Monday, August 3, 2026

Policy & Regulation

CISA warns of device management risks after Stryker hack

CISA has issued a security warning for Microsoft Intune after pro-Iran hackers exploited the system to mass-wipe tens of thousands of devices at medical tech giant Stryker.

CISA warns of device management risks after Stryker hack

Medical technology company Stryker, which develops medical devices and equipment for hospitals, confirmed on March 11 that it had been hacked. The company experienced a cyberattack that caused global disruption to its network and impacted its global operations. Hackers mass-wiped thousands of its phones, tablets, and computers after gaining access to the company’s Windows-based network. Reports indicate that the attackers abused this access to reach internal dashboards, deleting data stored on tens of thousands of employee devices, including personal phones and computers connected to Stryker’s network. Stryker stated that the hackers did not deploy malware or ransomware. While the company’s medical devices remain operational, its supply, ordering, and shipping systems remain offline, and Stryker has not provided a timeline for its recovery.

Following the incident, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged companies on Thursday to secure systems used for managing employee devices. The agency specifically advised that sensitive or high-impact changes—such as remote device wiping—within Microsoft Intune, an endpoint management software, should require approval from a second administrator. CISA confirmed it was aware that hackers had misused Stryker’s device endpoint systems, causing ongoing outages. Stryker has since stated that it contained the cyberattack and is restoring its systems, though it did not respond to TechCrunch’s request for comment.

A group of pro-Iran hacktivists known as Handala claimed responsibility for the cyberattack, asserting that the hack was in retaliation for the U.S. killing of dozens of children in an air strike on a school in Iran. The group also claimed to have stolen data from Stryker’s network, though they did not immediately provide evidence. On Wednesday, the FBI seized the Handala group’s website, TechCrunch reported.

Why it matters

The Stryker incident highlights a critical vulnerability in how companies manage employee devices via platforms like Microsoft Intune, prompting urgent regulatory guidance to prevent similar mass-wipe attacks.