The who, what, and why of the attack that has shut down Stryker's Windows network
Company says it doesn’t know how long it will take to restore its Microsoft environment.

TL;DR
- Stryker, a global medical device maker, has confirmed a cyberattack that disrupted its Microsoft environment.
- The hacking group Handala Hack, which researchers link to the Iranian government, claimed responsibility for the attack.
- The attack is believed to be retaliatory for recent US and Israeli airstrikes on Iran.
- Social media posts and reports indicated that employee phones and computers were wiped, with some displaying the Handala Hack logo.
- Stryker stated that ransomware or malware were not initially indicated as causes, and the incident is believed to be contained within the internal Microsoft environment.
- Critical Stryker devices like Lifepak, Lifenet, and Mako remained functional.
- The method of network breach is not yet public, but theories suggest the use of Microsoft's InTune tool for data wiping.
- Handala Hack, named after a Palestinian resistance symbol, is reportedly affiliated with Iran's Ministry of Intelligence and Security.
- The attack serves as a demonstration of retaliation, utilizing cyber disruption for psychological impact and to show that pro-Iranian forces can exact a price.
- Targeting Stryker, a key supplier of medical devices, carries strategic and symbolic weight for US and allied security.