Cybersecurity & Privacy — 2026-03-25

Stryker Confirms Iranian Cyber Actors Wiped 200,000 Devices Using Microsoft Intune; Production Lines Restarting

Medical technology company Stryker confirmed that alleged Iranian cyber actors exploited Microsoft Intune's native device wipe functionality to destroy data across 200,000 company devices globally, affecting operations in the US, Ireland, India, and other locations. Federal prosecutors attributed the attack to Iranian actors in a DOJ affidavit. Stryker reversed its initial claim that no malware was involved, acknowledging a 'malicious file' was used to execute commands and conceal activity. Production lines are now restarting, but some surgeries were cancelled due to unavailable Stryker-made implants. Palo Alto Networks' incident response team confirmed threat actors were removed from systems.

Analysis
Prior digest did not cover the Stryker attack. The confirmation of Iranian attribution by federal prosecutors and the use of Microsoft Intune as a wiper vector represents a novel tactic in state-directed cyber operations targeting medical supply chains during wartime.
1 sources
  1. Stryker says malware was involved in recent cyberattack as production lines reopen - The Record

View in full brief →

UNCLASSIFIED // OPEN SOURCE