Medical device manufacturer Stryker was hit by a severe cyberattack in March, claimed by the Iran-linked hacktivist group Handala, which wiped more than 200,000 systems, servers, and mobile devices across the company. Stryker has said the attack has since been contained after investigators found and neutralized a hidden malicious file used to run the wiping commands.
Handala said the attack was partly retaliation for a US strike on a school in Iran during that period’s escalation. Stryker has maintained throughout that its actual medical and surgical devices, the equipment used in operating rooms, were not compromised, and that there’s no evidence of malware capable of affecting the company’s physical products.
The Real-World Disruption
Even with devices unaffected, the attack had direct downstream effects: some hospitals in Maryland temporarily suspended their network connections to Stryker out of caution, and some patient procedures had to be rescheduled while systems were down. Stryker later disclosed the incident had a measurable impact on its first-quarter earnings, a sign of how disruptive a cyberattack on a supplier can be even when the products themselves keep working.
Why Hospitals Are Exposed Like This
Modern hospital systems depend on manufacturers like Stryker for continuous software support, inventory syncing, and remote maintenance features built into their equipment, which means a cyberattack on the manufacturer’s corporate network can ripple into hospital operations even without directly touching a single medical device. It’s part of a broader pattern security researchers have flagged: healthcare’s growing reliance on always-connected vendor infrastructure creates exposure that didn’t exist when hospital equipment operated independently of outside networks.







