MYNORTHWEST NEWS

Stryker cyberattack: Iran-linked hackers wipe 200,000 devices in global disruption

Mar 22, 2026, 5:01 AM | Updated: 4:32 pm

Stryker cyberattack...

In this photo illustration a young man types on an illuminated computer keyboard. (Photo: Sean Gallup, Getty Images)

(Photo: Sean Gallup, Getty Images)

An Iran-linked hacking group launched a massive cyberattack on Stryker Corporation, wiping more than 200,000 devices worldwide by exploiting the company’s own system, cybersecurity experts say.

The March 11 attack, attributed to the hacker group Handala, targeted administrator-level accounts and used them to issue remote wipe commands across Stryker’s global network. The breach impacted devices in 79 countries, including laptops, smartphones, and servers.

Experts said the attackers used a “living off the land” technique, meaning they leveraged legitimate internal tools instead of deploying malware or ransomware, allowing them to effectively turn Stryker’s systems against itself.

“This is a five-alarm fire,” Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency, told CBS Mornings. “It’s a wake-up call for every organization.”

Global impact of the Stryker cyberattack

The cyberattack caused widespread disruption to Stryker’s operations, taking internal systems offline and affecting ordering, shipping, and employee workflows worldwide.

“Handala was able to gain access to privileged, important administrator-level accounts within Stryker and then wipe out devices, hundreds of thousands of devices worldwide,” Krebs explained.

Employees were instructed to disconnect devices immediately, with some reporting their systems were erased in real time.

Handala also claimed it stole 50 terabytes of corporate data before launching the attack, though that has not been independently verified.

Investigators said the breach likely involved compromised credentials, potentially through phishing or other identity-based attacks, allowing hackers to gain access to high-level administrative controls.

“I think the conditions that created this attack on Stryker were probably independent anyway, in that some misconfiguration or other vulnerability contributed to the ability of Handala to get in.”

Medical devices not impacted

Despite the scale of the attack, Stryker said its connected medical devices, including LIFEPAK defibrillators, Mako surgical systems, and Vocera platforms, were not affected because they operate on separate networks.

Several hospitals and EMS providers pushed pause on using Stryker’s LIFENET system, which transmits patient data and vital signs. However, a person close to the matter told KIRO News Radio the system remained fully functional and Stryker did not recommend shutting the system down as it was not impacted by the cyber-attack or other disruption.

The source added the LIFENET system is a standalone product that does not use Stryker resources to function. The decision by some hospitals and EMS providers to temporarily suspend service did not impact care delivered and it required the EMS providers to call the emergency department at the receiving hospital and verbally communicate what the inbound situation was coming to their hospital.

Iran-linked motive and geopolitical context

There are reports that the group behind the attack claimed it was retaliation for a U.S.-Israeli missile strike in Iran, that reportedly killed more than 100 people.

Cybersecurity analysts said the Stryker cyberattack is one of the most significant and destructive cyber incidents targeting a U.S. company amid rising tensions involving Iran.

Recovery and cybersecurity concerns

Experts warn recovery from the Stryker attack could take months and cost millions, as the company works to restore systems and identify vulnerabilities.

Krebs said organizations across the U.S. should treat the incident as a warning.

“Every organization today, right now, yesterday even, needs to be running a full hands-on deck rehearsal of what happens if they have a similar event,” Krebs said. “Make sure the bad guys cannot easily get in and move throughout the entirety of an organization.”

Local healthcare systems monitoring

Healthcare and higher education sectors, which are often considered higher risk for cyberattacks according to cybercrime experts, are closely watching the situation.

A spokesperson for University of Washington (UW) Medicine said its operations and patient care remain unaffected. Washington State University also reported no impact, while UW has not yet responded to requests for comment.

Follow Luke Duecy on X. Read more of his stories here. Submit news tips here.

MyNorthwest News

Missing girl Everett...

Frank Lenzi

Missing girl: Everett Police search for Jocelyn Mora after she left Cascade High School with unknown male

Everett Police are asking for the public's help finding a girl who went missing from Cascade High School on March 26.

19 minutes ago

Seattle Fire Department drone...

Frank Lenzi

Seattle Fire Department proposes adding drones to emergency response fleet

The Seattle Fire Department (SFD) wants to start using drones.

32 minutes ago

human remains...

James Lynch

25-year-old Seattle mother faces manslaughter charge after her 2-year-old drowned

A 25‑year‑old Seattle mother, Nakeeya Arbogast, is facing a manslaughter charge after prosecutors said her 2‑year‑old son drowned.

36 minutes ago

corn I-5 semi-truck crash...

Frank Sumrall

Both ramps reopen after semi-truck crash spills corn across I-5 near JBLM

The southbound I-5 exit to Thorne Lane/JBLM has reopened after it was shut down early Thursday morning when a semi-truck carrying corn crashed into a ditch.

41 minutes ago

railroad fire...

KIRO 7 News Staff

Several homes lost; Level 3 ‘GO NOW’ evacuations in Grant County for Railroad Fire

At least seven homes have been lost, and Level 3 ‘GO NOW’ evacuations are continuing after the Railroad Fire started up in Grant County.

1 hour ago

stanwood plant layoff...

Jason Sutich

Plant-based food maker shutters Stanwood plant, laying off 123 workers

The No Meat Factory in Stanwood laid off 123 employees on Wednesday as the company plans to shutter its Washington location in September.

2 hours ago

Stryker cyberattack: Iran-linked hackers wipe 200,000 devices in global disruption