TL;DR: Stryker’s March 2026 attack showed how valid Microsoft identity access can be turned into a non-encrypting wiper, with public reporting citing nearly 80,000 devices wiped through Intune and at least 50 terabytes of corporate data deleted. The incident demonstrates that perimeter controls and MFA alone do not stop privileged cloud administration abuse, according to SlashID.
Editorial analysis by NHI Mgmt Group, based on content published by SlashID: “Ready to start a top-tier security upgrade?”.
By the numbers:
- At least 50 terabytes of corporate data were deleted from internal storage.
Key questions
Q: What breaks when Intune wipe permissions are overexposed?
A: A compromised admin or delegated user can turn a normal management action into a destructive enterprise event.
Q: Why can MFA fail to stop a cloud admin takeover?
A: Because the attacker may reuse a valid post-authentication session rather than replaying the password or challenge.
Q: What are the signs that Microsoft admin access is being abused?
A: Look for first-time access to Intune, Graph, or Entra admin paths, abnormal admin volumes, unusual user agents, risky geolocation, impossible travel, and destructive actions such as bulk wipe or factory reset outside the normal change pattern.
Practitioner guidance
- Restrict mass device actions Separate routine endpoint administration from destructive functions such as wipe, factory reset, and bulk retire.
- Review privileged Microsoft roles Inventory which accounts can assign roles, grant Graph permissions, or operate Intune at scale.
- Detect session-based admin abuse Alert on first-time use of Intune, Graph, or Entra admin paths, unusual user agents, risky geolocations, impossible travel, and bulk device operations from a previously quiet account.
Bottom line: The Stryker incident shows how a valid Microsoft admin path can become a destructive wiper channel when the control plane is over-trusted.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity control-plane abuse is now a destructive attack class, not a management anomaly. The Stryker incident shows that a cloud device-management plane can be weaponised when a valid identity reaches native wipe and reset functions. This is not about malware delivery failure; it is about destructive authority being concentrated in the same identity layer used for routine administration. Practitioners should stop treating management-plane access as low-risk SaaS use and start treating it as a high-consequence control surface.
A question worth separating out:
Q: How should teams respond to a compromised Intune administrator account?
A: Treat it as a control-plane incident, not just an endpoint event. Revoke sessions, disable or reset the affected identity, remove risky role assignments, review recent Intune and Graph actions, and verify whether any bulk device commands or permission grants were issued before containment completed.
👉 Read our full editorial: Stryker’s Intune wiper attack exposes identity control-plane gaps