{"id":896448,"date":"2026-04-03T03:12:16","date_gmt":"2026-04-03T08:12:16","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2026\/04\/03\/medtech-giant-stryker-fully-operational-after-data-wiping-attack\/"},"modified":"2026-04-03T03:12:16","modified_gmt":"2026-04-03T08:12:16","slug":"medtech-giant-stryker-fully-operational-after-data-wiping-attack","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2026\/04\/03\/medtech-giant-stryker-fully-operational-after-data-wiping-attack\/","title":{"rendered":"Medtech giant Stryker fully operational after data-wiping attack"},"content":{"rendered":"<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Stryker\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2026\/04\/02\/Stryker.jpg\" width=\"1600\"><\/p>\n<p>Stryker Corporation, one of the world&#8217;s leading medical technology companies, says it&#8217;s fully operational three weeks after many of its systems were wiped out in a cyberattack claimed by the Iranian-linked Handala hacktivist group.<\/p>\n<p>The Fortune 500 medtech giant has over 53,000 employees, makes a wide range of products (including neurotechnology and surgical equipment), and reported global sales of $22.6 billion in 2024.<\/p>\n<p>The attackers\u00a0<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/medtech-giant-stryker-offline-after-iran-linked-wiper-malware-attack\/\" target=\"_blank\" rel=\"nofollow noopener\">began wiping Stryker&#8217;s systems<\/a>\u00a0on March 11, claiming\u00a0they had stolen 50 terabytes of data before wiping nearly 80,000 devices early that morning, using a new Global Administrator account created after compromising a Windows domain admin account.<\/p>\n<p>After the attack was disclosed, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-warns-businesses-to-secure-microsoft-intune-systems-after-stryker-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">CISA<\/a> and <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/intunecustomersuccess\/best-practices-for-securing-microsoft-intune\/4502117\" target=\"_blank\" rel=\"nofollow noopener\">Microsoft<\/a> released guidance on securing Intune and hardening Windows domains to block similar attacks, while the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack\/\" target=\"_blank\" rel=\"nofollow noopener\">FBI seized two websites<\/a> used by the Handala hackers.<\/p>\n<p>On Wednesday, Stryker announced that it had restored enough systems to return to pre-attack operational levels and that production would quickly reach full capacity.<\/p>\n<p>&#8220;As of this week, we are fully operational across our global manufacturing network. Production is moving rapidly toward peak capacity with discipline and stability, supported by restored commercial, ordering and distribution systems,&#8221; <a href=\"https:\/\/www.stryker.com\/us\/en\/about\/news\/2026\/a-message-to-our-customers-03-2026.html#:~:text=04%2F01%2F2026%2010%3A45%20a%2Em%2E%20ET\" target=\"_blank\" rel=\"nofollow noopener\">Stryker said<\/a>.<\/p>\n<p>&#8220;Overall product supply remains healthy, with strong availability across most product lines, as we continue to meet customer demand and support patient care.&#8221;<\/p>\n<p>&#8220;Our work continues around the clock in close partnership with third\u2011party cybersecurity experts, relevant government agencies and industry partners as our investigation progresses, reflecting a shared commitment to protecting the healthcare ecosystem and supporting ongoing recovery efforts,&#8221; it added.<\/p>\n<p>This comes after the company said on March 23 that its teams were prioritizing the restoration of systems that directly support customer, ordering, and shipping operations.<\/p>\n<p>Although it was initially believed the attackers hadn&#8217;t used any malicious tools during the breach, Stryker also revealed that security experts who helped with the investigation found a malicious file that helped the attackers hide malicious activity while inside the company&#8217;s network.<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/tag\/handala\/\" target=\"_blank\" rel=\"nofollow noopener\">Handala<\/a> (also known as Handala Hack Team, Hatef, Hamsa) surfaced in December 2023 as an Iranian-linked and pro-Palestinian hacktivist operation that has been targeting Israeli organizations with Windows and Linux data-wiping malware.<\/p>\n<p>The hacktivist group has been <a href=\"https:\/\/unit42.paloaltonetworks.com\/iranian-cyberattacks-2026\/\" target=\"_blank\" rel=\"nofollow noopener\">linked to Iran&#8217;s Ministry of Intelligence and Security (MOIS)<\/a> and is also known for leaking sensitive data stolen from victims&#8217; compromised systems.<\/p>\n<div>\n<p><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\"><br \/>\n            <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/p\/picus-whitepaper.jpg\" alt=\"tines\"><br \/>\n        <\/a>\n    <\/p>\n<div>\n<h2><a href=\"https:\/\/hubs.li\/Q048zztN0\" target=\"_blank\" rel=\"noopener sponsored\">Automated Pentesting Covers Only 1 of 6 Surfaces.<\/a><\/h2>\n<p>Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.<\/p>\n<p>This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/medtech-giant-stryker-fully-operational-after-data-wiping-attack\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Sergiu Gatlan<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Stryker Corporation, one of the world&#8217;s leading medical technology companies, says it&#8217;s fully operational three weeks after many of its systems were wiped out in a cyberattack claimed by the Iranian-linked Handala hacktivist group. The Fortune 500 medtech giant has over 53,000 employees, makes a wide range of products (including neurotechnology and surgical equipment), and<\/p>\n","protected":false},"author":1,"featured_media":896449,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[266,44669,46],"tags":[],"class_list":{"0":"post-896448","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-giant","8":"category-medtech","9":"category-technology"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/896448","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=896448"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/896448\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/896449"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=896448"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=896448"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=896448"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}