Entry / dwell
Exact compromise date and dwell time were not publicly established.
Destructive cyberattack · medtech incident reconstruction
On March 11, 2026, a destructive cyberattack disrupted Stryker's global Microsoft environment, manufacturing, ordering and shipping. Iran-linked Handala claimed responsibility. Stryker found no ransomware and later identified a malicious file; public reporting indicates abuse of privileged Microsoft administration and device-management capabilities.
Public-information cutoff · August 29, 2026Handala claimed the Stryker attack as geopolitical retaliation. The U.S. Justice Department described Handala domains as controlled by Iran's Ministry of Intelligence and Security and seized four domains on March 19.
The attack claim and Iran linkage are well reported; several technical scale claims—such as exact numbers of wiped devices and 50 TB stolen—originated with the actor and were not independently verified by Reuters.
Exact compromise date and dwell time were not publicly established.
Global Microsoft disruption; Handala claims responsibility the same day; SEC 8-K filed.
Daily customer guidance; by Mar. 17 Stryker said the incident was contained.
DOJ/FBI seized four Handala domains in a broader Iran-linked operation.
Most critical manufacturing restored; electronic ordering operational.
Global manufacturing, commercial, ordering and distribution systems restored.
Stryker disclosed when it identified the incident, but not the precise first alert.
Separate direct company disclosures, federal action and attacker claims.
Confirmed actions, not a generic response checklist.
The central lesson is to treat administrative platforms as high-consequence production systems.
Evidence rule: attacker claims are labeled as claims; company and government findings are presented separately. “No fine announced” is time-bound and does not predict future enforcement.