Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

Summary: A hacktivist group linked to Iran's intelligence agencies claims responsibility for a data-wiping attack on Stryker, a global medical technology firm. The attack has affected thousands of systems worldwide and is impacting healthcare providers.

A hacktivist group with ties to Iran's intelligence agencies has taken responsibility for a significant data-wiping attack on Stryker, a leading global medical technology firm based in Michigan. The attack reportedly forced the closure of Stryker's offices in 79 countries and affected over 200,000 systems, servers, and mobile devices.

Stryker, known for its $25 billion annual sales and 56,000 global employees, experienced a major disruption. The company’s main U.S. headquarters reported a building emergency on the day of the attack, while Irish reports indicated that more than 5,000 workers were sent home. Additionally, Stryker devices held by employees have been wiped clean, leaving them without access to critical systems and communications.

The hacktivist group, known as Handala or Handala Hack Team, released a manifesto stating that the stolen data will be used for 'true advancement of humanity.' This attack is reportedly in response to a recent U.S. missile strike on an Iranian school, which killed at least 175 people, most of them children.

Further investigation by The New York Times suggests that the United States may have been responsible for this deadly Tomahawk missile strike. Palo Alto Networks has linked Handala to Iran's Ministry of Intelligence and Security (MOIS), describing it as one of several online personas maintained by Void Manticore, an MOIS-affiliated actor.

The wiper attack is believed to be executed through Microsoft Intune, a cloud-based solution used for IT security. Reports indicate that Stryker employees were told to urgently uninstall Intune, causing further disruptions in operations. The impact of this attack extends beyond Stryker’s immediate network; healthcare providers are already experiencing difficulties due to the disruption in supply chains.

Healthcare professionals and industry experts have highlighted the severity of this breach, emphasizing its potential to disrupt surgical supplies and medical equipment critical for patient care.

Key facts

  • Data-wiping attack on Stryker
  • Hacktivist group Handala claims responsibility
  • Impact on 79 countries
  • Use of Microsoft Intune for remote wipe command

Why it matters

The impact of this wiper attack on Stryker could lead to significant disruptions in healthcare operations worldwide. Given Stryker’s critical role as a major supplier of medical devices, the breach poses serious risks to hospitals and patients, potentially leading to shortages of vital surgical supplies and equipment.

Key metrics

  • Number of affected systems: 200,000+ systems, servers, and mobile devices (The scale of the wiper attack)
  • Number of Stryker employees impacted: 56,000 employees in 61 countries (Employee impact and distribution)