Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Stryker Cyberattack 2026: How One Hijacked Admin Account…
Breach analysis Incident: 11 Mar 2026

Stryker Cyberattack 2026: How One Hijacked Admin Account Used Microsoft Intune to Wipe Tens of Thousands of Devices

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 12 min read
On this page

In the early hours of 11 March 2026, attackers used Stryker's own Microsoft Intune endpoint management service to send remote wipe commands to the medical technology company's devices. A source familiar with the attack told BleepingComputer that nearly 80,000 devices were erased in about three hours, after the attacker compromised an administrator account and created a new Global Administrator account. The Iran-linked group Handala claimed the attack and said it wiped more than 200,000 systems in 79 countries; those figures are the group's own and Stryker has not confirmed them. Stryker says no ransomware or malware was deployed and the incident stayed inside its internal Microsoft environment, but order processing, manufacturing and shipping were disrupted and the company later reported a material impact on its first quarter results. The Stryker attack shows what happens when one privileged cloud administrator identity can issue destructive commands to an entire device fleet with no second check.

Key takeaways

  • Stryker identified the incident on 11 March 2026 and described it as a "global network disruption to our Microsoft environment", with no indication of ransomware or malware.
  • According to BleepingComputer's source, the attacker compromised an administrator account, created a new Global Administrator account and used Intune's wipe command against nearly 80,000 devices between 05:00 and 08:00 UTC.
  • Handala claimed more than 200,000 systems wiped, offices in 79 countries shut down and 50 TB of data stolen. These are attacker claims; BleepingComputer's source said there was no indication that data was exfiltrated.
  • The US Justice Department says Handala is a persona operated by Iran's Ministry of Intelligence and Security (MOIS), and seized four related domains on 19 March 2026. CISA urged organisations to harden endpoint management systems on 18 March.
  • Lesson: management consoles are privileged infrastructure. Least privilege, phishing-resistant MFA and multi-admin approval for bulk destructive actions would have made a single stolen admin identity far less dangerous.

At a glance

OrganisationStryker Corporation, a US medical technology company
WhenDevices wiped on 11 March 2026; Stryker fully operational across its manufacturing network by 1 April 2026
AttackerHandala, which claimed the attack; the US Justice Department says Handala is operated by Iran's Ministry of Intelligence and Security
Entry pointA compromised administrator account in Stryker's Microsoft environment (how that account was first compromised has not been published)
Identities abusedAn existing administrator account, a newly created Global Administrator account, and the Intune administrative rights used to issue wipe commands
ImpactNearly 80,000 devices wiped according to a source cited by BleepingComputer (Handala claimed more than 200,000); disruption to ordering, manufacturing and shipping; material impact on first quarter 2026 results, according to Stryker
CategoryHuman identity (privileged cloud administrator), destructive attack

What happened

On 11 March 2026, Stryker said it was experiencing a "global network disruption to our Microsoft environment as a result of a cyber attack". The company said there was no indication of ransomware or malware and that the incident was contained. KrebsOnSecurity reported the same day that the Irish Examiner said more than 5,000 workers at Stryker's Irish hub had been sent home, and that users claiming to be Stryker employees said on Reddit they had been told to uninstall Intune urgently. A trusted source told KrebsOnSecurity that the attackers appeared to have used Intune "to issue a 'remote wipe' command against all connected devices".

Handala claimed responsibility on Telegram. According to KrebsOnSecurity, the group said it had "erased data from more than 200,000 systems, servers and mobile devices" and that "Stryker's offices in 79 countries have been forced to shut down". Handala framed the attack as retaliation for a strike on a school in Iran on 28 February, and pointed to Stryker's 2019 acquisition of the Israeli company OrthoSpace.

On 12 March, Stryker furnished a Form 8-K to the SEC. It said the incident had "resulted in a global disruption to the Company's Microsoft environment", that its operations "continue to be disrupted, including its order processing, manufacturing and shipping", and that it did not believe patient-related services or connected products had been affected.

