Cyberattack Tied to Iran Knocks US Medical Firm Offline and Disrupts Global Operations


Employees arrived at work to find their login pages replaced with the logo of a hacker group. Phones and laptops connected to Stryker’s global network had been wiped clean. Stryker, one of the largest medical device companies in the world, confirmed it was “experiencing a global network disruption to our Microsoft environment as a result of a cyberattack.” What happened next would signal something unprecedented: a significant Iranian-linked cyberattack against an American company, and a warning that the war had crossed into a new domain.
Stryker makes everything from artificial joints and surgical instruments to hospital beds and robotic surgery systems. The company reported revenues of more than $25 billion in 2025 and says its products reach more than 150 million patients annually across 61 countries. The disruption was not limited to a single office or country. Employees were told not to log on to their computers or connect to any Stryker mobile apps, as a severe and widespread outage affected laptops and systems across the company’s entire global network. The scale of it stunned those watching from inside and outside the company.
The hacker group behind the attack, Handala, claimed it had forced 79 offices across the world to shut down, wiping over 200,000 systems, servers and mobile devices, and stealing 50 terabytes of data. Stryker initially said it found no evidence of malware. But as investigators dug deeper, a more complex and troubling picture began to emerge, one that exposed how Iranian-linked hackers had quietly positioned themselves inside one of America’s most critical medical supply chains.
A Hacker Group With Iran’s Fingerprints All Over It

Handala, also known as Handala Hack Team and Void Manticore, is a group known to deploy wiper malware as well as credential-stealing tools, and focuses on politically motivated cyber operations against Israeli-linked targets. The Justice Department later described its websites as platforms used for “psychological operations,” including claiming cyberattacks, leaking stolen data, and threatening dissidents, journalists, and Israeli-linked organizations. This was not a fringe group. It had institutional backing.
The FBI issued an alert describing malware linked to the group, which included masquerading software disguised as common applications like Pictory, KeePass, and Telegram. These were used to deploy persistent implants deeper into victim systems. Researchers noted significant overlap between Handala and Scarred Manticore, an advanced persistent threat group linked to Iran’s Revolutionary Guard Corps. The group’s reach extended well beyond Stryker. An email account tied to Handala was used to send death threats to Iranian dissidents around the world, with messages claiming the group was coordinating with a Mexican cartel to target its enemies.
Handala claimed the Stryker attack was carried out in retaliation for what it described as the brutal attack on the Minab school, referring to a strike the US military reportedly carried out on a girls’ school in southern Iran, killing more than 175 people, most of them children. According to IBM X-Force Exchange tracking, Handala’s operations focus on generating disruptive and psychological impact. Its campaigns consistently feature ideological messaging, inflated or misleading breach claims, and deliberate targeting of life-critical sectors such as healthcare and energy. The attack on Stryker fit that profile almost perfectly.
How Hackers Turned a Remote Management Tool Into a Weapon

Rather than deploying wiper malware, investigators found that the hackers used Microsoft Intune, a legitimate corporate tool for remotely managing desktop devices and mobile phones, to push operating system reset commands across Stryker’s network. Gaining access to Intune requires administrator-level credentials, pointing to a well-resourced and experienced threat actor. There is also evidence suggesting the hackers obtained these credentials through infostealer malware introduced earlier in the operation. The breach had been carefully prepared long before anyone noticed.
According to Rafe Pilling, director of threat intelligence at cybersecurity firm Sophos, the hackers “seem to have obtained access to the Microsoft Intune management console,” and from there triggered the remote wipe feature for some or all enrolled devices. Stryker later confirmed that a malicious file had been identified during investigation, which the threat actor used to run commands and conceal their activity while inside company systems. The company stressed the file was not capable of spreading inside or outside its environment. Even so, the damage had already been done across dozens of countries.
In an FBI affidavit, agents confirmed that a separate Handala cyberattack had disrupted hospital systems in Maryland, with healthcare providers proactively suspending connections to tools used to analyze patient data and vital signs, and at least one employee’s computer wiped during the attack. The Stryker attack itself disrupted order processing, manufacturing, and shipping. Beyond business operations, the attack touched a medical supply chain that supports surgeries and patient care in dozens of countries, raising alarms about how exposed the healthcare sector really is to state-aligned cyber operations.
The FBI Strikes Back, But the Threat Is Far From Over

Days after the attack, the FBI seized Handala’s website, replacing it with a banner bearing the logos of the Justice Department and the FBI. The Justice Department announced it had seized four domains used by actors linked to Iran’s Ministry of Intelligence and Security, calling them tools for psychological operations run on behalf of a foreign state actor. The FBI’s action was carried out under a court-authorized warrant and linked to a broader Iranian cyber and psychological operations campaign, including a 2022 cyberattack on the government of Albania and the targeting of US defense company executives. Washington had drawn a clear line.
Gil Messing, Chief of Staff at Israeli cybersecurity company Check Point, said the FBI seizure was an important move, because most of Handala’s power came from publishing its work and amplifying the psychological effect of the damage, even when exaggerated. Removing their platforms hit them where it mattered most. But Messing also cautioned that it was likely part of an ongoing game of whack-a-mole, as the group had bypassed previous takedowns by launching new channels. Cybersecurity analysts noted that Stryker’s attack may have been opportunistic rather than planned, with hackers exploiting a weakness they stumbled upon rather than following a precise, targeted operation.
Stryker had received sizable contracts with the US military for hospital equipment and surgical supplies, and analysts noted that the Pentagon has long warned of complex cyberattacks against the defense industrial base, a vast network of companies with disparate levels of cybersecurity that adversaries view as a backdoor into military systems. The Stryker attack was contained. The FBI responded. But if one of the world’s largest medical device companies, serving 150 million patients across 61 countries, could be knocked offline through a single compromised management tool, the harder question isn’t whether it will happen again. It’s which company, which hospital, or which system is next.