Cybersecurity & Privacy — 2026-03-18

Iran-Linked Handala Group Wipes 80,000 Stryker Devices via Compromised MDM Console

Medical device manufacturer Stryker announced containment of a cyberattack attributed to Iran-linked Handala group, who claimed retaliation for a strike on a girls' school. Attackers compromised Stryker's Microsoft Intune MDM console and wiped approximately 80,000 devices worldwide. Maryland EMS reported Stryker's Lifenet patient data system non-functional statewide.

Analysis
Prior digest reported cybercrime activity surging 245% since February 28 and 60+ Iran-aligned hacktivist groups active. Stryker is the first major US medical-sector target. The attack's stated motivation -- retaliation for the Minab school strike -- connects directly to the Amnesty/Bellingcat investigation tracked across multiple digests.

View in full brief →

UNCLASSIFIED // OPEN SOURCE