Stryker A.I CyberSecurity Scoring
Stryker
Company Information
Website:http://www.stryker.com
Employees number:51,473
Number of followers:1,856,594
NAICS:3391
Industry Type:Medical Equipment Manufacturing
Homepage:stryker.com
Stryker Risk Score (AI oriented)
Between 0 and 549
StrykerMedical Equipment Manufacturing
Updated:
13/07/2026
13/07/2026
521/1000
Critical
C
Stryker Global Score (TPRM)
xxxx
StrykerMedical Equipment Manufacturing
Score locked

StrykerCritical
Current Score
521C (CRITICAL)
01000
23 incidents
-24.83 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
533
JULY 2026
531
Cyber Attack
10 Jul 2026 • Stryker
Stryker Corporation: GigaWiper: Modular Windows Backdoor Combines Disk Wiper, Fake Ransomware, Spyware
GigaWiper: A Modular Windows Backdoor with Destructive Capabilities
521
CRITICAL-10
STR1783982145
GigaWiper: A Modular Windows Backdoor with Destructive Capabilities
On July 9, 2026, Microsoft’s threat intelligence team released a detailed analysis of GigaWiper, a sophisticated Windows backdoor that blends surveillance and irreversible destruction into a single implant. Unlike traditional wipers, GigaWiper is a full-featured espionage tool that can silently monitor networks before executing one of three distinct disk-erasure commands all without deploying additional payloads.
### Key Features and Attack Mechanics
GigaWiper, written in Go, integrates components from at least three older malware families:
- Command 1 (Raw Disk Wiper): Uses Windows Management Instrumentation (WMI) to overwrite all physical disks, erasing partition metadata and raw content with randomized patterns to evade detection.
- Command 3 (Fake Ransomware): Mimics ransomware by encrypting files with a .candy extension and displaying a ransom note but the keys are discarded, making recovery impossible. This module is derived from Crucio ransomware, previously linked to Iran’s CyberAv3ngers (IRGC-CEC).
- Command 12 (Multi-Pass Wiper): A Go-based reimplementation of FlockWiper, targeting the Windows drive with alternating overwrite patterns to prevent forensic recovery.
The malware also includes surveillance capabilities, such as screenshot capture, VNC-based remote desktop access, PowerShell execution, and file exfiltration via MinIO. A dormant keylogger module (Command 11) suggests further development.
### Command-and-Control (C2) Infrastructure
GigaWiper abuses legitimate enterprise tools for C2 communication:
- RabbitMQ (AMQP protocol) for operator commands.
- Redis for status updates.
- MinIO (S3-compatible storage) for data exfiltration.
Active C2 servers were identified at:
- 185.182.193[.]21 (RabbitMQ on port 554455445544, Redis on 754275427542)
- 212.8.248[.]104
### Persistence and Evasion Techniques
- OneDrive Impersonation: Creates a scheduled task named "OneDrive Update" and a registry key (HKCU\SOFTWARE\OneDrive\Environment) to maintain persistence.
- Firewall Rule Spoofing: Adds a rule named Microsoft.Windows.CloudExperienceHost to bypass detection.
- Behavioral Camouflage: Uses GUID-like directory names with non-hex characters to evade behavioral detection.
### Attribution and Geopolitical Context
While Microsoft did not attribute GigaWiper to a specific actor, Binary Defense and Google’s Threat Intelligence Group linked it to an Iran-nexus cluster responsible for BLUEWIPE and SEWERGOO in June 2025. The malware’s Crucio-derived module further ties it to CyberAv3ngers, a group sanctioned by the U.S. Treasury in 2024.
GigaWiper’s emergence aligns with a surge in Iranian wiper attacks following Operation Epic Fury (U.S.-Israel strikes on Iran in early 2026). Other Iran-linked groups, such as Handala Hack and Cavern Manticore, have conducted similar destructive campaigns, including the Stryker Corporation wipe in March 2026.
### Detection and Defense Priorities
Microsoft has released YARA rules and Defender signatures for GigaWiper. Key detection methods include:
- Monitoring for unexpected "OneDrive Update" scheduled tasks or Microsoft.Windows.CloudExperienceHost firewall rules.
- Auditing RabbitMQ, Redis, and MinIO traffic for unauthorized connections.
- Treating ransomware-like activity without ransom notes as a potential wiper attack.
- Ensuring offline, immutable backups are in place, as GigaWiper’s disk-wiping methods leave no recovery path.
First observed in October 2025, GigaWiper remained undetected for months before researchers connected it to earlier Iran-linked activity. Its modular design and abuse of legitimate tools make it a particularly challenging threat for defenders.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
519
MAY 2026
566
Cyber Attack
20 May 2026 • Stryker
Stryker: West Pharma says fully operational after cyberattack, sees no hit to 2026 forecast
West Pharmaceutical Services Cyberattack
555
CRITICAL-11
STR1779337852
West Pharmaceutical Services Recovers from Cyberattack, Restores Global Operations
West Pharmaceutical Services has fully restored operations across its global sites following a cybersecurity incident detected earlier this month. The medical equipment manufacturer first identified unauthorized activity on May 4 and confirmed a material cyberattack on May 7, which involved data exfiltration and system lockdowns.
In response, the company took systems offline worldwide, notified law enforcement, and engaged external cybersecurity experts to contain the breach. By May 20, West Pharmaceutical announced it had successfully restarted core processes including manufacturing, shipping, and supply chain operations across all locations.
