CISA Urges Action After Stryker–Microsoft Intune Attack
Cyber Security / Threat Detection | 5 min read
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory calling on all organisations to harden their endpoint management system configurations, following a 11 March 2026 cyberattack on medical technology giant Stryker Corporation. The attackers — a pro-Iran hacktivist group known as Handala — gained access to Stryker's Microsoft environment, compromised an administrator account, and used Microsoft Intune's built-in wipe command to remotely wipe tens of thousands of devices across the company's global network — without deploying a single line of malware.
How the Attack Worked: No Malware Required
The attack's mechanism was striking in its simplicity. Handala did not exploit a software vulnerability or deploy wiper malware — instead, they compromised an administrator account, used it to create a new Global Administrator account, and then issued Intune's native device wipe command at scale. Estimates of the damage range from nearly 80,000 devices (BleepingComputer, from a source familiar with the incident) to over 200,000 systems wiped, with Handala claiming to have also exfiltrated 50 terabytes of data before the wipe — though evidence for the data theft claim has not been publicly provided.
The impact extended beyond Stryker's own systems. The company's supply, ordering, and shipping systems were taken offline, and some patient-specific surgical cases scheduled for the week of 16 March 2026 were rescheduled due to shipping delays — underscoring the real-world consequences of enterprise IT disruption in the medical device sector. Stryker subsequently confirmed it was restoring systems and that its core medical devices remain operational.
CISA's Advisory: Three Immediate Actions
Issued on 18 March 2026 — developed with contributions from both Microsoft and Stryker — CISA's advisory calls on all organisations using Microsoft Intune and other endpoint management platforms to take three core hardening actions immediately:
- • Least-privilege administrative roles — use Microsoft Intune's role-based access control (RBAC) to ensure administrators only hold the permissions necessary for their specific responsibilities, limiting both the actions they can perform and the scope of devices and users they can manage
- • Phishing-resistant multi-factor authentication (MFA) — enforce phishing-resistant MFA across all privileged accounts, using Microsoft Entra ID Conditional Access, risk-based authentication signals, and privileged access controls to block unauthorised access to high-privilege Intune actions
- • Multi Admin Approval for sensitive operations — configure access policies requiring a second administrative account to approve any sensitive or high-impact actions, including device wiping, script deployments, application pushes, RBAC modifications, and configuration profile changes
CISA confirmed it is conducting enhanced coordination with the FBI to identify additional threats and determine broader mitigation actions. The FBI separately seized the Handala group's website, placing a banner confirming it had filed a seizure warrant after determining the site was used to conduct or facilitate malicious cyber activity on behalf of a foreign state actor.
The Broader Threat: Endpoint Management Platforms as Attack Surfaces
The Stryker attack highlights a growing and concerning trend: threat actors are increasingly targeting endpoint management and administrative control planes rather than individual devices or applications. By compromising these centralised systems, attackers can deploy malicious applications, alter device configurations, wipe endpoints, and move laterally across an organisation's entire infrastructure at scale — without needing to place malware on individual machines. Palo Alto Networks Unit 42 has observed a measurable increase in cyberattacks linked to the US-Iran conflict, including data-wiping attacks and spear phishing campaigns by Iran-linked and affiliated hacktivist groups.
"Any organisation has to be on very, very significant high alert to potentially be hit by these guys because they're quite sophisticated, they have a lot of resources. And their sole objective is chaos."
— Ronan Murphy, CEO, Smartech247
Key Takeaways
- • On 11 March 2026, pro-Iran hacktivist group Handala compromised Stryker's Microsoft environment, created a new Global Admin account, and used Microsoft Intune's native wipe command to wipe tens of thousands of devices — no malware required.
- • The attack took Stryker's supply, ordering, and shipping systems offline and caused rescheduling of surgical procedures at hospitals due to medical device shipping delays.
- • CISA's 18 March advisory — developed with Microsoft and Stryker — calls for three immediate actions: least-privilege RBAC roles, phishing-resistant MFA via Entra ID, and Multi Admin Approval for sensitive Intune operations.
- • The FBI seized the Handala group's website, citing its use to conduct malicious cyber activity on behalf of a foreign state actor; CISA and FBI are coordinating on identifying further threats.
- • The attack reflects a sector-wide shift: Iran-linked threat groups are increasingly targeting centralised endpoint management and administrative control planes — not individual devices — enabling widespread damage at scale without traditional malware.
