North America
Stryker Corporation
Operations at Stryker, America's largest medical device maker, remain disrupted more than a week after an Iran-linked cyberattack.
On March 11, Stryker Corporation confirmed it suffered a significant cyber incident that impacted its global Microsoft environment. The Iran-linked threat actor Handala claimed responsibility for the attack, which appears to be politically motivated and destructive in nature. Unlike typical financially driven incidents, Stryker stated there is no indication of ransomware or traditional malware, suggesting a deliberate data destruction campaign rather than extortion.
Reports indicate that attackers may have exploited Microsoft Intune, Stryker's mobile device management platform, to issue remote wipe commands across corporate devices worldwide. The group claims to have wiped thousands of servers and endpoints, including Windows laptops and smartphones, and alleges the exfiltration of up to 50 TB of corporate data.
How it could affect your business
It is important to note that relying on the belief that "the cloud has it covered" can leave organizations exposed when core systems are compromised. Even cloud-based environments such as Microsoft Azure, Microsoft 365 or Google Workspace can become single points of failure, making it critical to maintain independent, third-party backups. Distributing data across separate environments helps reduce single-cloud risk and ensures organizations can recover even when primary platforms are disrupted.
