MYNORTHWEST NEWS

Stryker cyberattack: Iran-linked hackers wipe 200,000 devices in global disruption

Mar 22, 2026, 5:01 AM | Updated: 4:32 pm

Stryker cyberattack...

In this photo illustration a young man types on an illuminated computer keyboard. (Photo: Sean Gallup, Getty Images)

(Photo: Sean Gallup, Getty Images)

An Iran-linked hacking group launched a massive cyberattack on Stryker Corporation, wiping more than 200,000 devices worldwide by exploiting the company’s own system, cybersecurity experts say.

The March 11 attack, attributed to the hacker group Handala, targeted administrator-level accounts and used them to issue remote wipe commands across Stryker’s global network. The breach impacted devices in 79 countries, including laptops, smartphones, and servers.

Experts said the attackers used a “living off the land” technique, meaning they leveraged legitimate internal tools instead of deploying malware or ransomware, allowing them to effectively turn Stryker’s systems against itself.

“This is a five-alarm fire,” Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency, told CBS Mornings. “It’s a wake-up call for every organization.”

Global impact of the Stryker cyberattack

The cyberattack caused widespread disruption to Stryker’s operations, taking internal systems offline and affecting ordering, shipping, and employee workflows worldwide.

“Handala was able to gain access to privileged, important administrator-level accounts within Stryker and then wipe out devices, hundreds of thousands of devices worldwide,” Krebs explained.

Employees were instructed to disconnect devices immediately, with some reporting their systems were erased in real time.

Handala also claimed it stole 50 terabytes of corporate data before launching the attack, though that has not been independently verified.

Investigators said the breach likely involved compromised credentials, potentially through phishing or other identity-based attacks, allowing hackers to gain access to high-level administrative controls.

“I think the conditions that created this attack on Stryker were probably independent anyway, in that some misconfiguration or other vulnerability contributed to the ability of Handala to get in.”

Medical devices not impacted

Despite the scale of the attack, Stryker said its connected medical devices, including LIFEPAK defibrillators, Mako surgical systems, and Vocera platforms, were not affected because they operate on separate networks.

Several hospitals and EMS providers pushed pause on using Stryker’s LIFENET system, which transmits patient data and vital signs. However, a person close to the matter told KIRO News Radio the system remained fully functional and Stryker did not recommend shutting the system down as it was not impacted by the cyber-attack or other disruption.

The source added the LIFENET system is a standalone product that does not use Stryker resources to function. The decision by some hospitals and EMS providers to temporarily suspend service did not impact care delivered and it required the EMS providers to call the emergency department at the receiving hospital and verbally communicate what the inbound situation was coming to their hospital.

Iran-linked motive and geopolitical context

There are reports that the group behind the attack claimed it was retaliation for a U.S.-Israeli missile strike in Iran, that reportedly killed more than 100 people.

Cybersecurity analysts said the Stryker cyberattack is one of the most significant and destructive cyber incidents targeting a U.S. company amid rising tensions involving Iran.

Recovery and cybersecurity concerns

Experts warn recovery from the Stryker attack could take months and cost millions, as the company works to restore systems and identify vulnerabilities.

Krebs said organizations across the U.S. should treat the incident as a warning.

“Every organization today, right now, yesterday even, needs to be running a full hands-on deck rehearsal of what happens if they have a similar event,” Krebs said. “Make sure the bad guys cannot easily get in and move throughout the entirety of an organization.”

Local healthcare systems monitoring

Healthcare and higher education sectors, which are often considered higher risk for cyberattacks according to cybercrime experts, are closely watching the situation.

A spokesperson for University of Washington (UW) Medicine said its operations and patient care remain unaffected. Washington State University also reported no impact, while UW has not yet responded to requests for comment.

Follow Luke Duecy on X. Read more of his stories here. Submit news tips here.

Please follow our Community Guidelines

MyNorthwest News

whatcom county...

KIRO 7 News Staff

Whatcom County man found to have died from a blow to the head

Cole Hilton was found unconscious with a blow to the head on the side of the road in Whatcom County.

14 minutes ago

baggage claim sign...

James Lynch

Suspicious item prompts closure of SEA baggage claim; reopens after bomb squad clears package

A suspicious item prompted a brief closure of several baggage claim carousels and nearby doors at Seattle-Tacoma International Airport (SEA).

47 minutes ago

cost guard plane crash...

Brooke Griffin, KIRO 7 News

Coast Guard details rescue of Kenmore Air floatplane crash survivors

KIRO 7 is learning more about the emergency response to the Kenmore Air floatplane crash off the San Juan Islands on Thursday.

2 hours ago

car fire...

MyNorthwest Staff

All northbound I-5 lanes reopen after 5-vehicle crash sparked car fire

All lanes on I-5 north have reopened after they were blocked due to a car fire caused by a crash involving two semitrucks and three cars.

2 hours ago

baby doll...

Katrina Guischard

A 3-year-old boy and his baby doll are showing millions what it means to raise empathetic kids

A toddler is teaching the internet a lesson about empathy with a baby doll.

3 hours ago

Kennewick locust grove fire...

KIRO 7 News Staff

More than 750 acres burned; residents evacuated for Locust Grove Fire near Kennewick

State fire assistance was mobilized overnight to support local firefighters working to contain the Locust Grove Fire in Benton County, near Kennewick.

5 hours ago

Stryker cyberattack: Iran-linked hackers wipe 200,000 devices in global disruption