Update, March 21, 2026: The Department of Justice formally attributed the Stryker attack to Iran's Ministry of Intelligence and Security (MOIS). The FBI seized four Handala domains, including Handala-Hack.to and Handala-Redwanted.to. Hours later, Handala launched replacement infrastructure and mocked the seizure on Telegram. The State Department is offering $10 million for information on the perpetrators. See full details below.
The bottom line: At 3:30 AM EST on March 11, Iran-linked hackers triggered simultaneous factory resets on over 200,000 Stryker corporate devices across 79 countries. They didn't deploy malware. They hijacked Stryker's own Microsoft Intune device management platform and turned it into a weapon. In Maryland, paramedics lost the ability to transmit ECGs to hospitals. This is the most significant wartime cyberattack on a U.S. company since the Iran conflict began.
The Attack
Stryker is a $22 billion medical device company. Their products are in hospitals worldwide: surgical systems, defibrillators, hospital beds, EMS communication platforms. On March 11, 2026, the Iranian hacktivist group Handala compromised Stryker's Microsoft Intune administrator account and pushed a coordinated wipe to every enrolled device [1].
More than 200,000 systems (servers, mobile devices, and corporate endpoints across 79 countries) went dark simultaneously. The attackers didn't need sophisticated malware. They just needed admin credentials to a cloud management platform that was designed to remotely control devices.
Handala claimed to have exfiltrated 50 terabytes of data before the wipe, though that figure remains unconfirmed [2].
When Emergency Services Went Dark
Here's where this stops being an IT problem and starts being a patient safety crisis.
Stryker's Lifenet platform lets paramedics transmit ECG readings to hospitals in real time. When someone's having a heart attack, those seconds matter. Hospitals use the data to prep catheterization labs before the ambulance arrives.
Maryland's Institute for Emergency Medical Services Systems reported that Lifenet was "non-functional in most parts of the state" after the attack [3].
The workaround? Call the hospital on the radio and describe what you're seeing on the ECG. That's 2026 emergency medicine running on 1980s backup procedures.
Stryker later clarified that Lifenet and other connected devices were "not affected" by the attack, that the systems run on separate infrastructure [4]. But if Lifenet went down in Maryland, something in the communication chain broke. Whether it was network connectivity, supporting systems, or collateral damage from the broader IT meltdown, paramedics lost a critical tool.
They Used Stryker's Own Tools
Microsoft Intune is a mobile device management platform. Companies use it to push software updates, enforce security policies, and (if a device gets stolen) remotely wipe it.
Handala didn't break into individual devices. They compromised the master control panel and pushed legitimate wipe commands to everything at once. The devices did exactly what they were designed to do when receiving an authenticated wipe order from the central server.
Security researchers call this "living off the land": using legitimate tools for malicious purposes. Except in this case, they weren't living off the land. They were living in the cloud control plane.
Check Point Research and Palo Alto Networks confirmed ties between Handala and Iran's Ministry of Intelligence and Security (MOIS) [5]. The group first surfaced in late 2023 and is assessed to be a persona maintained by Void Manticore, an MOIS-affiliated threat actor.
Why Stryker?
Handala explicitly linked the attack to a February 28 missile strike that hit an elementary school in Iran, killing at least 175 people, most of them children, according to Iranian state media [6].
The group's statement framed the wiper attack as retaliation. Whether attacking a U.S. medical device company constitutes proportional response is a question for ethicists. What's clear is that civilian infrastructure on both sides is now fair game.
Stryker isn't a defense contractor. It makes surgical robots and hospital beds. But it's a high-profile American company with critical healthcare dependencies: the kind of target that causes maximum disruption without directly hitting military systems.
Stryker's Response
In updates posted March 12-15, Stryker emphasized several points [4]:
- No ransomware detected
- No malware identified
- The incident was "contained to Stryker's internal Microsoft environment"
- Connected medical devices (Mako surgical systems, LIFEPAK defibrillators, Vocera communications) were not affected
- External cybersecurity experts engaged
- Law enforcement collaboration initiated
CISA opened a formal investigation. Acting Director Nick Andersen is coordinating between public and private sector response teams [7].