The clearest public account of the attack path came on 16 March. A source familiar with the attack told BleepingComputer that the threat actor "used the wipe command in Intune" to erase data from nearly 80,000 devices between 5:00 and 8:00 a.m. UTC on 11 March. The attacker did this "after compromising an administrator account and creating a new Global Administrator account." BleepingComputer also reported that some employees had enrolled personal devices and lost personal data in the wipe, that Microsoft's Detection and Response Team worked with Palo Alto Networks Unit 42 on the investigation, and that its source saw no indication that data was exfiltrated. How the first administrator account was compromised has not been made public.

Stryker's own updates stayed consistent on scope. On 15 March it said the event "was contained to Stryker's internal Microsoft environment" and did not affect any of its products. On 23 March it added a new detail: working with Unit 42 and other experts, it found that "the threat actor used a malicious file to run commands which allowed them to hide their activity while in our systems", while stating the file was not capable of spreading. The company said it had found no malicious activity directed at customers, suppliers, vendors or partners.

Government action followed quickly. On 18 March, CISA urged organisations to harden endpoint management systems, and Redmond Magazine reported that CISA worked with Microsoft and Stryker on the guidance. On 19 March, the Justice Department announced the seizure of four domains, including two Handala sites, which it said were "used by the MOIS in furtherance of attempted psychological operations". The release referred to a destructive attack on "a U.S.-based multinational medical technologies firm" without naming Stryker.

On 1 April Stryker said it was "fully operational across our global manufacturing network". In April, Cybersecurity Dive reported that Stryker had told investors the attack had a material impact on its first quarter 2026 earnings, although it did not expect a material impact on its full-year results.

Timeline

DateEvent
11 March 2026, 05:00 to 08:00 UTCNearly 80,000 devices wiped through Intune, according to BleepingComputer's source, after an administrator account is compromised and a new Global Administrator account created.
11 March 2026Stryker reports a global disruption to its Microsoft environment; Handala claims the attack on Telegram.
12 March 2026Stryker furnishes an 8-K update; operations including order processing, manufacturing and shipping remain disrupted.
15 March 2026Stryker says the event was contained to its internal Microsoft environment and did not affect its products.
18 March 2026CISA urges organisations to harden endpoint management systems such as Intune.
19 March 2026US Justice Department seizes four domains, including two Handala sites, and attributes them to Iran's MOIS.
23 March 2026Stryker says the attacker used a malicious file to run commands and hide activity.
1 April 2026Stryker reports it is fully operational across its global manufacturing network.
By 10 April 2026Stryker discloses a material impact on first quarter earnings, according to Cybersecurity Dive.
30 April 2026Stryker reports first quarter results that fall short of analyst expectations, citing the attack.

How it happened: the identity attack path

  1. An administrator account is compromised. BleepingComputer's source says the attack began with a compromised administrator account in Stryker's Microsoft environment. The initial method (phishing, credential theft or something else) has not been published.
  2. A new Global Administrator is created. The attacker used that access to create a new Global Administrator account, the highest privilege level in a Microsoft Entra ID tenant. A new top-level admin identity under the attacker's control removed any dependence on the original victim account.
  3. Activity is hidden. Stryker says the attacker used a malicious file to run commands that concealed their activity while in its systems.
  4. The management plane becomes the weapon. With tenant-wide privilege, the attacker issued Intune wipe commands to enrolled devices. No wiper malware was needed on the endpoints because the legitimate device management service did the destruction.
  5. No second check on a bulk destructive action. Wiping tens of thousands of devices in about three hours implies that a single administrator identity could approve and run the action alone. CISA's guidance, issued a week later, specifically calls for a second administrator's approval for actions such as device wipes.
  6. Personal devices caught in the blast radius. Because some employees had enrolled personal devices, the wipe reached their personal data too, according to BleepingComputer.

