---
title: "Stryker Was Wiped Through Its Own Infrastructure"
url: https://daily.dev/posts/stryker-was-wiped-through-its-own-infrastructure-zi0fhudny
source_url: https://smallstep.com/blog/stryker-was-not-ransomwared-it-was-remotely-wiped
type: article
source: "Smallstep"
published: 2026-03-23T13:30:59.324Z
updated: 2026-03-23T13:31:23.883Z
tags: ["cloud", "cyber"]
reading_time: 11
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Stryker Was Wiped Through Its Own Infrastructure

**[Smallstep](https://daily.dev/sources/smallstep)** · 11 min read · 0 upvotes · 0 comments

## Summary

On March 11, 2026, an Iran-linked group used Stryker's own Microsoft Intune admin console to remotely wipe tens of thousands of devices across 79 countries using a single compromised credential — no malware, no exploit. The attack succeeded because Stryker's infrastructure could not distinguish a legitimate admin session from an attacker replaying valid credentials. Key failures included no MFA on the admin account, weak/unrotated passwords, no multi-admin approval in Intune, and no hardware-bound device verification. The post argues that hardware-bound device attestation (via TPM/Secure Enclave) is the missing layer beneath MFA and PAM — cryptographically proving a privileged session originates from a specific enrolled device, not just that someone holds valid credentials. Smallstep's ACME Device Attestation product is presented as a solution to this specific gap, deployable starting with admin console access.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://smallstep.com/blog/stryker-was-not-ransomwared-it-was-remotely-wiped>

## Similar posts on daily.dev

- [CISA urges companies to secure Microsoft Intune systems after hackers mass-wipe Stryker devices](https://daily.dev/posts/cisa-urges-companies-to-secure-microsoft-intune-systems-after-hackers-mass-wipe-stryker-devices-ayxpwklzh) · TechCrunch · 0 upvotes · 0 comments

---

Tags: [#cloud](https://daily.dev/tags/cloud), [#cyber](https://daily.dev/tags/cyber)

[View this post on daily.dev](https://daily.dev/posts/stryker-was-wiped-through-its-own-infrastructure-zi0fhudny)