While the investigation remains ongoing, the company stated it has not detected further unauthorized access. Analysts at Evercore ISI noted West Pharmaceutical’s swift recovery, citing its ability to leverage 24/7 operations and flex capacity to mitigate disruptions. The incident is not expected to have a material impact on the company’s 2026 financial outlook, including second-quarter or full-year forecasts.
The attack follows a recent wave of cybersecurity incidents in the healthcare sector, with Stryker, Intuitive Surgical, and Medtronic reporting similar breaches in March and April. West Pharmaceutical continues to assess the extent of data affected as part of its review.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
APRIL 2026
567
Cyber Attack
01 Apr 2026 • Stryker
Stryker: Weak authentication, exposed ICS environments heighten concerns over Iranian cyber intrusions into US critical infrastructure
Iranian Cyber Actors Exploit Weak Security in U.S. Critical Infrastructure
556
CRITICAL-11
STR1779452900
Iranian Cyber Actors Exploit Weak Security in U.S. Critical Infrastructure
Iran-aligned cyber threat groups are intensifying efforts to target poorly secured U.S. critical infrastructure, leveraging gaps in basic cybersecurity practices to infiltrate operational technology (OT) systems. A recent analysis by the Foundation for Defense of Democracies (FDD) reveals that attackers have accessed exposed industrial environments, including gas station tank gauge systems across multiple states, by exploiting default or absent passwords. While these intrusions have not yet caused physical disruptions such as altering fuel levels they have manipulated display data, potentially obscuring critical issues like leaks or empty tanks.
The campaign reflects a broader pattern of Iranian-linked groups probing internet-facing industrial control systems (ICS), particularly where authentication and network segmentation are weak. Though many incidents have resulted in limited operational impact, U.S. officials warn that the intent is evolving toward disruption and psychological pressure, especially in sectors with outdated or minimal security controls. Targets include energy, water, and other essential services, with adversaries frequently exploiting vulnerabilities in programmable logic controllers (PLCs) and supervisory control systems.
Iranian threat actors, while less sophisticated than their Chinese or Russian counterparts, combine cyber operations with influence campaigns to maximize societal impact. Groups linked to the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security often operate through hacktivist fronts, as seen in past incidents involving high-profile targets, including an attempted breach of FBI Director Kash Patel and an attack on medical technology firm Stryker.
Recent examples highlight Iran’s persistent but often overstated claims of success. In April, the group Ababil of Minab took credit for an attack on the Los Angeles transit authority, asserting control over internal systems though officials confirmed only partial access with no disruption to services. Similarly, the IRGC-affiliated APTIRAN previously claimed to have compromised gas station systems in Pennsylvania, though no public confirmation of the breach was provided.
The FDD report underscores that many exploited systems rely on default credentials or lack password protection entirely, emphasizing the need for stronger baseline security. The U.S. government’s Secure by Design initiative aims to address these vulnerabilities by working with vendors to enforce security-by-default measures, such as requiring password changes during installation.
Separately, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation active since May 2025. The platform, used by ransomware gangs and other threat actors, abused Microsoft’s code-signing infrastructure to distribute malicious software, including strains like Oyster, Lumma Stealer, and Akira, infecting thousands of systems globally.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
586
Cyber Attack
30 Mar 2026 • Stryker
Stryker and Jones Day: In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack
Cybersecurity Roundup: AI Risks, Mac Malware, and Major Breaches Dominate the Week
567
CRITICAL-19
DOWSTR1775838732
Cybersecurity Roundup: AI Risks, Mac Malware, and Major Breaches Dominate the Week
This week’s cybersecurity landscape was marked by high-profile threats, regulatory discussions, and industry responses to emerging risks. Here are the key developments:
AI Cybersecurity Concerns Prompt Fed Discussions
Federal Reserve Chair Jerome Powell and Treasury Secretary Scott Bessent met with major U.S. banks to assess cyber risks posed by Anthropic’s Mythos, a high-reasoning AI model with advanced exploit-chaining capabilities. Currently restricted to select partners under Project Glasswing, Mythos raises concerns about autonomous cyber threats.
New macOS Stealer Targets High-Value Crypto Wallets
A hacker, previously active in underground forums, resurfaced with NotnullOSX, a macOS stealer targeting victims holding over $10,000 in cryptocurrency. Detected in Vietnam, Taiwan, and Spain on March 30, 2026, the malware spreads via fake Google documents and malicious DMG files, gaining Full Disk Access to steal iMessages, browser credentials, and crypto wallets.
Japanese Corporations Form Cybersecurity Alliance
Ten major Japanese firms, including Suntory, Kao, Asahi, and NTT, are launching a joint organization to share threat intelligence and develop cybersecurity talent. The initiative follows a September 2025 breach at Asahi that disrupted supply chains and exposed vulnerabilities in interconnected networks.
Law Firm Jones Day Hit by Ransomware Attack
The Silent Ransom Group (aka Luna Moth) infiltrated Jones Day using social engineering, accessing records of 10 clients and leaking sensitive documents after the firm refused a $13 million ransom demand.
Spyware Founder Receives Lenient Sentence
Bryan Fleming, creator of the surveillance tool pcTattletale, was sentenced to time served and a $5,000 fine the first federal conviction of a spyware operator in over a decade. Despite facilitating illegal surveillance and suffering a data leak, Fleming avoided additional prison time.
DocketWise Breach Exposes 116,000 Individuals
Austin-based legal tech firm DocketWise confirmed a 2025 breach exposing personal data of 116,000 individuals after unauthorized access to a third-party repository containing unstructured client records.
Cloudflare Accelerates Post-Quantum Security Transition
Following Google’s advancements in quantum algorithms, Cloudflare moved its post-quantum security deadline to 2029. The shift responds to research suggesting neutral atom computers could break RSA-2048 and P-256 encryption with fewer qubits than previously estimated.
HackerOne Pauses Bug Bounty Submissions Amid AI Surge
The Internet Bug Bounty (IBB) program halted new submissions on March 27, 2026, citing an overwhelming influx of AI-assisted vulnerability reports. While existing submissions are processed, organizers plan to restructure incentives to balance discovery and remediation.
Windows Zero-Day Exploit Leaked After Microsoft Dispute
A researcher publicly released BlueHammer, a Windows zero-day exploiting a race condition in Microsoft Defender to gain SYSTEM privileges. The disclosure followed a breakdown in communication with Microsoft, which has yet to patch the flaw or assign a CVE.
Hacker Claims Breach of China’s Supercomputing Center
A hacker known as FlamingChina alleged access to the National Supercomputing Center in Tianjin, extracting 10 petabytes of data over six months via a compromised VPN. Leaked samples include classified documents and defense equipment simulations, though some experts question the authenticity of the claims.
Stryker Confirms Financial Impact from Cyberattack
Medical device manufacturer Stryker reported that a March 2026 cyberattack caused operational disruptions, materially affecting Q1 financial results. While systems have been restored, the investigation into data exposure and regulatory implications remains ongoing. The company reaffirmed its full-year guidance.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
597
Cyber Attack
27 Mar 2026 • Stryker
Stryker and U.S. Justice Department: FBI director emails breached by Iran-linked hackers — what happened and how to protect yourself
Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos
586
CRITICAL-11
CRISTR1774636436
Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos
On March 27, 2026, the Iranian-linked hacktivist group Handala Hack Team claimed responsibility for accessing the personal emails of FBI Director Kash Patel, publishing alleged photos and documents as proof. The leaked images dated between 2010 and 2019 depict Patel in personal settings, including vacations and social gatherings. The U.S. Justice Department confirmed the breach, verifying the authenticity of the materials.
Handala framed the attack as retaliation for the ongoing U.S.-Iran conflict and the FBI’s $10 million bounty for information on its members. The group boasted of bypassing the FBI’s security systems, though officials clarified that only Patel’s personal Gmail account not government systems was compromised. The incident highlights persistent risks tied to officials using personal emails for professional matters.
About Handala Hack Team
Active since 2023 and linked to Iran’s Ministry of Intelligence and Security, Handala specializes in disruptive cyberattacks, often targeting Israeli and Western entities. The group has previously breached Lockheed Martin and executed a 200,000-user data wipe at medical tech firm Stryker, leveraging malware designed to delete or expose sensitive data.
The breach underscores vulnerabilities in personal email security, even among high-profile officials.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
562
Cyber Attack
16 Mar 2026 • Stryker
Stryker: Iranian hackers responsible for LA transit system breach, Israeli researchers say
Disruptive Cyberattack on Los Angeles County Metropolitan Transportation Authority (LACMTA)
551
CRITICAL-11
STR1779805618
Iranian Hackers Linked to Disruptive LA Transit System Breach, Israeli Researchers Confirm
Israeli cybersecurity firm Gambit Security has attributed a March cyberattack on the Los Angeles County Metropolitan Transportation Authority (LACMTA) to Iranian state-linked hackers, following an investigation that uncovered 700GB of stolen data including emails and backups left exposed online. The breach, detected around March 16, forced the transit agency to temporarily shut down parts of its network, though train and bus operations remained unaffected. However, local reports indicated disruptions to arrival screens and transit card payment systems.
The attack was claimed by Ababil of Minab, a pro-Iran hacking group named after a 2023 school bombing in Iran. While U.S. and Israeli researchers have long suspected Ababil of acting as a front for Iranian intelligence, Gambit’s findings provide forensic evidence linking the group to Tehran. Eyal Sela, Gambit’s director of threat intelligence, stated that the connection to the Iranian state had been a "working assumption" but is now supported by digital traces.
The LACMTA confirmed the incident in a March statement, noting an ongoing investigation with law enforcement and cybersecurity experts but declined to comment on attribution. The FBI acknowledged awareness of the breach and said it was coordinating with partners, while CISA and Iran’s UN mission did not respond to requests for comment.
Ababil has also claimed responsibility for recent attacks on South Florida’s Tri-Rail, vehicle tracking firm Vyncs, and Saudi infrastructure company Unimac. Tri-Rail confirmed a breach but described the stolen data as non-critical, while Vyncs reported its incident on April 2, with the FBI involved in both cases. Unimac did not respond to inquiries.
Gambit’s analysis suggests Ababil has targeted additional organizations including an Israeli media outlet, an Israeli educational institution, and a Turkish insurance brokerage though details remain undisclosed. The group’s activity aligns with a broader surge in Iranian cyber operations since late February, coinciding with heightened tensions following the Israel-Hamas war. Recent incidents include a cyberattack on medical device manufacturer Stryker, the leak of FBI Director Kash Patel’s emails, and alleged tampering with U.S. gas station fuel gauges, as reported by CNN.
The LACMTA breach underscores the growing threat of state-backed cyber sabotage targeting critical infrastructure, with Iranian hackers increasingly leveraging proxy groups to obscure their involvement.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
669
Breach
13 Mar 2026 • Stryker
Shoppers Drug Mart, President’s Choice, Loblaw, No Frills and PC Optimum: “Threat Actor” on the dark web claims Loblaw’s “low-level” data breach is a much larger threat
Alleged Massive Data Breach at Loblaw
606
CRITICAL-63
NO-SHOPRELOB1773534483
Loblaw Faces Alleged Massive Data Breach as Threat Actor Demands Response
A threat actor operating under the handle "igotafeeling" on the DarkWeb Informer forum has claimed to have breached Loblaw, Canada’s largest food and pharmacy retailer, which owns brands like President’s Choice, No Frills, Shoppers Drug Mart, Real Canadian Superstore, and the PC Optimum loyalty program.
