
American medical equipment supplier Stryker said it suffered a major cyber attack that caused global disruption to its Microsoft environment as well as to its order processing, manufacturing and shipping operations.
The Kalamazoo, Michigan-based medical, surgical and orthopaedic devices manufacturer announced on Wednesday that it was dealing with a global network disruption to its Microsoft environment which occurred as a result of a cyber attack.
The company said its teams were trying to understand the impact of the attack to its systems but it had business continuity measures in place to support customers and partners during times of disruption.
Stryker enjoys global leadership in medical technology equipment manufacturing and services, employing 53,000 workers across 44 manufacturing and research facilities worldwide and recording sales of $22.6 billion in more than 75 countries. The company says its MedSurg, Neurotechnology and Orthopaedics products are used by more than 150 million people worldwide.
The company’s announcement followed claims by Iran-linked hacker group Handala that it specifically targeted the MedTech giant to deliver an "unprecedented blow" in response to U.S. air strikes on a girls’ school in Iran and ongoing cyber assaults on Iranian infrastructure.
The hacker group
HELLO Stryker#HANDALA https://t.co/Wxfu1Cd9f3 pic.twitter.com/1o6Bc8kwRI
— HPR INTELLIGENCE (@HPRNEW) March 11, 2026
"Stryker’s offices in 79 countries have been forced to shut down," Handala wrote in a post on microblogging platform X. "All the acquired data is now in the hands of the free people of the world, ready to be used for the true advancement of humanity and the exposure of injustice and corruption."
The MedTech company announced Thursday that the cyber attack disrupted its internal Microsoft environment and also disrupted order processing, manufacturing and shipping operations. It emphasised that there was no malware or ransomware involved and its connected products were safe to use.
"Upon detecting this incident, we quickly activated our incident response plan and launched an investigation with the support of external advisors and cybersecurity experts," Stryker said. "We are working diligently to restore our systems and above all, we are committed to ensuring our customers can continue to deliver seamless patient care.
"Our investigation into the nature and scope of this incident remains ongoing and is in its early stages. We are collaborating with law enforcement and our government agency partners to share meaningful intelligence about this incident as we learn more," the company added.
The company added that its Mako, Vocera and LIFEPAK35 branded medical and surgical products were not affected by the cyber security incident and were safe to use. At present, the company’s electronic ordering system is down but Stryker has committed to start shipping existing orders as soon as its system communications are restored.
Commenting on Handala’s targeted attack on Stryker’s network, Binalyze’s chief investigator Lee Suit said the operation intended to cause damage and spread chaos. "Handala is using a scorched earth approach, they get in fast, wipe devices, steal data, and leave chaos behind them. Thousands of employees locked out of devices isn’t just an operational crisis. It quickly becomes a financial, reputational, and potentially life-and-property risk," Suit said.
He said Iranian actors like Handala are surely looking to strike at other high-profile targets in the U.S. in response to ongoing operations in the Middle East, and organisations must strengthen the security of their systems, put in place incident response measures and monitor for indicators of compromise. "In firefighting terms, it’s time to cancel vacations and pre-stage your fire companies near critical assets," he added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543