Hospitals in Michigan took precautionary measures, temporarily pulling some Stryker equipment offline and switching to backup communication systems [7].
The Surveillance Angle
This attack demonstrates something we've been warning about: centralized control systems are single points of failure.
The same cloud management platforms that give IT departments visibility and control over devices also give attackers a force multiplier. Compromise one admin account, own 200,000 devices. It's not a bug in the system: it's the system working exactly as designed, just for the wrong person.
We've seen this pattern before:
- Israel hacked Tehran's traffic cameras and used them to track Ayatollah Khamenei before his assassination
- Iranian hackers are now targeting IP cameras across Gulf states for military intelligence
- The Salt Typhoon telecoms breach let Chinese hackers access U.S. wiretap systems
Every centralized system is a target. Medical device management. Telecom wiretaps. Traffic cameras. Building access systems. Smart city infrastructure. The more we consolidate control, the more catastrophic a single breach becomes.
DOJ Makes It Official: Iran's MOIS Behind Stryker Attack
On March 20, 2026, the Justice Department formally attributed the Stryker attack to Iran's Ministry of Intelligence and Security. The FBI seized four domains used by Handala [8]:
- Justicehomeland.org
- Handala-Hack.to
- Karmabelow80.org
- Handala-Redwanted.to
The seizure affidavit tied the domains together through shared infrastructure, Iranian IP ranges, and common operational patterns. This is the first time the U.S. government has formally attributed a major destructive cyberattack on American soil to MOIS during the current conflict.
What the FBI Found
Beyond the Stryker wiper, Handala's operations included:
- Death threats: Emails from Handala_Team@outlook.com offered "$250,000 for operatives who kills and beheads" targets and referenced "Mexican cartel partners"
- Doxxing: 190 Israeli Defense Force and government personnel names with PII posted with explicit threats
- Jewish community targeting: 851 gigabytes stolen from the Sanzer Hasidic community, accompanied by "No place is safe for you"
Handala's Response: We're Still Here
Hours after the seizure, Handala posted screenshots of their seized domains on Telegram and launched replacement infrastructure. According to threat intelligence firm Cyble, the new sites were operational within hours and looked identical to the originals [9].
Domain seizures are a symbolic gesture. They don't stop sophisticated threat actors. They give DOJ a press release while the hackers spin up new infrastructure from backup plans they'd already prepared.
The State Department's Rewards for Justice program is offering $10 million for information leading to the perpetrators. Whether anyone inside Iran's intelligence apparatus will risk their life for that bounty remains to be seen.
What to Watch
- Escalation: If Handala hit Stryker, what's next? Healthcare, energy, and financial systems are all potential targets
- CISA findings: How did Handala get admin credentials? Was this phishing, credential stuffing, or an insider?
- Policy response: Will this accelerate requirements for medical device cybersecurity?
- Iranian cyber capabilities: U.S. officials are warning more cyberattacks could follow. This may have been a proof of concept
Sources
- CNN - Pro-Iran hackers claim cyberattack on major US medical device maker
- Krebs on Security - Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
- Zeron - Stryker Cyberattack 2026: How Handala Wiped 200,000 Devices Overnight
- Stryker - A Message to Our Customers
- Check Point Research - Iranian Targeting of IP Cameras
- NBC News - Iran appears to have conducted significant cyberattack against U.S. company
- Digital Health News - Stryker Cyberattack Triggers Precautions Across Michigan Hospitals
- DOJ - Justice Department Disrupts Iranian Cyber Enabled Psychological Operations (March 20, 2026)
- The Cyber Express - Handala Hackers Launch New Domain Hours After FBI Seizure
Published: March 17, 2026 | Updated: March 21, 2026