On 11 March 2026, Stryker, one of the world's largest medical device companies, with annual sales exceeding $25 billion, disclosed a cybersecurity incident that had caused a global disruption to its Microsoft environment. The attack was claimed by Handala, a pro-Iran hacktivist group that had been escalating operations against US and Israeli targets in the weeks surrounding the US-Iran conflict.
Stryker confirmed the incident in an SEC filing, stating that the attack had "caused, and is expected to continue to cause, disruptions and limitations of access to certain of the company's information systems and business applications supporting aspects of the company's operations and corporate function." The company said it had found no indication of ransomware or malware and believed the incident was contained, but the disruption to a global Microsoft environment across a company of Stryker's scale - medical devices, surgical equipment, hospital infrastructure - carries consequences that extend beyond operational inconvenience.
This incident belongs to a category that is growing rapidly and has no adequate industry answer: state-linked or state-proxied attacks on commercial critical infrastructure, motivated not by financial gain but by geopolitical pressure. The objective is disruption. The method is access followed by damage. The target selection - healthcare, medical devices, infrastructure - is deliberate, because the downstream consequences for patients and health systems amplify the political impact.
Handala's attacks, like those of the broader Iranian cyber ecosystem, typically combine social engineering for initial access with destructive or disruptive payloads deployed once inside. The 2024 FBI, CISA and Department of Defense joint advisory on Iranian threat groups specifically identified healthcare providers, defence firms, schools, and municipal governments as primary targets, noting that these groups exploit internet-facing edge devices to gain initial access before handing off to ransomware affiliates.
The conventional security response to nation-state attacks is to harden the perimeter, implement zero-trust architecture, and improve detection and response times. All of that is necessary. None of it addresses the execution boundary. A nation-state actor with the resources and patience to gain persistent access to a target network still reaches the same gap - the moment a consequential action attempts to execute, there is no confirmed human authority requirement in place.
GoFirm does not prevent a determined nation-state from gaining access to a network. What it does is ensure that the consequential actions that follow - access to sensitive systems, data exfiltration, infrastructure disruption - cannot execute without a named human authority confirming them on a registered device through a separate channel. The attacker is inside. The gate is still there.
The Stryker attack is recent enough that its full impact is still being assessed. What is already clear is that a pro-Iran group caused a global network disruption at a major medical device company during an active geopolitical conflict, and the execution boundary offered no resistance.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.
References
1. CNN Politics, Pro-Iran Hackers Claim Cyberattack on Major US Medical Device Maker, March 2026
2. pharmaphorum, Iran Hackers Claim Cyberattack at US Medtech Firm, March 2026
3. Industrial Cyber, Iranian Hackers Target US Critical Infrastructure Through Ransomware Proxies, March 2026
