MYNORTHWEST NEWS

Stryker cyberattack: Iran-linked hackers wipe 200,000 devices in global disruption

Mar 22, 2026, 5:01 AM | Updated: 4:32 pm

Stryker cyberattack...

In this photo illustration a young man types on an illuminated computer keyboard. (Photo: Sean Gallup, Getty Images)

(Photo: Sean Gallup, Getty Images)

An Iran-linked hacking group launched a massive cyberattack on Stryker Corporation, wiping more than 200,000 devices worldwide by exploiting the company’s own system, cybersecurity experts say.

The March 11 attack, attributed to the hacker group Handala, targeted administrator-level accounts and used them to issue remote wipe commands across Stryker’s global network. The breach impacted devices in 79 countries, including laptops, smartphones, and servers.

Experts said the attackers used a “living off the land” technique, meaning they leveraged legitimate internal tools instead of deploying malware or ransomware, allowing them to effectively turn Stryker’s systems against itself.

“This is a five-alarm fire,” Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency, told CBS Mornings. “It’s a wake-up call for every organization.”

Global impact of the Stryker cyberattack

The cyberattack caused widespread disruption to Stryker’s operations, taking internal systems offline and affecting ordering, shipping, and employee workflows worldwide.

“Handala was able to gain access to privileged, important administrator-level accounts within Stryker and then wipe out devices, hundreds of thousands of devices worldwide,” Krebs explained.

Employees were instructed to disconnect devices immediately, with some reporting their systems were erased in real time.

Handala also claimed it stole 50 terabytes of corporate data before launching the attack, though that has not been independently verified.

Investigators said the breach likely involved compromised credentials, potentially through phishing or other identity-based attacks, allowing hackers to gain access to high-level administrative controls.

“I think the conditions that created this attack on Stryker were probably independent anyway, in that some misconfiguration or other vulnerability contributed to the ability of Handala to get in.”

Medical devices not impacted

Despite the scale of the attack, Stryker said its connected medical devices, including LIFEPAK defibrillators, Mako surgical systems, and Vocera platforms, were not affected because they operate on separate networks.

Several hospitals and EMS providers pushed pause on using Stryker’s LIFENET system, which transmits patient data and vital signs. However, a person close to the matter told KIRO News Radio the system remained fully functional and Stryker did not recommend shutting the system down as it was not impacted by the cyber-attack or other disruption.

The source added the LIFENET system is a standalone product that does not use Stryker resources to function. The decision by some hospitals and EMS providers to temporarily suspend service did not impact care delivered and it required the EMS providers to call the emergency department at the receiving hospital and verbally communicate what the inbound situation was coming to their hospital.

Iran-linked motive and geopolitical context

There are reports that the group behind the attack claimed it was retaliation for a U.S.-Israeli missile strike in Iran, that reportedly killed more than 100 people.

Cybersecurity analysts said the Stryker cyberattack is one of the most significant and destructive cyber incidents targeting a U.S. company amid rising tensions involving Iran.

Recovery and cybersecurity concerns

Experts warn recovery from the Stryker attack could take months and cost millions, as the company works to restore systems and identify vulnerabilities.

Krebs said organizations across the U.S. should treat the incident as a warning.

“Every organization today, right now, yesterday even, needs to be running a full hands-on deck rehearsal of what happens if they have a similar event,” Krebs said. “Make sure the bad guys cannot easily get in and move throughout the entirety of an organization.”

Local healthcare systems monitoring

Healthcare and higher education sectors, which are often considered higher risk for cyberattacks according to cybercrime experts, are closely watching the situation.

A spokesperson for University of Washington (UW) Medicine said its operations and patient care remain unaffected. Washington State University also reported no impact, while UW has not yet responded to requests for comment.

Follow Luke Duecy on X. Read more of his stories here. Submit news tips here.

MyNorthwest News

Longview fire air quality...

Frank Lenzi

Massive scrap pile fire in Longview triggers air quality warning; residents urged to stay indoors

A large scrap pile fire at PNW Metals in Longview sent a massive plume of smoke into the sky Saturday, prompting fire officials to issue an air quality warning urging nearby residents to stay indoors. The Longview Fire Department and Cowlitz 2 Fire & Rescue were on scene as of Saturday afternoon and anticipated remaining […]

13 hours ago

world cup hotel bookings...

Tom Brock

Unauthorized parachutists caught on video jumping from Space Needle

Tourists at Seattle's Space Needle got a little more than the view they expected Friday, when two men parachuted off the iconic structure's Observation Deck.

16 hours ago

courthouse escapee snohomish county...

KIRO 7 News Staff

Deputies looking for Snohomish County courthouse escapee

The Snohomish County Sheriff’s Office is looking for a 39-year-old who escaped the courthouse Friday afternoon when a judge told him he would be taken into custody.

21 hours ago

plane crash san juan islands...

Lexi Herda, KIRO 7 News

All but 3 passengers released from hospital after floatplane crash in San Juan Islands

All but three people have been released from the hospital after their floatplane crashed in the San Juan Islands on Thursday.

21 hours ago

Parkinson's...

Luke Duecy

‘It’s going to come quicker than we think’: Parkinson’s advocate shares hope for treatment as Allen Institute launches AI-powered initiative

When Lisa Volenec was diagnosed with Parkinson's disease, she struggled to accept a future shaped by a neurological disorder with no cure.

24 hours ago

pho restaurant...

MyNorthwest Staff

Beloved pho restaurant closing on Bainbridge Island after nearly 20 years

A pho restaurant that has served the Bainbridge Island community for nearly two decades is closing its doors as its owner has decided to retire.

1 day ago

Stryker cyberattack: Iran-linked hackers wipe 200,000 devices in global disruption