.

Makala yanayohusiana

Illustration depicting Iranian hackers targeting US critical infrastructure PLCs in water, energy, and wastewater systems, per joint US agency advisory.
Picha iliyoundwa na AI

US agencies warn of Iranian hackers targeting critical infrastructure PLCs

Imeripotiwa na AI Picha iliyoundwa na AI

The FBI, CISA, NSA, EPA, Department of Energy, and US Cyber Command issued a joint advisory warning of intensified cyberattacks by Iranian-affiliated hackers on programmable logic controllers (PLCs) in US critical infrastructure. Attacks since at least March 2026 have caused operational disruptions and financial losses in government facilities, wastewater, water, energy, and municipal systems, amid escalating tensions in the US-Israel war with Iran.

Iran's Islamic Revolutionary Guard Corps warned on Tuesday that it plans to target more than a dozen American companies across the Middle East beginning Wednesday. The list includes tech giants such as Apple, Google, Microsoft, IBM, Intel and Tesla, as well as Boeing. The IRGC cited retaliation for the killing of Iranian citizens amid the ongoing war with the US and Israel.

Imeripotiwa na AI

A hacking group known as Handala, believed to be affiliated with Iranian cyberintelligence units, has breached the personal email account of FBI Director Kash Patel. The group published photos and emails from the account as proof of the hack, which the FBI and Department of Justice have confirmed involved only historical personal information. The breach follows recent U.S. actions against the group's websites and Patel's public threats to pursue them.

Jumatano, 20. Mwezi wa tano 2026, 10:09:47

Microsoft warns of password reset exploits by hackers

Jumanne, 12. Mwezi wa tano 2026, 13:51:23

West pharmaceutical services discloses cybersecurity intrusion at conference

Jumanne, 12. Mwezi wa tano 2026, 13:24:19

Microsoft restructures Israeli office following data probe

Ijumaa, 8. Mwezi wa tano 2026, 19:01:28

Cyberattack disrupts canvas during us final exams

Jumapili, 29. Mwezi wa tatu 2026, 12:35:09

Iran launches missile attack on southern Israeli industrial center

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa