Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Stryker

Stryker Vendor Cyber Rating & Cyber Score

stryker.com

Stryker is a global leader in medical technologies and, together with our customers, we are driven to make healthcare better. We offer innovative products and services in MedSurg, Neurotechnology and Orthopaedics that help improve patient and healthcare outcomes. Alongside its customers around the world, Stryker impacts more than 150 million patients annually. More information is available at stryker.com and careers.stryker.com. Facts: ● 2024 Sales: $22.6 billion ● Industry: Medical Instruments & Supplies ● Employees: 53,000 worldwide ● 44+ Manufacturing and R&D Locations Worldwide ● $1.5 billion spent on research and development in 2024 ● ~14,200 patents owned globally in 2024 ● Products sold in ~75 countries ● Fortune 500 Company


Stryker A.I CyberSecurity Scoring

Stryker
Company Information
Website:http://www.stryker.com
Employees number:51,473
Number of followers:1,856,594
NAICS:3391
Industry Type:Medical Equipment Manufacturing
Homepage:stryker.com
Stryker Risk Score (AI oriented)
Between 0 and 549
logo
StrykerMedical Equipment Manufacturing
Updated:
13/07/2026
521/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Stryker Global Score (TPRM)
xxxx
logo
StrykerMedical Equipment Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Stryker
StrykerCritical
Current Score
521C (CRITICAL)
01000
23 incidents
-24.83 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
533Before Incident
JULY 2026
531Before Incident
Cyber Attack
10 Jul 2026Stryker
Stryker Corporation: GigaWiper: Modular Windows Backdoor Combines Disk Wiper, Fake Ransomware, Spyware

GigaWiper: A Modular Windows Backdoor with Destructive Capabilities

521After Incident
CRITICAL-10
STR1783982145
GigaWiper: A Modular Windows Backdoor with Destructive Capabilities On July 9, 2026, Microsoft’s threat intelligence team released a detailed analysis of GigaWiper, a sophisticated Windows backdoor that blends surveillance and irreversible destruction into a single implant. Unlike traditional wipers, GigaWiper is a full-featured espionage tool that can silently monitor networks before executing one of three distinct disk-erasure commands all without deploying additional payloads. ### Key Features and Attack Mechanics GigaWiper, written in Go, integrates components from at least three older malware families: - Command 1 (Raw Disk Wiper): Uses Windows Management Instrumentation (WMI) to overwrite all physical disks, erasing partition metadata and raw content with randomized patterns to evade detection. - Command 3 (Fake Ransomware): Mimics ransomware by encrypting files with a .candy extension and displaying a ransom note but the keys are discarded, making recovery impossible. This module is derived from Crucio ransomware, previously linked to Iran’s CyberAv3ngers (IRGC-CEC). - Command 12 (Multi-Pass Wiper): A Go-based reimplementation of FlockWiper, targeting the Windows drive with alternating overwrite patterns to prevent forensic recovery. The malware also includes surveillance capabilities, such as screenshot capture, VNC-based remote desktop access, PowerShell execution, and file exfiltration via MinIO. A dormant keylogger module (Command 11) suggests further development. ### Command-and-Control (C2) Infrastructure GigaWiper abuses legitimate enterprise tools for C2 communication: - RabbitMQ (AMQP protocol) for operator commands. - Redis for status updates. - MinIO (S3-compatible storage) for data exfiltration. Active C2 servers were identified at: - 185.182.193[.]21 (RabbitMQ on port 554455445544, Redis on 754275427542) - 212.8.248[.]104 ### Persistence and Evasion Techniques - OneDrive Impersonation: Creates a scheduled task named "OneDrive Update" and a registry key (HKCU\SOFTWARE\OneDrive\Environment) to maintain persistence. - Firewall Rule Spoofing: Adds a rule named Microsoft.Windows.CloudExperienceHost to bypass detection. - Behavioral Camouflage: Uses GUID-like directory names with non-hex characters to evade behavioral detection. ### Attribution and Geopolitical Context While Microsoft did not attribute GigaWiper to a specific actor, Binary Defense and Google’s Threat Intelligence Group linked it to an Iran-nexus cluster responsible for BLUEWIPE and SEWERGOO in June 2025. The malware’s Crucio-derived module further ties it to CyberAv3ngers, a group sanctioned by the U.S. Treasury in 2024. GigaWiper’s emergence aligns with a surge in Iranian wiper attacks following Operation Epic Fury (U.S.-Israel strikes on Iran in early 2026). Other Iran-linked groups, such as Handala Hack and Cavern Manticore, have conducted similar destructive campaigns, including the Stryker Corporation wipe in March 2026. ### Detection and Defense Priorities Microsoft has released YARA rules and Defender signatures for GigaWiper. Key detection methods include: - Monitoring for unexpected "OneDrive Update" scheduled tasks or Microsoft.Windows.CloudExperienceHost firewall rules. - Auditing RabbitMQ, Redis, and MinIO traffic for unauthorized connections. - Treating ransomware-like activity without ransom notes as a potential wiper attack. - Ensuring offline, immutable backups are in place, as GigaWiper’s disk-wiping methods leave no recovery path. First observed in October 2025, GigaWiper remained undetected for months before researchers connected it to earlier Iran-linked activity. Its modular design and abuse of legitimate tools make it a particularly challenging threat for defenders.
INCIDENT DETAILS -
TYPE
backdoorwiperransomware
MOTIVATION
espionagedestructiongeopolitical retaliation
IMPACT
Windows systemsirreversible data destructionsystem erasure
DATA BREACH
screenshotsfileskeylogging datafake ransomware (Crucio-derived)
JUNE 2026
519Before Incident
MAY 2026
566Before Incident
Cyber Attack
20 May 2026Stryker
Stryker: West Pharma says fully operational after cyberattack, sees no hit to 2026 forecast

West Pharmaceutical Services Cyberattack

555After Incident
CRITICAL-11
STR1779337852
West Pharmaceutical Services Recovers from Cyberattack, Restores Global Operations West Pharmaceutical Services has fully restored operations across its global sites following a cybersecurity incident detected earlier this month. The medical equipment manufacturer first identified unauthorized activity on May 4 and confirmed a material cyberattack on May 7, which involved data exfiltration and system lockdowns. In response, the company took systems offline worldwide, notified law enforcement, and engaged external cybersecurity experts to contain the breach. By May 20, West Pharmaceutical announced it had successfully restarted core processes including manufacturing, shipping, and supply chain operations across all locations. While the investigation remains ongoing, the company stated it has not detected further unauthorized access. Analysts at Evercore ISI noted West Pharmaceutical’s swift recovery, citing its ability to leverage 24/7 operations and flex capacity to mitigate disruptions. The incident is not expected to have a material impact on the company’s 2026 financial outlook, including second-quarter or full-year forecasts. The attack follows a recent wave of cybersecurity incidents in the healthcare sector, with Stryker, Intuitive Surgical, and Medtronic reporting similar breaches in March and April. West Pharmaceutical continues to assess the extent of data affected as part of its review.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Data Compromised: Data exfiltrationSystems Affected: Global systems, including manufacturing, shipping, and supply chain operationsOperational Impact: Systems taken offline worldwide; core processes restarted by May 20
APRIL 2026
567Before Incident
Cyber Attack
01 Apr 2026Stryker
Stryker: Weak authentication, exposed ICS environments heighten concerns over Iranian cyber intrusions into US critical infrastructure

Iranian Cyber Actors Exploit Weak Security in U.S. Critical Infrastructure

556After Incident
CRITICAL-11
STR1779452900
Iranian Cyber Actors Exploit Weak Security in U.S. Critical Infrastructure Iran-aligned cyber threat groups are intensifying efforts to target poorly secured U.S. critical infrastructure, leveraging gaps in basic cybersecurity practices to infiltrate operational technology (OT) systems. A recent analysis by the Foundation for Defense of Democracies (FDD) reveals that attackers have accessed exposed industrial environments, including gas station tank gauge systems across multiple states, by exploiting default or absent passwords. While these intrusions have not yet caused physical disruptions such as altering fuel levels they have manipulated display data, potentially obscuring critical issues like leaks or empty tanks. The campaign reflects a broader pattern of Iranian-linked groups probing internet-facing industrial control systems (ICS), particularly where authentication and network segmentation are weak. Though many incidents have resulted in limited operational impact, U.S. officials warn that the intent is evolving toward disruption and psychological pressure, especially in sectors with outdated or minimal security controls. Targets include energy, water, and other essential services, with adversaries frequently exploiting vulnerabilities in programmable logic controllers (PLCs) and supervisory control systems. Iranian threat actors, while less sophisticated than their Chinese or Russian counterparts, combine cyber operations with influence campaigns to maximize societal impact. Groups linked to the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security often operate through hacktivist fronts, as seen in past incidents involving high-profile targets, including an attempted breach of FBI Director Kash Patel and an attack on medical technology firm Stryker. Recent examples highlight Iran’s persistent but often overstated claims of success. In April, the group Ababil of Minab took credit for an attack on the Los Angeles transit authority, asserting control over internal systems though officials confirmed only partial access with no disruption to services. Similarly, the IRGC-affiliated APTIRAN previously claimed to have compromised gas station systems in Pennsylvania, though no public confirmation of the breach was provided. The FDD report underscores that many exploited systems rely on default credentials or lack password protection entirely, emphasizing the need for stronger baseline security. The U.S. government’s Secure by Design initiative aims to address these vulnerabilities by working with vendors to enforce security-by-default measures, such as requiring password changes during installation. Separately, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation active since May 2025. The platform, used by ransomware gangs and other threat actors, abused Microsoft’s code-signing infrastructure to distribute malicious software, including strains like Oyster, Lumma Stealer, and Akira, infecting thousands of systems globally.
INCIDENT DETAILS -
TYPE
Cyber EspionageData Manipulation
MOTIVATION
DisruptionPsychological pressureSocietal impact
IMPACT
Gas station tank gauge systemsOperational technology (OT) systemsIndustrial control systems (ICS)Programmable logic controllers (PLCs)Supervisory control systemsOperational Impact: Manipulation of display data (e.g., obscuring leaks or empty tanks)
MARCH 2026
586Before Incident
Cyber Attack
30 Mar 2026Stryker
Stryker and Jones Day: In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack

Cybersecurity Roundup: AI Risks, Mac Malware, and Major Breaches Dominate the Week

567After Incident
CRITICAL-19
DOWSTR1775838732
Cybersecurity Roundup: AI Risks, Mac Malware, and Major Breaches Dominate the Week This week’s cybersecurity landscape was marked by high-profile threats, regulatory discussions, and industry responses to emerging risks. Here are the key developments: AI Cybersecurity Concerns Prompt Fed Discussions Federal Reserve Chair Jerome Powell and Treasury Secretary Scott Bessent met with major U.S. banks to assess cyber risks posed by Anthropic’s Mythos, a high-reasoning AI model with advanced exploit-chaining capabilities. Currently restricted to select partners under Project Glasswing, Mythos raises concerns about autonomous cyber threats. New macOS Stealer Targets High-Value Crypto Wallets A hacker, previously active in underground forums, resurfaced with NotnullOSX, a macOS stealer targeting victims holding over $10,000 in cryptocurrency. Detected in Vietnam, Taiwan, and Spain on March 30, 2026, the malware spreads via fake Google documents and malicious DMG files, gaining Full Disk Access to steal iMessages, browser credentials, and crypto wallets. Japanese Corporations Form Cybersecurity Alliance Ten major Japanese firms, including Suntory, Kao, Asahi, and NTT, are launching a joint organization to share threat intelligence and develop cybersecurity talent. The initiative follows a September 2025 breach at Asahi that disrupted supply chains and exposed vulnerabilities in interconnected networks. Law Firm Jones Day Hit by Ransomware Attack The Silent Ransom Group (aka Luna Moth) infiltrated Jones Day using social engineering, accessing records of 10 clients and leaking sensitive documents after the firm refused a $13 million ransom demand. Spyware Founder Receives Lenient Sentence Bryan Fleming, creator of the surveillance tool pcTattletale, was sentenced to time served and a $5,000 fine the first federal conviction of a spyware operator in over a decade. Despite facilitating illegal surveillance and suffering a data leak, Fleming avoided additional prison time. DocketWise Breach Exposes 116,000 Individuals Austin-based legal tech firm DocketWise confirmed a 2025 breach exposing personal data of 116,000 individuals after unauthorized access to a third-party repository containing unstructured client records. Cloudflare Accelerates Post-Quantum Security Transition Following Google’s advancements in quantum algorithms, Cloudflare moved its post-quantum security deadline to 2029. The shift responds to research suggesting neutral atom computers could break RSA-2048 and P-256 encryption with fewer qubits than previously estimated. HackerOne Pauses Bug Bounty Submissions Amid AI Surge The Internet Bug Bounty (IBB) program halted new submissions on March 27, 2026, citing an overwhelming influx of AI-assisted vulnerability reports. While existing submissions are processed, organizers plan to restructure incentives to balance discovery and remediation. Windows Zero-Day Exploit Leaked After Microsoft Dispute A researcher publicly released BlueHammer, a Windows zero-day exploiting a race condition in Microsoft Defender to gain SYSTEM privileges. The disclosure followed a breakdown in communication with Microsoft, which has yet to patch the flaw or assign a CVE. Hacker Claims Breach of China’s Supercomputing Center A hacker known as FlamingChina alleged access to the National Supercomputing Center in Tianjin, extracting 10 petabytes of data over six months via a compromised VPN. Leaked samples include classified documents and defense equipment simulations, though some experts question the authenticity of the claims. Stryker Confirms Financial Impact from Cyberattack Medical device manufacturer Stryker reported that a March 2026 cyberattack caused operational disruptions, materially affecting Q1 financial results. While systems have been restored, the investigation into data exposure and regulatory implications remains ongoing. The company reaffirmed its full-year guidance.
INCIDENT DETAILS -
TYPE
AI Cybersecurity RiskMalwareRansomwareData BreachSpywareZero-Day ExploitCyber Espionage
MOTIVATION
Financial GainEspionageData TheftSurveillance
IMPACT
Financial Loss: $13 million ransom demand (Jones Day), Material impact on Q1 results (Stryker)Data Compromised: 10 petabytes (National Supercomputing Center in Tianjin), 116,000 individuals (DocketWise), Client records (Jones Day)macOS (NotnullOSX)Windows (BlueHammer)Third-party repositories (DocketWise)Corporate networks (Asahi, Stryker)Downtime: Operational disruptions (Stryker)Operational Impact: Supply chain disruptions (Asahi), Q1 financial impact (Stryker)Revenue Loss: Material impact on Q1 results (Stryker)Brand Reputation Impact: Potential reputational damage (Jones Day, DocketWise, Stryker)Legal Liabilities: Regulatory implications (Stryker), Potential fines (DocketWise)Identity Theft Risk: 116,000 individuals (DocketWise)
DATA BREACH
Personal DataClient RecordsClassified DocumentsDefense Equipment SimulationsCryptocurrency Wallet DataNumber Of Records Exposed: 116,000 (DocketWise), 10 petabytes (National Supercomputing Center in Tianjin)Sensitivity Of Data: High (Classified documents, defense simulations, PII)Data Exfiltration: Yes (National Supercomputing Center in Tianjin, Jones Day)Personally Identifiable Information: Yes (DocketWise)
MARCH 2026
597Before Incident
Cyber Attack
27 Mar 2026Stryker
Stryker and U.S. Justice Department: FBI director emails breached by Iran-linked hackers — what happened and how to protect yourself

Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos

586After Incident
CRITICAL-11
CRISTR1774636436
Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos On March 27, 2026, the Iranian-linked hacktivist group Handala Hack Team claimed responsibility for accessing the personal emails of FBI Director Kash Patel, publishing alleged photos and documents as proof. The leaked images dated between 2010 and 2019 depict Patel in personal settings, including vacations and social gatherings. The U.S. Justice Department confirmed the breach, verifying the authenticity of the materials. Handala framed the attack as retaliation for the ongoing U.S.-Iran conflict and the FBI’s $10 million bounty for information on its members. The group boasted of bypassing the FBI’s security systems, though officials clarified that only Patel’s personal Gmail account not government systems was compromised. The incident highlights persistent risks tied to officials using personal emails for professional matters. About Handala Hack Team Active since 2023 and linked to Iran’s Ministry of Intelligence and Security, Handala specializes in disruptive cyberattacks, often targeting Israeli and Western entities. The group has previously breached Lockheed Martin and executed a 200,000-user data wipe at medical tech firm Stryker, leveraging malware designed to delete or expose sensitive data. The breach underscores vulnerabilities in personal email security, even among high-profile officials.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation for U.S.-Iran conflictResponse to FBI's $10 million bounty
IMPACT
Data Compromised: Personal photos and documentsSystems Affected: Personal Gmail accountBrand Reputation Impact: High (FBI Director's personal data exposed)Identity Theft Risk: High (personal photos and documents exposed)
DATA BREACH
Type Of Data Compromised: Personal photos and documentsSensitivity Of Data: High (personal and potentially sensitive images)Data Exfiltration: Yes (leaked publicly)ImagesDocumentsPersonally Identifiable Information: Yes (personal photos, potential metadata)
MARCH 2026
562Before Incident
Cyber Attack
16 Mar 2026Stryker
Stryker: Iranian hackers responsible for LA transit system breach, Israeli researchers say

Disruptive Cyberattack on Los Angeles County Metropolitan Transportation Authority (LACMTA)

551After Incident
CRITICAL-11
STR1779805618
Iranian Hackers Linked to Disruptive LA Transit System Breach, Israeli Researchers Confirm Israeli cybersecurity firm Gambit Security has attributed a March cyberattack on the Los Angeles County Metropolitan Transportation Authority (LACMTA) to Iranian state-linked hackers, following an investigation that uncovered 700GB of stolen data including emails and backups left exposed online. The breach, detected around March 16, forced the transit agency to temporarily shut down parts of its network, though train and bus operations remained unaffected. However, local reports indicated disruptions to arrival screens and transit card payment systems. The attack was claimed by Ababil of Minab, a pro-Iran hacking group named after a 2023 school bombing in Iran. While U.S. and Israeli researchers have long suspected Ababil of acting as a front for Iranian intelligence, Gambit’s findings provide forensic evidence linking the group to Tehran. Eyal Sela, Gambit’s director of threat intelligence, stated that the connection to the Iranian state had been a "working assumption" but is now supported by digital traces. The LACMTA confirmed the incident in a March statement, noting an ongoing investigation with law enforcement and cybersecurity experts but declined to comment on attribution. The FBI acknowledged awareness of the breach and said it was coordinating with partners, while CISA and Iran’s UN mission did not respond to requests for comment. Ababil has also claimed responsibility for recent attacks on South Florida’s Tri-Rail, vehicle tracking firm Vyncs, and Saudi infrastructure company Unimac. Tri-Rail confirmed a breach but described the stolen data as non-critical, while Vyncs reported its incident on April 2, with the FBI involved in both cases. Unimac did not respond to inquiries. Gambit’s analysis suggests Ababil has targeted additional organizations including an Israeli media outlet, an Israeli educational institution, and a Turkish insurance brokerage though details remain undisclosed. The group’s activity aligns with a broader surge in Iranian cyber operations since late February, coinciding with heightened tensions following the Israel-Hamas war. Recent incidents include a cyberattack on medical device manufacturer Stryker, the leak of FBI Director Kash Patel’s emails, and alleged tampering with U.S. gas station fuel gauges, as reported by CNN. The LACMTA breach underscores the growing threat of state-backed cyber sabotage targeting critical infrastructure, with Iranian hackers increasingly leveraging proxy groups to obscure their involvement.
INCIDENT DETAILS -
TYPE
Cyberattack, Data Breach
MOTIVATION
Cyber sabotage, Disruption of critical infrastructure, Geopolitical tensions
IMPACT
Data Compromised: 700GB of data (emails, backups)Systems Affected: Network systems, transit card payment systems, arrival screensOperational Impact: Temporary shutdown of parts of the network
DATA BREACH
EmailsBackupsData Exfiltration: 700GB of data exposed online
MARCH 2026
669Before Incident
Breach
13 Mar 2026Stryker
Shoppers Drug Mart, President’s Choice, Loblaw, No Frills and PC Optimum: “Threat Actor” on the dark web claims Loblaw’s “low-level” data breach is a much larger threat

Alleged Massive Data Breach at Loblaw

606After Incident
CRITICAL-63
NO-SHOPRELOB1773534483
Loblaw Faces Alleged Massive Data Breach as Threat Actor Demands Response A threat actor operating under the handle "igotafeeling" on the DarkWeb Informer forum has claimed to have breached Loblaw, Canada’s largest food and pharmacy retailer, which owns brands like President’s Choice, No Frills, Shoppers Drug Mart, Real Canadian Superstore, and the PC Optimum loyalty program. The actor alleges possession of over 1.8 billion records, including: - 75.1 million Salesforce customer records (names, emails, phone numbers, addresses, loyalty IDs, and health card numbers) - 724.9 million Shoppers Drug Mart records (passwords, tokens, loyalty IDs, payment details, and full credit card numbers with expiry dates) - 129.9 million pharmacy fill requests (prescription numbers and patient IDs) - 120.4 million e-commerce fraud-feed records (payment card BINs, last-four digits, and expiry dates) - 20.2 million Delivery Ops Portal records (orders, deliveries, and postal codes) - 3,014 GitLab projects containing Loblaw’s full source code - 19.3 million Oracle identity records (MFA device details and credentials) - 55.3 million marketing and email records across 673 tables The threat actor has given Loblaw until March 19 to respond, accusing the company of "ghosting" them and dismissing customer and investor concerns. They have also invited media organizations to verify the data’s authenticity. In response, Loblaw issued a March 12 press release, labeling the incident a "low-level data breach" and stating that only "basic customer information" (names, phone numbers, and emails) may have been accessed. The company explicitly denied evidence of financial or credit card data compromise directly contradicting the threat actor’s claims. While the breach remains unverified, the scale of the alleged exposure if confirmed would rank among the largest in Canadian history. The situation mirrors past high-profile breaches (e.g., T-Mobile, Equifax, Capital One), where initial corporate statements downplayed impact before later revelations proved otherwise. Loblaw customers with PC Optimum accounts, Shoppers Drug Mart loyalty cards, or prescription histories may be affected if the claims hold true. The deadline for Loblaw’s response is six days away.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion (response demanded by March 19)
IMPACT
Data Compromised: Over 1.8 billion records allegedly exposedSalesforceShoppers Drug Mart systemsGitLab projectsOracle identity systemsE-commerce platformsBrand Reputation Impact: Potential significant impact if claims are verifiedIdentity Theft Risk: High (health card numbers, prescription IDs, PII)Payment Information Risk: High (full credit card numbers with expiry dates)
DATA BREACH
Customer records (names, emails, phone numbers, addresses, loyalty IDs)Health card numbersPharmacy fill requests (prescription numbers, patient IDs)Payment details (full credit card numbers with expiry dates, BINs, last-four digits)Source code (GitLab projects)MFA device details and credentials (Oracle identity records)Marketing and email recordsNumber Of Records Exposed: 1.8 billion (alleged)Sensitivity Of Data: High (PII, financial data, health information, source code)Data Exfiltration: Alleged (data sold on dark web if claims are true)Personally Identifiable Information: Yes (names, emails, phone numbers, addresses, health card numbers, prescription IDs)
MARCH 2026
703Before Incident
Cyber Attack
11 Mar 2026Stryker
Stryker: Suspected Iranian cyberattack hits Stryker, disrupting systems across medical device company

Iran-Linked Cyberattack Disrupts Stryker, Global Medical Device Manufacturer

669After Incident
CRITICAL-34
STR1780043335
Iran-Linked Cyberattack Disrupts Stryker, Global Medical Device Manufacturer A suspected cyberattack attributed to an Iran-affiliated hacking group has disrupted operations at Stryker, a Michigan-based global medical device manufacturer. The attack, reported on June 10, 2024, caused widespread system outages across the company’s network, affecting facilities including its Portage, Michigan headquarters. Employees and contractors reported seeing the hacking group’s logo appear on company devices during the incident. The group claimed responsibility in a post on X (formerly Twitter), citing retaliation for an alleged attack on an Iranian school in Minab. Stryker confirmed the disruption and is working to restore affected systems. The incident highlights growing cybersecurity risks in the healthcare and medical device sectors, where operational disruptions can have cascading effects on patient care and supply chains. No details on data breaches or patient impact have been disclosed.
INCIDENT DETAILS -
TYPE
Cyberattack
MOTIVATION
Retaliation for an alleged attack on an Iranian school in Minab
IMPACT
Systems Affected: Widespread system outages across the company’s networkOperational Impact: Disrupted operations at global medical device manufacturing facilities
Cyber Attack
11 Mar 2026Stryker
Stryker: Cork-based Stryker hit with cyber attack linked to Iranian-backed group

Stryker Hit by Destructive Cyberattack Linked to Iranian-Backed Group

669After Incident
CRITICAL-34
STR1773240573
Stryker Hit by Destructive Cyberattack Linked to Iranian-Backed Group A global medical technology firm, Stryker, suffered a devastating wiper cyberattack on Wednesday, suspected to be orchestrated by Handala Hack, a group with ties to the Iranian regime. The attack targeted the company’s Cork, Ireland headquarters, where up to 5,000 employees including 4,000 in Cork are based, crippling critical IT systems and manufacturing operations. The National Cyber Security Centre (NCSC) in Dublin is responding to the incident, which involved the permanent deletion of data from infected systems a hallmark of wiper attacks, typically politically motivated rather than financially driven. Devices connected to Stryker’s network, including employee phones with Outlook installed, were wiped, and login screens were defaced with the Handala logo, a symbol of Palestinian resistance. The attack has disrupted production of Stryker’s medical devices, with some manufacturing machines still operational but their long-term functionality uncertain. Staff were instructed to avoid connecting to the company’s network via any device, including mobile apps like Microsoft Teams and Outlook, while recovery efforts continue. Employees have been sent home, relying on WhatsApp groups for updates. Stryker, which operates six manufacturing sites and three innovation centers in Ireland, is one of the country’s largest medical tech employers. The company confirmed the incident in a staff memo, stating that security experts and law enforcement are involved in the response, emphasizing that sites and personnel remain safe while efforts focus on restoring systems. Handala Hack, linked to Iran’s cyber warfare campaigns, has recently targeted Israeli, Jordanian, and Saudi oil and gas facilities, as well as the Academy of the Hebrew Language, according to Israeli media. The Israeli National Cyber Directorate has warned of a surge in Iranian cyberattacks against civilian companies, suggesting Stryker may have been targeted due to its business ties with Israel. The attack underscores Iran’s expanding cyber-economic warfare, extending beyond regional conflicts to global operations. With Ireland serving as Stryker’s largest hub outside the U.S., the incident highlights the growing threat of state-backed cyber sabotage in critical industries.
INCIDENT DETAILS -
TYPE
Wiper Attack
MOTIVATION
Politically motivated (suspected state-backed cyber sabotage)
IMPACT
Data Compromised: Permanent deletion of data from infected systemsSystems Affected: IT systems, manufacturing operations, employee devices (Outlook, Microsoft Teams)Operational Impact: Disrupted production of medical devices, employees sent home, reliance on WhatsApp for updates
DATA BREACH
Type Of Data Compromised: System data (permanently deleted)
Cyber Attack
11 Mar 2026Stryker
Stryker: Medical technology company Stryker disrupted globally by cyberattack

Stryker Hit by Global Cyberattack Disrupting Medical Technology Services

669After Incident
CRITICAL-34
STR1773354343
Stryker Hit by Global Cyberattack Disrupting Medical Technology Services On March 11, Stryker, a leading medical technology provider serving hospitals worldwide, confirmed a global cyberattack that disrupted its operations. The company reported that its Microsoft environment was compromised but found no evidence of ransomware or malware. Stryker stated the incident had been contained. John Riggi, the American Hospital Association’s (AHA) national advisor for cybersecurity and risk, acknowledged the attack, noting ongoing collaboration with hospitals and federal agencies to assess the threat’s scope. While no direct disruptions to U.S. hospital operations have been reported, Riggi warned that impacts could emerge as hospitals evaluate Stryker’s services, technology, and supply chain particularly if the disruption persists. The incident highlights the vulnerability of critical healthcare infrastructure to cyber threats, even in the absence of traditional ransomware tactics. Further details on the attack’s origin and full impact remain under investigation.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Systems Affected: Microsoft environmentOperational Impact: Disrupted operations
MARCH 2026
714Before Incident
Cyber Attack
01 Mar 2026Stryker
Stryker and Rockwell Automation: Iranian hackers launching disruptive attacks at U.S. energy, water targets, feds warn

U.S. Government Warns of Iranian Cyberattacks Targeting Critical Infrastructure

702After Incident
CRITICAL-12
STRROC1775594506
U.S. Government Warns of Iranian Cyberattacks Targeting Critical Infrastructure U.S. intelligence and cybersecurity agencies issued an urgent joint alert on Tuesday, warning that Iranian government-linked hackers are conducting disruptive cyberattacks against American energy and water infrastructure. The attacks, which have intensified since the onset of U.S.-Israel military strikes against Iran, specifically target operational technology (OT) systems, including programmable logic controllers (PLCs) from Rockwell Automation/Allen-Bradley. The alert issued by the FBI, NSA, CISA, EPA, Energy Department, and Cyber Command details how Iran-affiliated advanced persistent threat (APT) actors have exploited internet-facing OT devices, leading to disruptions in critical infrastructure sectors. These attacks involve malicious interactions with project files and manipulation of human-machine interface (HMI) and supervisory control and data acquisition (SCADA) systems, resulting in operational disruptions and financial losses for victims. Since March, the agencies have identified new victims tied to an Iranian APT group, with at least 75 devices compromised in earlier campaigns. Affected sectors include government services, water and wastewater systems (WWS), and energy. Some organizations have already experienced operational downtime due to the attacks. This latest wave follows previous warnings about Iranian cyber threats, including a 2023 attack on a Pennsylvania water facility. Recent targets have also included major corporations like medtech firm Stryker and local government entities. Separately, the FBI had previously flagged Iranian hackers using Telegram to distribute malware, though that campaign predates the current conflict.
INCIDENT DETAILS -
TYPE
Cyberattack
MOTIVATION
Disruptive cyberattacks in response to U.S.-Israel military strikes against Iran
IMPACT
Financial Loss: YesSystems Affected: Operational technology (OT) systems, PLCs, HMI, SCADA systemsDowntime: YesOperational Impact: Operational disruptions in critical infrastructure sectorsRevenue Loss: Yes
MARCH 2026
750Before Incident
Breach
28 Feb 2026Stryker
Medtronic, Intuitive Surgical and Stryker: Medtronic discloses cybersecurity breach in certain IT systems

Medtronic Unauthorized Access to Corporate IT Systems

702After Incident
HIGH-48
MEDINTSTR1777141606
Medtronic Confirms Unauthorized Access to Corporate IT Systems in Cybersecurity Incident Medtronic, a leading medical technology company, disclosed that an unauthorized party accessed data within certain corporate IT systems. The breach, detected during routine monitoring, prompted an immediate response, including containment measures and the activation of incident response protocols. The company has engaged cybersecurity experts to investigate and remediate the incident while working to determine whether personal information was compromised. Medtronic emphasized that the breach did not affect product functionality, patient safety, customer connections, manufacturing, or distribution operations. Its corporate IT networks remain separate from systems supporting medical devices, production, and hospital networks, minimizing potential disruptions. The company does not anticipate a material impact on its business or financial performance but continues to assess security enhancements. This incident follows recent cyberattacks on other major medtech firms. In February 2026, Iranian-backed hacktivists executed a "wiper attack" against Stryker, erasing data in retaliation for U.S. and Israeli actions. Shortly after, Intuitive Surgical reported a breach stemming from a phishing incident that exposed internal IT applications. At this time, there is no evidence linking these breaches to a coordinated campaign or shared motives.
INCIDENT DETAILS -
TYPE
Unauthorized Access
IMPACT
Data Compromised: Data within certain corporate IT systemsSystems Affected: Corporate IT systemsOperational Impact: No impact on product functionality, patient safety, customer connections, manufacturing, or distribution operations
DATA BREACH
Sensitivity Of Data: Personal information (potentially)
FEBRUARY 2026
749Before Incident
Breach
04 Feb 2026Stryker
Social Security Administration: The Social Security data breach is a national-security disaster that could hurt Americans for the rest of their lives: whistleblower

Potential Massive Social Security Data Breach

703After Incident
CRITICAL-46
SOC1770609457
Former SSA Chief Data Officer Warns of Massive Social Security Data Breach A whistleblower has raised alarms over a potential national security disaster involving the exposure of sensitive Social Security data for every American with or who ever had a Social Security number (SSN). Chuck Borges, the former chief data officer of the Social Security Administration (SSA), resigned in August and filed a complaint alleging that employees of the Department of Government Efficiency (DOGE) uploaded a copy of the SSA’s database to an unsecured cloud environment. According to Borges, the breach if confirmed could leave personal data, including names, SSNs, and addresses, vulnerable to fraud and exploitation, with long-term consequences for millions of Americans. He has called for a congressional investigation into the alleged mismanagement, framing the incident as a severe threat to national security. The SSA has not publicly confirmed the breach, but the whistleblower’s claims highlight critical vulnerabilities in government data handling. If verified, the exposure could have far-reaching implications for identity theft, financial fraud, and cybersecurity risks across the U.S. The incident underscores ongoing concerns about federal agencies’ ability to safeguard sensitive citizen data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names, SSNs, AddressesSystems Affected: SSA DatabaseBrand Reputation Impact: SevereLegal Liabilities: PotentialIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Number Of Records Exposed: Potentially all Americans with an SSNSensitivity Of Data: HighPersonally Identifiable Information: Names, SSNs, Addresses
FEBRUARY 2026
771Before Incident
Cyber Attack
01 Feb 2026Stryker
Stryker: Iran-linked ransomware gang targeted US healthcare org amid military conflict

Iranian-Linked Pay2Key Ransomware Targets U.S. Healthcare Organization

749After Incident
CRITICAL-22
STR1774369485
Iranian-Linked Pay2Key Ransomware Targets U.S. Healthcare Organization Amid Rising Cyber Conflict In late February, an unnamed U.S. healthcare organization fell victim to a ransomware attack by Pay2Key, a strain linked to Iranian state-affiliated cyber actors. The incident, investigated by Beazley Security and Halcyon Ransomware Research Center, revealed significant upgrades to the ransomware, making it harder to detect and more destructive. Unlike typical financially motivated attacks, this intrusion showed no evidence of data exfiltration a departure from previous Pay2Key operations, which U.S. intelligence agencies had tied to espionage. Researchers noted the group’s activity surged following recent U.S.-Iran military tensions, suggesting motivations beyond profit, including strategic disruption. The attackers compromised an administrative account days before deploying the ransomware, then attempted to erase logs to cover their tracks. Cynthia Kaiser, Halcyon’s senior vice president and former FBI Cyber Division official, questioned whether the attack was timed to exploit geopolitical chaos, emphasizing the group’s dual role as both a state-aligned actor and a ransomware-as-a-service (RaaS) operator. Pay2Key has undergone significant shifts in recent months. In mid-2025, the group marketed itself on Russian cybercriminal forums, briefly offering to sell its operations for 0.15 BTC while recruiting affiliates with an 80% ransom split up from 70%. Despite internal upheaval, the group remains active, with Morphisec tracking $4 million in ransom payments over four months and a total of $8 million from 170 victims since then. First identified in 2020, Pay2Key has targeted organizations in the U.S., Israel, Azerbaijan, and the UAE, with ransom payments traced to Excoino, an Iranian cryptocurrency exchange requiring national ID verification. A 2024 U.S. advisory highlighted its coordination with other ransomware gangs, reinforcing its ties to Iranian government operations. The healthcare attack preceded a high-profile wiper attack on Stryker, a U.S. medical device company, claimed by the Iranian group Handala, which wiped 200,000 devices. Kaiser warned that unreported Iranian cyberattacks are likely ongoing, with a mix of ransomware, wiper malware, and critical infrastructure targeting expected as tensions persist.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Strategic disruptionGeopolitical tensions
IMPACT
Operational Impact: Disruption of healthcare services
DATA BREACH
Data Exfiltration: No evidence of data exfiltrationData Encryption: Yes
Cyber Attack
01 Feb 2026Stryker
Stryker: U.S. medical equipment company Stryker says cyberattack disrupted its global networks

Stryker Cyberattack Disrupts Global Medical Equipment Operations

749After Incident
CRITICAL-22
STR1773260617
Stryker Cyberattack Disrupts Global Medical Equipment Operations U.S.-based medical technology giant Stryker confirmed that a cyberattack disrupted its global networks, impacting operations across its systems. The incident, disclosed in recent reports, highlights growing cybersecurity threats targeting critical healthcare infrastructure. Stryker, a leading manufacturer of surgical equipment, implants, and medical devices, has not released details on the nature of the attack, its origin, or whether ransomware or data exfiltration was involved. The company has not specified the duration of the disruption or the extent of the operational impact, though such incidents often lead to delays in production, supply chain interruptions, and potential risks to patient care. The attack underscores the vulnerability of healthcare and medical device companies to cyber threats, which have increasingly become high-value targets for malicious actors. No further updates on recovery efforts or regulatory responses have been provided at this time.
INCIDENT DETAILS -
TYPE
cyberattack
IMPACT
Systems Affected: global networksOperational Impact: delays in production, supply chain interruptions, potential risks to patient care
JANUARY 2026
771Before Incident
DECEMBER 2025
770Before Incident
NOVEMBER 2025
768Before Incident
OCTOBER 2025
767Before Incident
SEPTEMBER 2025
765Before Incident
MARCH 2025
766Before Incident
Cyber Attack
28 Mar 2025Stryker
Stryker: Stryker shares fall after report on suspected Iran-linked cyberattack

Stryker Hit by Suspected Iran-Linked Cyberattack, Causing Global Outages

755After Incident
CRITICAL-11
STR1773246684
Stryker Hit by Suspected Iran-Linked Cyberattack, Causing Global Outages Medical technology giant Stryker suffered a global system outage on March 10, 2025, following a suspected cyberattack linked to an Iran-backed hacking group. The incident began shortly after midnight on the U.S. East Coast, disrupting operations across the company’s network. According to reports, remote devices running Microsoft Windows including laptops and mobile devices connected to Stryker’s systems were wiped, rendering them inoperable. Employees and contractors reported seeing the logo of Handala, a pro-Palestinian hacking group with alleged ties to Iran, on login screens, though Reuters could not independently verify the claim. The attack triggered a 3% drop in Stryker’s stock price after The Wall Street Journal first reported the breach. The company has not yet issued an official response to requests for comment. Stryker, a major supplier of medical equipment, operates globally, with facilities including a plant in Carrigtwohill, Ireland. The full extent of the disruption and potential data compromise remains unclear.
INCIDENT DETAILS -
TYPE
Cyberattack
MOTIVATION
Political (pro-Palestinian)
IMPACT
Systems Affected: Remote devices running Microsoft Windows (laptops, mobile devices)Downtime: Global system outageOperational Impact: Disrupted operations across the company’s networkBrand Reputation Impact: 3% drop in stock price
DECEMBER 2024
772Before Incident
Cyber Attack
05 Dec 2024Stryker
Stryker and Federal Bureau of Investigation: Pro-Iranian group claims credit for hacking into FBI Director Patel's personal account

Pro-Iranian Hackers Claim Breach of FBI Director’s Personal Account

761After Incident
CRITICAL-11
STRFBI1774644063
Pro-Iranian Hackers Claim Breach of FBI Director’s Personal Account A pro-Iranian hacking group, Handala, announced on Friday that it had compromised an account belonging to FBI Director Kash Patel, releasing decades-old personal photographs, a resume, and other documents online. The group, which has ties to Iran and Palestine, posted a statement alongside the materials, taunting Patel and declaring him among their "successfully hacked victims." The leaked files including images of Patel with a vintage sports car and a cigar appear to date back over a decade, primarily involving personal travel and business records. The FBI confirmed awareness of the incident, stating that the exposed data was historical and contained no classified or government information. The bureau added that it had taken steps to mitigate risks from the breach. The timing of the hack remains unclear, though reports from December 2024 indicated Patel had been previously warned by the FBI about Iranian targeting efforts. Handala, which has escalated its cyber operations in recent months, recently claimed responsibility for disrupting systems at Stryker, a Michigan-based medical technology firm, in retaliation for alleged U.S. airstrikes linked to Iranian civilian casualties. The group has been a persistent threat, with the U.S. Justice Department seizing four web domains tied to its operations last week as part of efforts to counter Iranian cyber campaigns. The Trump administration has also offered a $10 million reward for information leading to the identification of Handala members. The incident underscores the growing role of proxy hacking groups in Iran’s broader cyber conflict with Western targets.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation for alleged U.S. airstrikes linked to Iranian civilian casualties, cyber conflict with Western targets
IMPACT
Data Compromised: Personal photographs, resume, and other personal documentsBrand Reputation Impact: Potential reputational harm to FBI DirectorIdentity Theft Risk: Possible risk due to exposure of personal documents
DATA BREACH
Type Of Data Compromised: Personal photographs, resume, personal documentsSensitivity Of Data: Low (historical, no classified or government information)Data Exfiltration: YesImagesDocumentsPersonally Identifiable Information: Yes
MAY 2024
798Before Incident
Breach
01 May 2024Stryker
Stryker Corporation

Stryker Corporation Cybersecurity Incident

762After Incident
HIGH-36
STR200080525
The Vermont Office of the Attorney General reported that Stryker Corporation experienced a cybersecurity incident on June 10, 2024. The breach involved unauthorized access to Stryker internal systems between May 14, 2024, and June 10, 2024, affecting an unspecified number of individuals and potentially compromising personal information including names. A notification letter was included with the report.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Names
DATA BREACH
Personal InformationNames
JANUARY 2024
819Before Incident
Cyber Attack
01 Jan 2024Stryker
Stryker: Hospital cyber attacks are increasingly hitting patient care

European Hospitals Face Escalating Cyber Threats to Patient Care

795After Incident
CRITICAL-24
STR1779114633
European Hospitals Face Escalating Cyber Threats to Patient Care, Survey Reveals A new report from Black Book Research highlights a stark shift in the cybersecurity risks facing European hospitals, where attacks are no longer just about data breaches or IT disruptions but now pose direct threats to clinical operations. Based on a survey of 284 hospital cybersecurity decision-makers, 82% rate their 2026 cyberattack risk as "very high" or "extreme," while 74% expect a major incident within the year. The findings underscore a growing concern: cyberattacks are increasingly targeting the availability and integrity of critical healthcare systems, from emergency departments to ICUs, rather than just stealing data. Hospitals operate in a uniquely vulnerable environment aging infrastructure, cross-border supplier networks, strict regulatory pressures, and cloud migration all while relying on digital workflows that cannot afford downtime. Attackers are exploiting these weaknesses, focusing on authentication failures, recovery delays, third-party dependencies, and fragile clinical processes. In response, European hospitals are reallocating cybersecurity investments toward clinical continuity, with 66% prioritizing identity and access management (IAM, PAM, SSO failover), 57% boosting ransomware recovery and immutable backups, and 51% adopting zero trust and network segmentation. Other key areas include third-party risk management (45%), medical device security (37%), and resilience training (29%). Despite these efforts, gaps remain. While 78% of hospital boards receive cybersecurity updates, only 31% review resilience metrics tied to clinical operations. Alarmingly, only 25% conducted a full clinical downtime simulation in the past year, and 32% have never run one or rely solely on tabletop exercises. Confidence in operational resilience is also low: 59% believe their hospitals can function safely for 24 hours without core Electronic Health Record (EHR) access, but that drops to 32% at 48 hours and just 14% at 72 hours. Experts warn that prolonged downtime beyond 48 hours risks patient safety, disrupting medication reconciliation, lab results, radiology, pharmacy verification, and discharge planning. Recent incidents reflect this trend. A 2024 ransomware attack on NHS pathology provider Synnovis and a "destructive" (non-ransomware) attack on medical tech firm Stryker demonstrate how cyber threats are evolving from financial extortion to direct sabotage of healthcare delivery. As one expert noted, "The cyber battleground has moved from the server room to the bedside."
INCIDENT DETAILS -
TYPE
ransomwaredestructive attack
MOTIVATION
disruption of clinical operationssabotage of healthcare deliveryfinancial extortion
IMPACT
Electronic Health Record (EHR)emergency departmentsICUspathology systemsmedical devicespharmacy verificationlab resultsradiologydischarge planning24 hours (59% confidence)48 hours (32% confidence)72 hours (14% confidence)Operational Impact: Disruption of medication reconciliation, lab results, radiology, pharmacy verification, and discharge planning; risk to patient safety during prolonged downtime
Cyber Attack
01 Jan 2024Stryker
Stryker: Handala Hack Uses RDP, NetBird, and Parallel Wipers in MOIS-Linked Destructive Intrusions

Iranian Threat Actor Handala Hack Launches Destructive Cyberattacks Across Israel, Albania, and the U.S.

795After Incident
CRITICAL-24
STR1773714231
Iranian Threat Actor Handala Hack Launches Destructive Cyberattacks Across Israel, Albania, and the U.S. A cyber threat group linked to Iran’s Ministry of Intelligence and Security (MOIS), known as Handala Hack (also tracked as Void Manticore, Red Sandstorm, and Banished Kitten), has executed a series of data-destructive attacks targeting organizations in Israel, Albania, and the United States. Unlike traditional espionage-focused operations, the group’s campaigns are designed to permanently erase data, making recovery nearly impossible. Active since late 2023, Handala Hack operates under multiple public-facing personas, including Homeland Justice (used since mid-2022 against Albanian government and telecom sectors) and Karma (now largely replaced by Handala). Recent attacks expanded to the U.S., with medical technology firm Stryker among the confirmed victims. ### Attack Methods and Evolution Check Point researchers identified consistent yet evolving tactics in the group’s operations. While core techniques such as compromised VPN credentials, RDP exploitation, and simultaneous wiper deployments have remained stable since 2024, newer campaigns incorporate: - NetBird, a legitimate peer-to-peer networking tool, to tunnel traffic within victim networks. - An AI-assisted PowerShell script as part of its wiping toolkit. - A decline in operational security, with attacks traced directly to Iranian IP addresses instead of commercial VPNs. ### Multi-Layered Destruction Handala Hack’s destructive phase employs four simultaneous wiping techniques to maximize damage: 1. Handala Wiper – A custom tool distributed via Group Policy logon scripts (`handala.bat`), overwriting files and corrupting Master Boot Records (MBR). The executable runs remotely from domain controllers, evading detection. 2. AI-PowerShell Wiper – Deletes user directory files and floods drives with a propaganda image (`handala.gif`). 3. VeraCrypt Abuse – Legitimate encryption software is downloaded via the victim’s browser to lock drives and prevent recovery. 4. Manual Deletion – Attackers delete virtual machines and files over RDP, a tactic documented in leaked videos. ### Tactical Execution Intrusions typically begin with compromised VPN credentials, obtained through brute-force attacks or supply chain breaches. Once inside, operators use RDP to navigate manually, deploying multiple attacker-controlled machines within a single environment to accelerate destruction. The group’s lack of operational discipline including direct use of Iranian IPs has made attribution easier. The attacks reflect a shift from espionage to pure sabotage, with no financial or intelligence-gathering motives. Instead, the focus is on maximizing disruption across critical sectors.
INCIDENT DETAILS -
TYPE
Data Destruction / Wiper Attack
MOTIVATION
Sabotage and disruption
IMPACT
Data Compromised: Permanent data erasureMaster Boot Records (MBR)User directoriesVirtual machinesEncrypted drivesOperational Impact: Severe disruption across critical sectors
DATA BREACH
Type Of Data Compromised: Permanently erased dataData Encryption: VeraCrypt abuse for drive encryption
MAY 2023
828Before Incident
Cyber Attack
03 May 2023Stryker
Stryker: Pro-Iran hacking group claims responsibility for cyberattack on Stryker