The actor alleges possession of over 1.8 billion records, including:
- 75.1 million Salesforce customer records (names, emails, phone numbers, addresses, loyalty IDs, and health card numbers)
- 724.9 million Shoppers Drug Mart records (passwords, tokens, loyalty IDs, payment details, and full credit card numbers with expiry dates)
- 129.9 million pharmacy fill requests (prescription numbers and patient IDs)
- 120.4 million e-commerce fraud-feed records (payment card BINs, last-four digits, and expiry dates)
- 20.2 million Delivery Ops Portal records (orders, deliveries, and postal codes)
- 3,014 GitLab projects containing Loblaw’s full source code
- 19.3 million Oracle identity records (MFA device details and credentials)
- 55.3 million marketing and email records across 673 tables
The threat actor has given Loblaw until March 19 to respond, accusing the company of "ghosting" them and dismissing customer and investor concerns. They have also invited media organizations to verify the data’s authenticity.
In response, Loblaw issued a March 12 press release, labeling the incident a "low-level data breach" and stating that only "basic customer information" (names, phone numbers, and emails) may have been accessed. The company explicitly denied evidence of financial or credit card data compromise directly contradicting the threat actor’s claims.
While the breach remains unverified, the scale of the alleged exposure if confirmed would rank among the largest in Canadian history. The situation mirrors past high-profile breaches (e.g., T-Mobile, Equifax, Capital One), where initial corporate statements downplayed impact before later revelations proved otherwise.
Loblaw customers with PC Optimum accounts, Shoppers Drug Mart loyalty cards, or prescription histories may be affected if the claims hold true. The deadline for Loblaw’s response is six days away.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
703
Cyber Attack
11 Mar 2026 • Stryker
Stryker: Suspected Iranian cyberattack hits Stryker, disrupting systems across medical device company
Iran-Linked Cyberattack Disrupts Stryker, Global Medical Device Manufacturer
669
CRITICAL-34
STR1780043335
Iran-Linked Cyberattack Disrupts Stryker, Global Medical Device Manufacturer
A suspected cyberattack attributed to an Iran-affiliated hacking group has disrupted operations at Stryker, a Michigan-based global medical device manufacturer. The attack, reported on June 10, 2024, caused widespread system outages across the company’s network, affecting facilities including its Portage, Michigan headquarters.
Employees and contractors reported seeing the hacking group’s logo appear on company devices during the incident. The group claimed responsibility in a post on X (formerly Twitter), citing retaliation for an alleged attack on an Iranian school in Minab. Stryker confirmed the disruption and is working to restore affected systems.
The incident highlights growing cybersecurity risks in the healthcare and medical device sectors, where operational disruptions can have cascading effects on patient care and supply chains. No details on data breaches or patient impact have been disclosed.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Cyber Attack
11 Mar 2026 • Stryker
Stryker: Cork-based Stryker hit with cyber attack linked to Iranian-backed group
Stryker Hit by Destructive Cyberattack Linked to Iranian-Backed Group
669
CRITICAL-34
STR1773240573
Stryker Hit by Destructive Cyberattack Linked to Iranian-Backed Group
A global medical technology firm, Stryker, suffered a devastating wiper cyberattack on Wednesday, suspected to be orchestrated by Handala Hack, a group with ties to the Iranian regime. The attack targeted the company’s Cork, Ireland headquarters, where up to 5,000 employees including 4,000 in Cork are based, crippling critical IT systems and manufacturing operations.
The National Cyber Security Centre (NCSC) in Dublin is responding to the incident, which involved the permanent deletion of data from infected systems a hallmark of wiper attacks, typically politically motivated rather than financially driven. Devices connected to Stryker’s network, including employee phones with Outlook installed, were wiped, and login screens were defaced with the Handala logo, a symbol of Palestinian resistance.
The attack has disrupted production of Stryker’s medical devices, with some manufacturing machines still operational but their long-term functionality uncertain. Staff were instructed to avoid connecting to the company’s network via any device, including mobile apps like Microsoft Teams and Outlook, while recovery efforts continue. Employees have been sent home, relying on WhatsApp groups for updates.
Stryker, which operates six manufacturing sites and three innovation centers in Ireland, is one of the country’s largest medical tech employers. The company confirmed the incident in a staff memo, stating that security experts and law enforcement are involved in the response, emphasizing that sites and personnel remain safe while efforts focus on restoring systems.
Handala Hack, linked to Iran’s cyber warfare campaigns, has recently targeted Israeli, Jordanian, and Saudi oil and gas facilities, as well as the Academy of the Hebrew Language, according to Israeli media. The Israeli National Cyber Directorate has warned of a surge in Iranian cyberattacks against civilian companies, suggesting Stryker may have been targeted due to its business ties with Israel.
The attack underscores Iran’s expanding cyber-economic warfare, extending beyond regional conflicts to global operations. With Ireland serving as Stryker’s largest hub outside the U.S., the incident highlights the growing threat of state-backed cyber sabotage in critical industries.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Cyber Attack
11 Mar 2026 • Stryker
Stryker: Medical technology company Stryker disrupted globally by cyberattack
Stryker Hit by Global Cyberattack Disrupting Medical Technology Services
669
CRITICAL-34
STR1773354343
Stryker Hit by Global Cyberattack Disrupting Medical Technology Services
On March 11, Stryker, a leading medical technology provider serving hospitals worldwide, confirmed a global cyberattack that disrupted its operations. The company reported that its Microsoft environment was compromised but found no evidence of ransomware or malware. Stryker stated the incident had been contained.
John Riggi, the American Hospital Association’s (AHA) national advisor for cybersecurity and risk, acknowledged the attack, noting ongoing collaboration with hospitals and federal agencies to assess the threat’s scope. While no direct disruptions to U.S. hospital operations have been reported, Riggi warned that impacts could emerge as hospitals evaluate Stryker’s services, technology, and supply chain particularly if the disruption persists.
The incident highlights the vulnerability of critical healthcare infrastructure to cyber threats, even in the absence of traditional ransomware tactics. Further details on the attack’s origin and full impact remain under investigation.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2026
714
Cyber Attack
01 Mar 2026 • Stryker
Stryker and Rockwell Automation: Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn
U.S. Government Warns of Iranian Cyberattacks Targeting Critical Infrastructure
702
CRITICAL-12
STRROC1775594506
U.S. Government Warns of Iranian Cyberattacks Targeting Critical Infrastructure
U.S. intelligence and cybersecurity agencies issued an urgent joint alert on Tuesday, warning that Iranian government-linked hackers are conducting disruptive cyberattacks against American energy and water infrastructure. The attacks, which have intensified since the onset of U.S.-Israel military strikes against Iran, specifically target operational technology (OT) systems, including programmable logic controllers (PLCs) from Rockwell Automation/Allen-Bradley.
The alert issued by the FBI, NSA, CISA, EPA, Energy Department, and Cyber Command details how Iran-affiliated advanced persistent threat (APT) actors have exploited internet-facing OT devices, leading to disruptions in critical infrastructure sectors. These attacks involve malicious interactions with project files and manipulation of human-machine interface (HMI) and supervisory control and data acquisition (SCADA) systems, resulting in operational disruptions and financial losses for victims.
Since March, the agencies have identified new victims tied to an Iranian APT group, with at least 75 devices compromised in earlier campaigns. Affected sectors include government services, water and wastewater systems (WWS), and energy. Some organizations have already experienced operational downtime due to the attacks.
This latest wave follows previous warnings about Iranian cyber threats, including a 2023 attack on a Pennsylvania water facility. Recent targets have also included major corporations like medtech firm Stryker and local government entities. Separately, the FBI had previously flagged Iranian hackers using Telegram to distribute malware, though that campaign predates the current conflict.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
750
Breach
28 Feb 2026 • Stryker
Medtronic, Intuitive Surgical and Stryker: Medtronic discloses cybersecurity breach in certain IT systems
Medtronic Unauthorized Access to Corporate IT Systems
702
HIGH-48
MEDINTSTR1777141606
Medtronic Confirms Unauthorized Access to Corporate IT Systems in Cybersecurity Incident
Medtronic, a leading medical technology company, disclosed that an unauthorized party accessed data within certain corporate IT systems. The breach, detected during routine monitoring, prompted an immediate response, including containment measures and the activation of incident response protocols. The company has engaged cybersecurity experts to investigate and remediate the incident while working to determine whether personal information was compromised.
Medtronic emphasized that the breach did not affect product functionality, patient safety, customer connections, manufacturing, or distribution operations. Its corporate IT networks remain separate from systems supporting medical devices, production, and hospital networks, minimizing potential disruptions. The company does not anticipate a material impact on its business or financial performance but continues to assess security enhancements.
This incident follows recent cyberattacks on other major medtech firms. In February 2026, Iranian-backed hacktivists executed a "wiper attack" against Stryker, erasing data in retaliation for U.S. and Israeli actions. Shortly after, Intuitive Surgical reported a breach stemming from a phishing incident that exposed internal IT applications. At this time, there is no evidence linking these breaches to a coordinated campaign or shared motives.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
749
Breach
04 Feb 2026 • Stryker
Social Security Administration: The Social Security data breach is a national-security disaster that could hurt Americans for the rest of their lives: whistleblower
Potential Massive Social Security Data Breach
703
CRITICAL-46
SOC1770609457
Former SSA Chief Data Officer Warns of Massive Social Security Data Breach
A whistleblower has raised alarms over a potential national security disaster involving the exposure of sensitive Social Security data for every American with or who ever had a Social Security number (SSN). Chuck Borges, the former chief data officer of the Social Security Administration (SSA), resigned in August and filed a complaint alleging that employees of the Department of Government Efficiency (DOGE) uploaded a copy of the SSA’s database to an unsecured cloud environment.
According to Borges, the breach if confirmed could leave personal data, including names, SSNs, and addresses, vulnerable to fraud and exploitation, with long-term consequences for millions of Americans. He has called for a congressional investigation into the alleged mismanagement, framing the incident as a severe threat to national security.
The SSA has not publicly confirmed the breach, but the whistleblower’s claims highlight critical vulnerabilities in government data handling. If verified, the exposure could have far-reaching implications for identity theft, financial fraud, and cybersecurity risks across the U.S. The incident underscores ongoing concerns about federal agencies’ ability to safeguard sensitive citizen data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
771
Cyber Attack
01 Feb 2026 • Stryker
Stryker: Iran-linked ransomware gang targeted US healthcare org amid military conflict
Iranian-Linked Pay2Key Ransomware Targets U.S. Healthcare Organization
749
CRITICAL-22
STR1774369485
Iranian-Linked Pay2Key Ransomware Targets U.S. Healthcare Organization Amid Rising Cyber Conflict
In late February, an unnamed U.S. healthcare organization fell victim to a ransomware attack by Pay2Key, a strain linked to Iranian state-affiliated cyber actors. The incident, investigated by Beazley Security and Halcyon Ransomware Research Center, revealed significant upgrades to the ransomware, making it harder to detect and more destructive.
Unlike typical financially motivated attacks, this intrusion showed no evidence of data exfiltration a departure from previous Pay2Key operations, which U.S. intelligence agencies had tied to espionage. Researchers noted the group’s activity surged following recent U.S.-Iran military tensions, suggesting motivations beyond profit, including strategic disruption.
The attackers compromised an administrative account days before deploying the ransomware, then attempted to erase logs to cover their tracks. Cynthia Kaiser, Halcyon’s senior vice president and former FBI Cyber Division official, questioned whether the attack was timed to exploit geopolitical chaos, emphasizing the group’s dual role as both a state-aligned actor and a ransomware-as-a-service (RaaS) operator.
Pay2Key has undergone significant shifts in recent months. In mid-2025, the group marketed itself on Russian cybercriminal forums, briefly offering to sell its operations for 0.15 BTC while recruiting affiliates with an 80% ransom split up from 70%. Despite internal upheaval, the group remains active, with Morphisec tracking $4 million in ransom payments over four months and a total of $8 million from 170 victims since then.
First identified in 2020, Pay2Key has targeted organizations in the U.S., Israel, Azerbaijan, and the UAE, with ransom payments traced to Excoino, an Iranian cryptocurrency exchange requiring national ID verification. A 2024 U.S. advisory highlighted its coordination with other ransomware gangs, reinforcing its ties to Iranian government operations.
The healthcare attack preceded a high-profile wiper attack on Stryker, a U.S. medical device company, claimed by the Iranian group Handala, which wiped 200,000 devices. Kaiser warned that unreported Iranian cyberattacks are likely ongoing, with a mix of ransomware, wiper malware, and critical infrastructure targeting expected as tensions persist.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Cyber Attack
01 Feb 2026 • Stryker
Stryker: U.S. medical equipment company Stryker says cyberattack disrupted its global networks
Stryker Cyberattack Disrupts Global Medical Equipment Operations
749
CRITICAL-22
STR1773260617
Stryker Cyberattack Disrupts Global Medical Equipment Operations
U.S.-based medical technology giant Stryker confirmed that a cyberattack disrupted its global networks, impacting operations across its systems. The incident, disclosed in recent reports, highlights growing cybersecurity threats targeting critical healthcare infrastructure.
Stryker, a leading manufacturer of surgical equipment, implants, and medical devices, has not released details on the nature of the attack, its origin, or whether ransomware or data exfiltration was involved. The company has not specified the duration of the disruption or the extent of the operational impact, though such incidents often lead to delays in production, supply chain interruptions, and potential risks to patient care.
The attack underscores the vulnerability of healthcare and medical device companies to cyber threats, which have increasingly become high-value targets for malicious actors. No further updates on recovery efforts or regulatory responses have been provided at this time.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JANUARY 2026
771
DECEMBER 2025
770
NOVEMBER 2025
768
OCTOBER 2025
767
SEPTEMBER 2025
765
MARCH 2025
766
Cyber Attack
28 Mar 2025 • Stryker
Stryker: Stryker shares fall after report on suspected Iran-linked cyberattack
Stryker Hit by Suspected Iran-Linked Cyberattack, Causing Global Outages
755
CRITICAL-11
STR1773246684
Stryker Hit by Suspected Iran-Linked Cyberattack, Causing Global Outages
Medical technology giant Stryker suffered a global system outage on March 10, 2025, following a suspected cyberattack linked to an Iran-backed hacking group. The incident began shortly after midnight on the U.S. East Coast, disrupting operations across the company’s network.
According to reports, remote devices running Microsoft Windows including laptops and mobile devices connected to Stryker’s systems were wiped, rendering them inoperable. Employees and contractors reported seeing the logo of Handala, a pro-Palestinian hacking group with alleged ties to Iran, on login screens, though Reuters could not independently verify the claim.
The attack triggered a 3% drop in Stryker’s stock price after The Wall Street Journal first reported the breach. The company has not yet issued an official response to requests for comment.
Stryker, a major supplier of medical equipment, operates globally, with facilities including a plant in Carrigtwohill, Ireland. The full extent of the disruption and potential data compromise remains unclear.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
DECEMBER 2024
772
Cyber Attack
05 Dec 2024 • Stryker
Stryker and Federal Bureau of Investigation: Pro-Iranian group claims credit for hacking into FBI Director Patel's personal account
Pro-Iranian Hackers Claim Breach of FBI Director’s Personal Account
761
CRITICAL-11
STRFBI1774644063
Pro-Iranian Hackers Claim Breach of FBI Director’s Personal Account
A pro-Iranian hacking group, Handala, announced on Friday that it had compromised an account belonging to FBI Director Kash Patel, releasing decades-old personal photographs, a resume, and other documents online. The group, which has ties to Iran and Palestine, posted a statement alongside the materials, taunting Patel and declaring him among their "successfully hacked victims."
The leaked files including images of Patel with a vintage sports car and a cigar appear to date back over a decade, primarily involving personal travel and business records. The FBI confirmed awareness of the incident, stating that the exposed data was historical and contained no classified or government information. The bureau added that it had taken steps to mitigate risks from the breach.
The timing of the hack remains unclear, though reports from December 2024 indicated Patel had been previously warned by the FBI about Iranian targeting efforts. Handala, which has escalated its cyber operations in recent months, recently claimed responsibility for disrupting systems at Stryker, a Michigan-based medical technology firm, in retaliation for alleged U.S. airstrikes linked to Iranian civilian casualties.
The group has been a persistent threat, with the U.S. Justice Department seizing four web domains tied to its operations last week as part of efforts to counter Iranian cyber campaigns. The Trump administration has also offered a $10 million reward for information leading to the identification of Handala members. The incident underscores the growing role of proxy hacking groups in Iran’s broader cyber conflict with Western targets.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2024
798
Breach
01 May 2024 • Stryker
Stryker Corporation
Stryker Corporation Cybersecurity Incident
762
HIGH-36
STR200080525
The Vermont Office of the Attorney General reported that Stryker Corporation experienced a cybersecurity incident on June 10, 2024. The breach involved unauthorized access to Stryker internal systems between May 14, 2024, and June 10, 2024, affecting an unspecified number of individuals and potentially compromising personal information including names. A notification letter was included with the report.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2024
819
Cyber Attack
01 Jan 2024 • Stryker
Stryker: Hospital cyber attacks are increasingly hitting patient care
European Hospitals Face Escalating Cyber Threats to Patient Care
795
CRITICAL-24
STR1779114633
European Hospitals Face Escalating Cyber Threats to Patient Care, Survey Reveals
A new report from Black Book Research highlights a stark shift in the cybersecurity risks facing European hospitals, where attacks are no longer just about data breaches or IT disruptions but now pose direct threats to clinical operations. Based on a survey of 284 hospital cybersecurity decision-makers, 82% rate their 2026 cyberattack risk as "very high" or "extreme," while 74% expect a major incident within the year.
The findings underscore a growing concern: cyberattacks are increasingly targeting the availability and integrity of critical healthcare systems, from emergency departments to ICUs, rather than just stealing data. Hospitals operate in a uniquely vulnerable environment aging infrastructure, cross-border supplier networks, strict regulatory pressures, and cloud migration all while relying on digital workflows that cannot afford downtime.
Attackers are exploiting these weaknesses, focusing on authentication failures, recovery delays, third-party dependencies, and fragile clinical processes. In response, European hospitals are reallocating cybersecurity investments toward clinical continuity, with 66% prioritizing identity and access management (IAM, PAM, SSO failover), 57% boosting ransomware recovery and immutable backups, and 51% adopting zero trust and network segmentation. Other key areas include third-party risk management (45%), medical device security (37%), and resilience training (29%).
Despite these efforts, gaps remain. While 78% of hospital boards receive cybersecurity updates, only 31% review resilience metrics tied to clinical operations. Alarmingly, only 25% conducted a full clinical downtime simulation in the past year, and 32% have never run one or rely solely on tabletop exercises.
Confidence in operational resilience is also low: 59% believe their hospitals can function safely for 24 hours without core Electronic Health Record (EHR) access, but that drops to 32% at 48 hours and just 14% at 72 hours. Experts warn that prolonged downtime beyond 48 hours risks patient safety, disrupting medication reconciliation, lab results, radiology, pharmacy verification, and discharge planning.
Recent incidents reflect this trend. A 2024 ransomware attack on NHS pathology provider Synnovis and a "destructive" (non-ransomware) attack on medical tech firm Stryker demonstrate how cyber threats are evolving from financial extortion to direct sabotage of healthcare delivery. As one expert noted, "The cyber battleground has moved from the server room to the bedside."
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Cyber Attack
01 Jan 2024 • Stryker
Stryker: Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions
Iranian Threat Actor Handala Hack Launches Destructive Cyberattacks Across Israel, Albania, and the U.S.
795
CRITICAL-24
STR1773714231
Iranian Threat Actor Handala Hack Launches Destructive Cyberattacks Across Israel, Albania, and the U.S.
A cyber threat group linked to Iran’s Ministry of Intelligence and Security (MOIS), known as Handala Hack (also tracked as Void Manticore, Red Sandstorm, and Banished Kitten), has executed a series of data-destructive attacks targeting organizations in Israel, Albania, and the United States. Unlike traditional espionage-focused operations, the group’s campaigns are designed to permanently erase data, making recovery nearly impossible.
Active since late 2023, Handala Hack operates under multiple public-facing personas, including Homeland Justice (used since mid-2022 against Albanian government and telecom sectors) and Karma (now largely replaced by Handala). Recent attacks expanded to the U.S., with medical technology firm Stryker among the confirmed victims.
### Attack Methods and Evolution
Check Point researchers identified consistent yet evolving tactics in the group’s operations. While core techniques such as compromised VPN credentials, RDP exploitation, and simultaneous wiper deployments have remained stable since 2024, newer campaigns incorporate:
- NetBird, a legitimate peer-to-peer networking tool, to tunnel traffic within victim networks.
- An AI-assisted PowerShell script as part of its wiping toolkit.
- A decline in operational security, with attacks traced directly to Iranian IP addresses instead of commercial VPNs.
### Multi-Layered Destruction
Handala Hack’s destructive phase employs four simultaneous wiping techniques to maximize damage:
1. Handala Wiper – A custom tool distributed via Group Policy logon scripts (`handala.bat`), overwriting files and corrupting Master Boot Records (MBR). The executable runs remotely from domain controllers, evading detection.
2. AI-PowerShell Wiper – Deletes user directory files and floods drives with a propaganda image (`handala.gif`).
3. VeraCrypt Abuse – Legitimate encryption software is downloaded via the victim’s browser to lock drives and prevent recovery.
