• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

MassDevice

The Medical Device Business Journal — Medical Device News & Articles | MassDevice

  • Special Reports
  • Technologies
    • Artificial Intelligence (AI)
    • Cardiovascular
    • Orthopedics
    • Neurological
    • Diabetes
    • Surgical Robotics
  • Business & Finance
    • Wall Street Beat
    • Earnings Reports
    • Funding Roundup
    • Mergers & Acquisitions
    • Initial Public Offering (IPO)
    • Legal News
    • Personnel Moves
    • Medtech 100 Stock Index
  • Regulatory
    • Food & Drug Administration (FDA)
    • Recalls
    • 510(k)
    • Pre-Market Approval (PMA)
    • MDSAP
    • Clinical Trials
  • Resources
    • About MassDevice
    • Leadership in Medtech
    • Manufacturers & Suppliers Search
    • MedTech100 Index
    • Videos
    • Webinars
    • Whitepapers
    • Voices
    • In-Depth Coverage
    • Latest News
  • Attend DeviceTalks
    • Events
      • DeviceTalks Minnesota – May 4
      • DeviceTalks Boston – May 27–28
      • DeviceTalks West
      • DeviceTalks Tuesdays
    • DeviceTalks Podcast Network
      • DeviceTalks Weekly
      • AbbottTalks
      • Boston ScientificTalks
      • DeviceTalks AI
      • IntuitiveTalks
      • MedtechWOMEN Talks
      • MedtronicTalks
      • Neuro Innovation Talks
      • Ortho Innovation Talks
      • Structural Heart Talks
      • StrykerTalks
  • Advertise
  • Subscribe
Home » Stryker reportedly hit with Iran-backed cyberattack

Stryker reportedly hit with Iran-backed cyberattack

March 11, 2026 By Sean Whooley

This is the logo of Stryker.Multiple reports today say that Stryker (NYSE: SYK) has been hit by a cyberattack linked to an Iran-backed group.

Reports out of Ireland, including from The Irish Examiner, say that the attack is known as a “wiper” attack. It reportedly targeted data on Stryker’s IT system, effectively wiping it out so it can’t be retrieved.

(MassDevice spoke to cybersecurity experts about the potential ramifications of this cyberattack on medtech. Read about it here.)

The report states that systems in Stryker’s Cork location were shut down and company devices were also “wiped,” as around 5,000 employees were affected in Ireland.

According to The Wall Street Journal, Handala’s logo appeared on login pages for Stryker employees attempting to access their devices. That report says outages on company devices began shortly after midnight EST, claiming devices running Microsoft’s Windows operating system had been wiped.

Shares of Stryker took a hit on the reports, falling by about 4.5% to $342.51 in afternoon trading today.

Was there a reason for targeting Stryker?

Former Washington Post reporter Brian Krebs shared on his KrebsonSecurity website that Handala, an Iran-backed “hacktivist” group, took credit for the cyberattack, claiming on social media platform Telegram (as shared by Krebs) that its attack forced Stryker to shut down offices in 79 countries, erasing data from more than 200,000 systems, servers and mobile devices.

The hacktivist group stated that it conducted the attack in response to the joint attack on Iran launched by the U.S. and Israel last month — namely, the Tomahawk missile strike on an Iranian elementary school that killed at least 175 people, most of them children. The New York Times reported today that preliminary findings from a military investigation found the U.S. responsible for that deadly strike, despite the Trump Administration’s effort to place responsibility elsewhere. 

Handala’s Telegram post called Stryker, an orthopedic giant based in Michigan, a “Zionist-rooted” corporation, claiming the company’s data accessed in the hack is “ready to be used for the true advancement of humanity and the exposure of injustice and corruption.” It offered no other reason for targeting Stryker. Krebs noted that it could be related to the company’s 2019 acquisition of Israel-based OrthoSpace.

Stryker’s statement

The official Stryker LinkedIn account today posted a statement:

Stryker is experiencing a global network disruption to our Microsoft environment as a result of a cyber attack. We have no indication of ransomware or malware and believe the incident is contained.

Our teams are working rapidly to understand the impact of the attack on our systems.

Stryker has business continuity measures in place to continue to support our customers and partners. We are committed to transparency and will keep stakeholders informed as we know more.