Stryker Hit by Cyberattack Claimed by Pro-Iran Hacking Group Handala

817After Incident
CRITICAL-11
STR1773268034
Stryker Hit by Cyberattack Claimed by Pro-Iran Hacking Group Handala Medical technology firm Stryker, a leading manufacturer of surgical tools and medical implants based in Kalamazoo, Michigan, confirmed a cyberattack on Wednesday that disrupted its global Microsoft environment. The company stated it had no evidence of ransomware or malware and believed the incident was contained, though it is still assessing the impact. Continuity measures remain in place to support customers and partners. The pro-Iran hacking group Handala claimed responsibility for the attack, alleging it wiped over 200,000 systems, servers, and mobile devices and exfiltrated 50 terabytes of critical data. The group cited retaliation for the ongoing regional conflict and a February 28 airstrike on a girls' elementary school in Minab, Iran, which killed 168 people, as motivations. While the attack’s origins remain unconfirmed, U.S. military operations were reported near the site. Stryker has not disclosed further details, and U.S. officials have not commented on the incident. The investigation is ongoing.
INCIDENT DETAILS -
TYPE
Cyberattack
MOTIVATION
Retaliation for ongoing regional conflictFebruary 28 airstrike on a girls' elementary school in Minab, Iran
IMPACT
Data Compromised: 50 terabytesSystems Affected: 200,000 systems, servers, and mobile devicesOperational Impact: Disrupted global Microsoft environment
DATA BREACH
Type Of Data Compromised: Critical dataData Exfiltration: 50 terabytes
JULY 2016
831Before Incident
Cyber Attack
19 Jul 2016Stryker
Stryker, Dubai Courts, Dubai Land Department and PSK Wind Technologies: Iran-linked group Handala claims to have breached three major UAE organizations

Iran-Linked Handala Claims Cyberattacks on Three Major UAE Organizations

816After Incident
CRITICAL-15
STRTWEDUBDUB1776084002
Iran-Linked Handala Claims Cyberattacks on Three Major UAE Organizations On April 13, 2026, the Iran-aligned hacking group Handala announced a series of cyberattacks targeting three key UAE institutions: Dubai Courts, Dubai Land Department, and Dubai Roads & Transport Authority. The group claimed to have destroyed 6 petabytes of data and stolen 149 terabytes of sensitive information, framing the breach as retaliation against the UAE’s alleged alignment with Western and Israeli interests. In a statement posted on its Tor-based website, Handala described the attack as a "preemptive warning" to regional governments, citing the UAE’s perceived betrayal of the "Resistance Axis" a term often associated with Iran-backed factions. While the group’s claims remain unverified, its history of destructive operations lends credibility to the allegations. Handala, widely believed to be a front for Iran-backed Void Manticore, has a track record of phishing, data theft, extortion, and wiper attacks, often blending cyber operations with psychological warfare. Since the February 2026 escalation of U.S.-Israeli tensions with Iran, the group has intensified its activities, targeting Israeli military servers, intelligence personnel, and defense contractors. Recent attacks include: - A breach of PSK Wind Technologies, an Israeli defense and IT firm specializing in command-and-control systems (early April 2026). - A destructive attack on medical tech giant Stryker, where Handala claimed to have wiped over 200,000 devices across 79 countries and exfiltrated 50TB of corporate data all without deploying traditional malware. - The alleged hack of FBI Director Kash Patel’s personal Gmail account, with the group releasing purported photos and files. The FBI has offered a $10 million reward for information leading to the identification of Handala’s operatives, underscoring the group’s growing threat to critical infrastructure and national security.
INCIDENT DETAILS -
TYPE
Data DestructionData TheftExtortion
MOTIVATION
Political RetaliationPsychological Warfare
IMPACT
Data Compromised: 149 terabytes of sensitive informationOperational Impact: Destruction of 6 petabytes of data
DATA BREACH
Type Of Data Compromised: Sensitive informationSensitivity Of Data: HighData Exfiltration: 149 terabytes
JANUARY 2010
833Before Incident
Cyber Attack
01 Jan 2010Stryker
Stryker and Federal Bureau of Investigation: FBI Director Kash Patel’s email leaked by Iran-backed hackers

Iran-Linked Hackers Leak FBI Director Kash Patel’s Personal Emails in Cyber Espionage Campaign

818After Incident
CRITICAL-15
FEDSTR1774629686
Iran-Linked Hackers Leak FBI Director Kash Patel’s Personal Emails in Cyber Espionage Campaign On March 27, 2026, the Iran-backed hacking group Handala Hack Team publicly released a trove of personal emails belonging to FBI Director Kash Patel, marking a high-profile breach in a series of cyber operations attributed to Iranian state-linked actors. The leaked correspondence, spanning from 2010 to 2019, includes a mix of personal and professional communications tied to Patel’s Gmail account, which had been previously exposed in other data breaches. Western cybersecurity researchers identify Handala as one of several personas used by Iranian government cyberintelligence units, which have recently escalated attacks on Western targets. Earlier this year, the group claimed responsibility for hacking Stryker, a U.S. medical devices manufacturer, further demonstrating its focus on high-value entities. The hackers published photographs of Patel alongside the leaked documents, declaring him among their "successfully hacked victims." A U.S. Justice Department official confirmed the breach, stating that the released material appeared authentic. While the full extent of the compromise remains unclear, the incident underscores the persistent threat posed by state-sponsored cyber espionage, particularly from Iranian-linked groups targeting U.S. officials and critical infrastructure.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber Espionage, Intelligence Gathering
IMPACT
Data Compromised: Personal and professional emails (2010-2019)Systems Affected: Personal email account (Gmail)Brand Reputation Impact: High (FBI Director)Identity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Emails, Personal PhotographsSensitivity Of Data: High (Personal and Professional Communications)Data Exfiltration: YesEmailsImagesPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Stryker ?
?
What was Stryker's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Stryker's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Stryker's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Stryker's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Stryker's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Stryker's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Stryker ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Stryker's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?