Medical Device Maker Stryker Hit by Iran-Linked Cyberattack

A large medical technology company saw employee computers remotely wiped in real time, forcing offices to shut down during the incident response.

Illustration: Medical Device Maker Stryker Hit by Iran-Linked Cyberattack
AI-generated illustration · Sylvaris

Destructive attack disrupts operations

Medical technology company Stryker experienced a large cyberattack in March 2026 linked to an Iran-aligned hacktivist group. Employees reportedly watched as company computers were wiped in real time, forcing offices to shut down while security teams investigated.

While the incident didn't expose customer data according to initial assessments, it had a significant operational effect. The attack was described as one of the most prominent breaches of March 2026, demonstrating how geopolitical cyberattacks are increasingly targeting organizations connected to government or defense sectors.

Pattern of escalating infrastructure targeting

Security researchers noted the attack as part of a broader trend of nation-state and hacktivist groups targeting critical business functions, not just data stores. The severity of such attacks often increases because organizations lack adequate threat detection capabilities and incident response training.

The Stryker incident was classified among attacks that expose how cyber risk has become embedded across critical business functions. Multiple security firms cited the attack as evidence that adversaries are increasingly targeting systems that organizations rely on to operate.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.