Monday, August 3, 2026

Markets & Business

Stryker hit by global cyberattack claimed by pro-Iran group

Pro-Iran hacktivist group Handala claims responsibility for a global cyberattack on medical technology company Stryker, which has caused global network disruptions and system wipes.

Stryker hit by global cyberattack claimed by pro-Iran group

U.S. medical technology company Stryker is experiencing a global network disruption following a cyberattack. The pro-Iran hacktivist group Handala has claimed responsibility for the incident, stating that its operation has severely impacted the company’s global infrastructure.

According to claims posted by Handala, the impact of the attack includes:

  • Over 200,000 systems, servers, and mobile devices wiped
  • 50 terabytes of critical data extracted
  • Stryker offices in 79 countries forced to shut down

The hackers’ claims appear to be at least partly credible, as some Stryker systems worldwide have been wiped, and others are showing the hacker group’s logo on login pages.

“Stryker is experiencing a global network disruption to our Microsoft environment as a result of a cyberattack. We have no indication of ransomware or malware and believe the incident is contained,” a Stryker spokesperson said. However, an internal notice sent to employees, reported by The Wall Street Journal, described a severe, global disruption across the Windows environment impacting both client devices and servers.

Handala stated that the attack was in retaliation for the brutal attack on the Minab school and in response to ongoing cyber assaults against the infrastructure of Iran and its allies. The bombing of the Minab school reportedly resulted in the killing of more than 175 people. While Stryker has no direct link to the conflict, the company holds a $450 million contract from the U.S. Department of Defense and has operations in Israel.

The Cybersecurity and Infrastructure Security Agency (CISA), the U.S. cyber defense agency, is investigating the attack. Nick Andersen, the Acting Director of CISA, stated that the agency is working with public and private sector partners to provide technical assistance.

According to the IBM X-Force Exchange, a threat intelligence platform, Handala emerged after the October 7 Hamas attack on Israel. The platform notes that the group’s campaigns consistently feature deliberate targeting of life-critical sectors, employing custom wiper malware, data theft, and hack-and-leak activity to maximize psychological impact. The group has previously targeted Israeli civilian infrastructure, energy companies in the Gulf region, and Western organizations, and maintains a website that doxes individuals associated with Israeli defense contractors, such as Elbit Systems and NSO Group.

Why it matters

The attack on Stryker highlights the vulnerability of critical infrastructure and medical technology firms to politically motivated cyber operations, particularly as hacktivist groups increasingly target life-critical sectors.