Multiple reports today say that Stryker
(NYSE: SYK)
has been hit by a cyberattack linked to an Iran-backed group.
Reports out of Ireland, including from The Irish Examiner, say that the attack is known as a “wiper” attack. It reportedly targeted data on Stryker’s IT system, effectively wiping it out so it can’t be retrieved.
(MassDevice spoke to cybersecurity experts about the potential ramifications of this cyberattack on medtech. Read about it here.)
The report states that systems in Stryker’s Cork location were shut down and company devices were also “wiped,” as around 5,000 employees were affected in Ireland.
According to The Wall Street Journal, Handala’s logo appeared on login pages for Stryker employees attempting to access their devices. That report says outages on company devices began shortly after midnight EST, claiming devices running Microsoft’s Windows operating system had been wiped.
Shares of Stryker took a hit on the reports, falling by about 4.5% to $342.51 in afternoon trading today.
Was there a reason for targeting Stryker?
Former Washington Post reporter Brian Krebs shared on his KrebsonSecurity website that Handala, an Iran-backed “hacktivist” group, took credit for the cyberattack, claiming on social media platform Telegram (as shared by Krebs) that its attack forced Stryker to shut down offices in 79 countries, erasing data from more than 200,000 systems, servers and mobile devices.
The hacktivist group stated that it conducted the attack in response to the joint attack on Iran launched by the U.S. and Israel last month — namely, the Tomahawk missile strike on an Iranian elementary school that killed at least 175 people, most of them children. The New York Times reported today that preliminary findings from a military investigation found the U.S. responsible for that deadly strike, despite the Trump Administration’s effort to place responsibility elsewhere.
Handala’s Telegram post called Stryker, an orthopedic giant based in Michigan, a “Zionist-rooted” corporation, claiming the company’s data accessed in the hack is “ready to be used for the true advancement of humanity and the exposure of injustice and corruption.” It offered no other reason for targeting Stryker. Krebs noted that it could be related to the company’s 2019 acquisition of Israel-based OrthoSpace.
Stryker’s statement
The official Stryker LinkedIn account today posted a statement:
Stryker is experiencing a global network disruption to our Microsoft environment as a result of a cyber attack. We have no indication of ransomware or malware and believe the incident is contained.
Our teams are working rapidly to understand the impact of the attack on our systems.
Stryker has business continuity measures in place to continue to support our customers and partners. We are committed to transparency and will keep stakeholders informed as we know more.
In an SEC filing, Stryker expanded on the cybersecurity incident. It said that it has activated its cybersecurity response plan and launched an investigation internally with the support of external advisors and cybersecurity experts to assess and contain the threat.
Stryker reiterated its earlier statement saying it has no indication of ransomware or malware and believes the incident is contained.
Another update from Stryker
In a statement posted on Stryker’s website on Thursday, March 12, the company said it is continuing to resolve the disruption caused by the attack. It continues to dismiss the potential of the involvement of malware or ransomware, believing the situation is contained to its internal Microsoft environment.
Stryker said connected products like Mako, Vocera and LifePak35 remain safe to use. It has visibility to orders entered before the event and plans to ship them as soon as it restores system communications. Orders that arrived after the event are being examined.
The company said it continues to work to get its ordering system back up and running “as quickly as possible. It remains safe to communicate with Stryker employees and sales representatives by email and phone, the company noted.
“We are committed to keeping our stakeholders informed as we manage this situation,” the company said. “There is nothing more important to us than the customers and patients we serve.”
Stryker later added that the incident caused disruptions to order processing, manufacturing and shipping. It says its investigation remains ongoing and in its early stages as it works with law enforcement and government agency partners.
“We are working diligently to restore our systems and above all, we are committed to ensuring our customers can continue to deliver seamless patient care,” the company wrote.
Will it impact business?
In the SEC filing, Stryker said the incident has caused and is expected to continue to cause disruptions and limitations of access to certain information systems and business applications supporting aspects of its operations and corporate functions.
While Stryker continues to work to restore affected functions and systems access, it does not yet know the timeline for a full restoration. It has business continuity measures in place, as noted in the LinkedIn statement.
The company’s investigation into the incident remains ongoing. It does not yet have the full scope of the incident, its nature and its impacts, including operational and financial impacts. Stryker has not yet determined if there will be any material impact from the cyberattack.
The analysts’ reaction
BTIG analysts Ryan Zimmerman and Iseult McMahon issued a note saying that the Cork location considered the initial target of the attack is Stryker’s biggest manufacturing hub outside the U.S. and has several facilities.
The analysts say that the exposure of Cork’s key products, including 3D-printed devices, trauma and extremities systems, neurovascular coils, catheters and power tool bits and saws, means they anticipate “some modest potential impact” to Stryker financially depending on the duration of the outage.
“We assume though that [Stryker] has adequate safety stock of product across all facilities and do not expect a material change in customer buying patterns at this point,” the analysts wrote.
Associate Editor Skyler Rivera contributed to this report.