In an SEC filing, Stryker expanded on the cybersecurity incident. It said that it has activated its cybersecurity response plan and launched an investigation internally with the support of external advisors and cybersecurity experts to assess and contain the threat.

Stryker reiterated its earlier statement saying it has no indication of ransomware or malware and believes the incident is contained.

Another update from Stryker

In a statement posted on Stryker’s website on Thursday, March 12, the company said it is continuing to resolve the disruption caused by the attack. It continues to dismiss the potential of the involvement of malware or ransomware, believing the situation is contained to its internal Microsoft environment.

Stryker said connected products like Mako, Vocera and LifePak35 remain safe to use. It has visibility to orders entered before the event and plans to ship them as soon as it restores system communications. Orders that arrived after the event are being examined. 

The company said it continues to work to get its ordering system back up and running “as quickly as possible. It remains safe to communicate with Stryker employees and sales representatives by email and phone, the company noted.

“We are committed to keeping our stakeholders informed as we manage this situation,” the company said. “There is nothing more important to us than the customers and patients we serve.”

Stryker later added that the incident caused disruptions to order processing, manufacturing and shipping. It says its investigation remains ongoing and in its early stages as it works with law enforcement and government agency partners.

“We are working diligently to restore our systems and above all, we are committed to ensuring our customers can continue to deliver seamless patient care,” the company wrote.

Will it impact business?

In the SEC filing, Stryker said the incident has caused and is expected to continue to cause disruptions and limitations of access to certain information systems and business applications supporting aspects of its operations and corporate functions.

While Stryker continues to work to restore affected functions and systems access, it does not yet know the timeline for a full restoration. It has business continuity measures in place, as noted in the LinkedIn statement.

The company’s investigation into the incident remains ongoing. It does not yet have the full scope of the incident, its nature and its impacts, including operational and financial impacts. Stryker has not yet determined if there will be any material impact from the cyberattack.

The analysts’ reaction

BTIG analysts Ryan Zimmerman and Iseult McMahon issued a note saying that the Cork location considered the initial target of the attack is Stryker’s biggest manufacturing hub outside the U.S. and has several facilities. 

The analysts say that the exposure of Cork’s key products, including 3D-printed devices, trauma and extremities systems, neurovascular coils, catheters and power tool bits and saws, means they anticipate “some modest potential impact” to Stryker financially depending on the duration of the outage.

“We assume though that [Stryker] has adequate safety stock of product across all facilities and do not expect a material change in customer buying patterns at this point,” the analysts wrote.

 

Associate Editor Skyler Rivera contributed to this report.

Filed Under: Big Data, Business/Financial News, Digital Health, Electronic Medical Records (EMR), Featured, Health Information Technology, Health Technology, Orthopedics, Software / IT Tagged With: cyberattack, Cybersecurity, Stryker

More recent news

  • Citi downgrades Boston Scientific as cyberattack recovery compounds competitive pressure
  • Autonomix taps former Medtronic FDA counsel head for board of directors
  • Medtronic strengthens robotic surgery position with Cornerstone deal, analysts say
  • Science Corp. names president as it looks to roll out vision-restoring implant
  • Mindray looks to fill hospital ventilator gap left by Philips’ exit

About Sean Whooley

Sean Whooley is a senior editor who mainly produces work for MassDevice, Medical Design & Outsourcing and Drug Delivery Business News. He received a bachelor's degree in multiplatform journalism from the University of Maryland, College Park. You can connect with him on LinkedIn or email him at [email protected].

Primary Sidebar

Cart

“md
EXPAND YOUR KNOWLEDGE AND STAY CONNECTED
Get the latest med device regulatory, business and technology news.

DeviceTalks Weekly

See More >
MDO ad
MDO ad

Footer

MASSDEVICE MEDICAL NETWORK

DeviceTalks
Drug Delivery Business News
Medical Design & Outsourcing
Medical Tubing + Extrusion
Drug Discovery & Development
Pharmaceutical Processing World
MedTech 100 Index
R&D World
Medical Design Sourcing

DeviceTalks Webinars, Podcasts, & Discussions

Attend our Monthly Webinars
Listen to our Weekly Podcasts
Join our DeviceTalks Tuesdays Discussion

MASSDEVICE

Subscribe to MassDevice E-Newsletter
Advertise with us
About
Contact us

Copyright © 2026 · Arrowfly LLC and its licensors. All rights reserved.
The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Arrowfly.

Privacy Policy