Why the Stryker Attack Still Matters. And Five Steps You Can Take Today
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
The March 2026 cyberattack on Stryker, attributed to the pro-Iran group Handala, demonstrated a new class of threat: attackers compromising Microsoft Intune/MDM admin access to remotely wipe up to 200,000 corporate and personal devices, while simultaneously exfiltrating 50TB of data. Unlike ransomware, a mass remote wipe is irreversible and requires months of physical device re-provisioning. The attack disrupted NHS supply chains and exposed massive HR, legal, and regulatory liability from wiping employee personal phones. Five concrete defensive steps are outlined: treat management platforms as crown jewels with FIDO2 MFA and role separation; require multi-admin approval for destructive bulk actions; audit and fix BYOD/MDM enrollment to use MAM instead of full-device control; build out-of-band communication plans for when primary systems are offline; and rehearse large-scale 'Day Zero' fleet restoration exercises.