Stryker Cybersecurity Incident: Non-Ransomware Attack Contained

Stryker Cybersecurity Incident: Non-Ransomware Attack Contained

First seen 26 Mar 2026, 16:17 UTC Minichart.SgIndustrialcyber.Co 58.0

Article Content

Browse articles
ThreatCluster

Stryker Corporation experienced a cybersecurity incident attributed to a suspected Iran-linked threat actor, Handala, which disrupted its operations by knocking internal systems offline. The attack involved a malicious file that executed commands without spreading within or outside Stryker's environment. Following an investigation with Palo Alto Networks' Unit 42, Stryker confirmed there was no evidence of ransomware or malware, and all known malicious binaries were neutralized. As of March 20, 2026, the incident was contained, and remediation efforts are ongoing, including rebuilding systems from pre-compromise backups. Stryker reported that no customer, supplier, or partner data was compromised during the incident. The company is working closely with government agencies and industry partners to restore services and enhance cybersecurity measures. Manufacturing operations are stabilizing, prioritizing patient needs.

Key Points: • Stryker's cybersecurity incident was linked to a suspected Iran-affiliated group. • No ransomware or malware was found; the attack utilized a non-spreading malicious file. • Stryker is collaborating with government agencies to enhance cybersecurity and restore operations.

Timeline

2026-03-20
Investigation confirms no persistent unauthorized activity detected.
2026-03-23
Stryker issues update on containment and remediation efforts.
2026-03-26
Stryker announces incident is contained and operations are stabilizing.