HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Iran-Backed Hacktivist Handala Claims Wiper Attack Shutting Down Stryker Operations in 79 Countries

Handala, a group linked to Iran’s intelligence services, announced a wiper campaign that erased data on over 200,000 Stryker devices, forcing the medical‑technology maker to suspend operations worldwide. The incident highlights supply‑chain risk from state‑aligned hacktivists.

LiveThreat™ Intelligence · 📅 April 06, 2026· 📰 krebsonsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
krebsonsecurity.com

Iran-Backed Hacktivist Handala Claims Wiper Attack Shutting Down Stryker Operations in 79 Countries

What Happened — The Iran‑linked hacktivist group Handala announced a destructive wiper campaign that erased data on more than 200,000 systems, servers and mobile devices belonging to Stryker, a global medical‑technology manufacturer. The attack forced the closure of Stryker sites in 79 countries and sent thousands of employees home.

Why It Matters for TPRM

  • Operational shutdown of a critical medical‑device supplier can delay patient care and product delivery.
  • Wiper malware demonstrates the risk of state‑aligned hacktivist activity targeting supply‑chain partners.
  • Lack of resilient backup and recovery controls can amplify business impact.

Who Is Affected — Healthcare‑technology manufacturers, medical‑device OEMs, and any downstream hospitals or clinics that rely on Stryker products.

Recommended Actions — Review Stryker’s incident‑response and backup capabilities, verify continuity‑of‑operations plans, and assess alternative suppliers for critical devices.

Technical Notes — The attack leveraged a custom wiper payload delivered via compromised credentials and possibly phishing, overwriting data and defacing login screens with the Handala logo. No public CVE is associated. Source: Krebs on Security

📰 Original Source
https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.