4. Manual Deletion – Attackers delete virtual machines and files over RDP, a tactic documented in leaked videos.
### Tactical Execution
Intrusions typically begin with compromised VPN credentials, obtained through brute-force attacks or supply chain breaches. Once inside, operators use RDP to navigate manually, deploying multiple attacker-controlled machines within a single environment to accelerate destruction. The group’s lack of operational discipline including direct use of Iranian IPs has made attribution easier.
The attacks reflect a shift from espionage to pure sabotage, with no financial or intelligence-gathering motives. Instead, the focus is on maximizing disruption across critical sectors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2023
828
Cyber Attack
03 May 2023 • Stryker
Stryker: Pro-Iran hacking group claims responsibility for cyberattack on Stryker
Stryker Hit by Cyberattack Claimed by Pro-Iran Hacking Group Handala
817
CRITICAL-11
STR1773268034
Stryker Hit by Cyberattack Claimed by Pro-Iran Hacking Group Handala
Medical technology firm Stryker, a leading manufacturer of surgical tools and medical implants based in Kalamazoo, Michigan, confirmed a cyberattack on Wednesday that disrupted its global Microsoft environment. The company stated it had no evidence of ransomware or malware and believed the incident was contained, though it is still assessing the impact. Continuity measures remain in place to support customers and partners.
The pro-Iran hacking group Handala claimed responsibility for the attack, alleging it wiped over 200,000 systems, servers, and mobile devices and exfiltrated 50 terabytes of critical data. The group cited retaliation for the ongoing regional conflict and a February 28 airstrike on a girls' elementary school in Minab, Iran, which killed 168 people, as motivations. While the attack’s origins remain unconfirmed, U.S. military operations were reported near the site.
Stryker has not disclosed further details, and U.S. officials have not commented on the incident. The investigation is ongoing.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2016
831
Cyber Attack
19 Jul 2016 • Stryker
Stryker, Dubai Courts, Dubai Land Department and PSK Wind Technologies: Iran-linked group Handala claims to have breached three major UAE organizations
Iran-Linked Handala Claims Cyberattacks on Three Major UAE Organizations
816
CRITICAL-15
STRTWEDUBDUB1776084002
Iran-Linked Handala Claims Cyberattacks on Three Major UAE Organizations
On April 13, 2026, the Iran-aligned hacking group Handala announced a series of cyberattacks targeting three key UAE institutions: Dubai Courts, Dubai Land Department, and Dubai Roads & Transport Authority. The group claimed to have destroyed 6 petabytes of data and stolen 149 terabytes of sensitive information, framing the breach as retaliation against the UAE’s alleged alignment with Western and Israeli interests.
In a statement posted on its Tor-based website, Handala described the attack as a "preemptive warning" to regional governments, citing the UAE’s perceived betrayal of the "Resistance Axis" a term often associated with Iran-backed factions. While the group’s claims remain unverified, its history of destructive operations lends credibility to the allegations.
Handala, widely believed to be a front for Iran-backed Void Manticore, has a track record of phishing, data theft, extortion, and wiper attacks, often blending cyber operations with psychological warfare. Since the February 2026 escalation of U.S.-Israeli tensions with Iran, the group has intensified its activities, targeting Israeli military servers, intelligence personnel, and defense contractors.
Recent attacks include:
- A breach of PSK Wind Technologies, an Israeli defense and IT firm specializing in command-and-control systems (early April 2026).
- A destructive attack on medical tech giant Stryker, where Handala claimed to have wiped over 200,000 devices across 79 countries and exfiltrated 50TB of corporate data all without deploying traditional malware.
- The alleged hack of FBI Director Kash Patel’s personal Gmail account, with the group releasing purported photos and files.
The FBI has offered a $10 million reward for information leading to the identification of Handala’s operatives, underscoring the group’s growing threat to critical infrastructure and national security.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2010
833
Cyber Attack
01 Jan 2010 • Stryker
Stryker and Federal Bureau of Investigation: FBI Director Kash Patel’s email leaked by Iran-backed hackers
Iran-Linked Hackers Leak FBI Director Kash Patel’s Personal Emails in Cyber Espionage Campaign
818
CRITICAL-15
FEDSTR1774629686
Iran-Linked Hackers Leak FBI Director Kash Patel’s Personal Emails in Cyber Espionage Campaign
On March 27, 2026, the Iran-backed hacking group Handala Hack Team publicly released a trove of personal emails belonging to FBI Director Kash Patel, marking a high-profile breach in a series of cyber operations attributed to Iranian state-linked actors. The leaked correspondence, spanning from 2010 to 2019, includes a mix of personal and professional communications tied to Patel’s Gmail account, which had been previously exposed in other data breaches.
Western cybersecurity researchers identify Handala as one of several personas used by Iranian government cyberintelligence units, which have recently escalated attacks on Western targets. Earlier this year, the group claimed responsibility for hacking Stryker, a U.S. medical devices manufacturer, further demonstrating its focus on high-value entities.
The hackers published photographs of Patel alongside the leaked documents, declaring him among their "successfully hacked victims." A U.S. Justice Department official confirmed the breach, stating that the released material appeared authentic. While the full extent of the compromise remains unclear, the incident underscores the persistent threat posed by state-sponsored cyber espionage, particularly from Iranian-linked groups targeting U.S. officials and critical infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Stryker ??
What was Stryker's A.I Rankiteo Cyber Score in July 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in June 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in May 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in April 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in March 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in February 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in January 2026 ??
What was Stryker's A.I Rankiteo Cyber Score in December 2025 ??
What was Stryker's A.I Rankiteo Cyber Score in November 2025 ??
What was Stryker's A.I Rankiteo Cyber Score in October 2025 ??
What was Stryker's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Stryker's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Stryker ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Stryker's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?