At 3:30 in the morning on March 11, Stryker Corporation’s IT administrators were not the first to notice something was wrong. Their devices were.
Across 79 countries, more than 200,000 corporate laptops, tablets and phones began reverting to factory settings simultaneously. No alarm triggered. No antivirus flagged anything. There was no malware to detect, because none was used. The attackers had done something more efficient: they walked in through the front door, picked up the keys to every device in the building and pressed delete.
The group responsible was Handala, an Iran-linked hacktivist collective that multiple threat intelligence firms, including Check Point Research and Palo Alto Networks, have confirmed has ties to Iran’s Ministry of Intelligence and Security. The Department of Justice formally attributed the attack to MOIS on March 21. The FBI seized four Handala domains, including Handala-Hack.to and Handala-Redwanted.to. The State Department put a $10 million bounty on information about the perpetrators. Hours after the seizure, Handala rebuilt their infrastructure and mocked the FBI on Telegram.
The vehicle for the attack was Microsoft Intune, a cloud-based device management platform that organisations use to push updates, enforce security policies and, when necessary, remotely wipe devices. That last function is exactly what Handala exploited. By compromising Stryker’s Intune administrator credentials, the group gained the ability to issue remote wipe commands to every device enrolled in the system. So they did.
Stryker, a $22 billion medical technology company whose products are present in hospitals across the world, confirmed the incident in an SEC 8-K filing, describing a “severe global disruption to the Company’s Microsoft environment.” The company’s stock dropped approximately 9% as the scale of the attack became clear. Manufacturing halted. Electronic ordering systems went offline. Offices shut down across 79 countries. Maryland paramedics lost the ability to transmit ECG data to hospitals because the Stryker platform that handles that transmission was down.
Before triggering the wipe, Handala claims to have exfiltrated 50 terabytes of data. That figure remains unconfirmed by Stryker, though the company has not disputed it publicly.
Security researchers at Lumos have noted that initial access appears to have been established months before the destructive phase. Check Point Research states that network access dates back several months before March 11. This matters because it means the attack was not opportunistic. It was planned, staged and timed. Handala described the attack as retaliation for a missile strike on a school in the Iranian city of Minab. The group had also listed Stryker as a target because of the company’s 2019 acquisition of Israeli medical device firm OrthoSpace.
The attack did not use a sophisticated exploit or a zero-day vulnerability. It used stolen credentials and a legitimate cloud management platform that was designed to do exactly what it did. That is the part security teams should be sitting with.
Stryker had a prior breach in 2024 involving unauthorised access between May and June, with personally identifiable information and medical records exfiltrated. That breach was not disclosed until December 2024. Whether persistence from that earlier compromise contributed to the March 2026 attack is still under investigation.
The technique Handala used has a name in the security research community: living off the land. Rather than deploying their own tools, attackers use the legitimate software already present in the target environment. It is harder to detect because there is nothing unfamiliar to flag. In Stryker’s case, the attackers used a legitimate Microsoft platform with legitimate administrator credentials to issue legitimate remote wipe commands. Every step looked exactly like normal IT operations.
What organisations should take from this is not that Microsoft Intune is insecure. It is that any platform capable of pushing commands to thousands of devices simultaneously becomes a weapon if someone can obtain admin credentials. Device management systems, cloud management consoles and identity platforms now carry an outsized level of risk because of the surface area they control.

Leave a Reply