Skip to main content
Back to overview
High

Stryker Hit by Wiper Malware Cyberattack

In March 2026, medical technology company Stryker experienced a large cyberattack linked to an Iran-aligned hacktivist group.

Key points

  • Cyberattack occurred on March 11, 2026.
  • Wiper malware used, affecting company computers and forcing office shutdowns.
  • Iran-aligned hacktivist group Handala claimed responsibility.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Malware

Threat source not confirmed

03

Potential impact

Potential extortion or operational risk

Impact remains under assessment

Published
Mar 11, 2026
Updated
Jun 20, 2026
Confidence
High
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential extortion or operational risk
Impact area
Unknown

Mentioned entities

StrykerStryker HitWiper Malware Cyberattack In MarchStrykerIran-alignedEmployeesThe HandalaCyberattackWiperHandala

Quick context

Questions about this signal

What happened in this signal?

In March 2026, medical technology company Stryker experienced a large cyberattack linked to an Iran-aligned hacktivist group. Employees reportedly watched as company computers were wiped in real time, forcing offices to shut down. The Handala group claimed to have stolen 50 terabytes (TB) of data before wiping tens of thousands of systems and servers across the company's network.

When was this signal reported?

Shadow Tier lists Mar 11, 2026 as the signal date.

Which organization is connected to this signal?

Stryker is the organization connected to this public signal.

Explore Stryker