Impact

  • Devices: nearly 80,000 devices wiped, according to a source familiar with the attack cited by BleepingComputer. Handala claimed more than 200,000 systems, servers and mobile devices and offices in 79 countries shut down; neither figure has been confirmed by Stryker.
  • Data: Handala claimed to have stolen 50 TB of data. BleepingComputer's source said there was no indication of exfiltration, and Stryker says its analysis found no evidence the attacker accessed customer, supplier, vendor or partner systems.
  • Operations: Stryker's 8-K described disruption to order processing, manufacturing and shipping. Stryker says its connected medical products were not affected and remained safe to use.
  • Financial: Stryker reported a material impact on first quarter 2026 results. Medical Device Network reported first quarter revenue of just over $6 billion against analyst expectations of $6.35 billion, with the company citing shipment delays and lost manufacturing absorption, while keeping its full-year outlook.

What this means for identity security

Stryker is a privileged identity breach, not a malware outbreak. By the account BleepingComputer published, the attacker never needed to plant a wiper on 80,000 endpoints. They needed one administrator identity with enough reach to create another, more powerful one, and a device management platform willing to act on that identity's instructions at scale.

That shifts the question from "was there malware?" to "who can do what, and does anyone check?". Standing Global Administrator rights, the ability to create new top-tier admins without an alert or approval, and bulk destructive actions that one account can run alone are all identity governance gaps. CISA's three themes after the attack were least-privilege role design in Intune, phishing-resistant MFA and Conditional Access for privileged accounts, and multi-admin approval for sensitive changes. All three are about constraining what a single administrator identity can do.

The same pattern runs through other recent intrusions. In Storm-2949, one cloud identity became control of a whole Azure estate. Automation and service identities with Intune or Graph permissions deserve the same scrutiny, because an app registration with device management rights could issue the same commands as a human administrator.

Recommendations

  • Require multi-admin approval for destructive actions. CISA recommends policies that "require a second administrative account's approval" for changes such as device wipes, scripts, app deployment and role changes. In Intune this is Multi Admin Approval.
  • Remove standing Global Administrator rights. Keep top-tier roles to a minimum, grant them just in time with approval and time limits, and alert on every new Global Administrator assignment. The JIT Access and Zero Standing Privilege Guide and the Privileged Access Management Guide cover the model.
  • Scope Intune roles tightly. Use role-based access control and scope tags so that no single role can wipe the whole fleet, and separate day-to-day device support from tenant administration.
  • Use phishing-resistant MFA and Conditional Access for admins. Require phishing-resistant authentication and compliant, dedicated admin devices for privileged roles, as set out in the Active Directory and Entra ID Hardening Guide.
  • Protect and test break-glass access. Emergency accounts must survive a tenant compromise and be monitored closely, following the Break-Glass Emergency Access Guide.
  • Audit non-human identities with management rights. Review app registrations and service principals that hold Intune or Microsoft Graph device management permissions, and remove any that are not needed.

Frequently asked questions

What happened in the Stryker cyberattack?

On 11 March 2026, attackers used Stryker's Microsoft Intune service to remotely wipe company devices. A source cited by BleepingComputer said nearly 80,000 devices were wiped after the attacker compromised an administrator account and created a new Global Administrator account. The Iran-linked group Handala claimed the attack.

Did Handala really wipe 200,000 devices in 79 countries?

Those figures come from Handala's own claim and have not been confirmed by Stryker. The most specific independent figure is BleepingComputer's report, based on a source familiar with the attack, of nearly 80,000 devices wiped.

Were Stryker's medical products or patient data affected?

Stryker says the incident was contained to its internal Microsoft environment and did not affect any of its products, connected or otherwise. It says its investigation found no evidence the attacker accessed customer, supplier, vendor or partner systems.

Storm-2949 Azure breach · Jaguar Land Rover cyberattack 2025 · Change Healthcare breach 2024 · Human vs Non-Human Identity · NHI breaches

How NHI Mgmt Group can help

The Stryker attack shows that any identity, human or non-human, holding tenant-wide management rights can turn trusted tooling into a weapon. Our NHI Foundation Level Training Course helps teams find, scope and govern the privileged identities, service principals and automation accounts that sit behind their management platforms.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org