2026 Stryker — ~50 TB claimed exfiltrated, 200K+ systems wiped (nation-state–linked; no ransomware)
Data compromised
Large volume of internal corporate data claimed stolen (~50 TB); exact categories undisclosed; widespread system wipe
Technical writeup
Stryker Corporation, a major medical device manufacturer, suffered a destructive March 11, 2026 cyberattack attributed in open reporting to Handala, an Iran-linked group. Attackers claimed roughly 50 TB of internal data stolen while wiping 200,000+ Windows endpoints, servers, and mobile devices across ~79 global offices—heavy operational disruption across corporate IT and Microsoft 365. U.S. and allied officials described nation-state–linked activity in sector commentary; the operation combined large-scale data theft with wiper-style destruction rather than traditional ransomware encryption. Stryker emphasized patient safety and device integrity; securities and press coverage noted broad business impact. March 2026 operational and regulatory-style updates continued to stress recovery while investigations into the full scope of any exfiltrated regulated or customer data remained ongoing.
Root cause
Nation-state–linked intrusion; data theft plus wiper malware (not ransomware)