Unverified claim. On July 24, 2026, ransomware group Qilin listed medtech manufacturer Stryker on its leak site (Ransomware.live, DeXpose).
Do not confuse this with Stryker’s March 2026 Handala-linked destructive incident and public customer status page. The July listing is a separate actor claim until Stryker says otherwise.
What monitors say
Qilin indicated sensitive data may be leaked and pressed for contact. No public proof dump or company confirmation of a Qilin ransomware event was available at indexing time.
Action items
- Hospitals and distributors: rely only on notices from stryker.com—not cold emails citing Qilin.
- Security teams: keep March 2026 recovery lessons and July claim hunting separate in tickets.
- Ignore ransom negotiators claiming to “speak for Stryker.”