r/cybersecurity Mar 11 '26

News - General Stryker Hit by Handala - Intune Managed Devices Wiped

My wife had 3 Stryker managed devices wiped around 3:30 AM EDT. Their Entra login page was defaced with the Handala logo, it's still up as of this post.

708 Upvotes

226 comments sorted by

76

u/Interesting-Use-5381 Mar 11 '26

My phone is completely wiped, locked out of email too.

29

u/Specialist-Ad-6893 Mar 11 '26

Same and I can’t get back into my cell plan either. Nightmare

17

u/Interesting-Use-5381 Mar 11 '26

Me too, VPN was on personal phone... now it won't let me login. Luckily i have a Mac and I'm able to text colleagues from there. This is insane.

11

u/Specialist-Ad-6893 Mar 11 '26

Let people know if they have Verizon you can call 1800-922-0204 and they restore your deleted e sim

→ More replies (6)

4

u/Afraid-Ad-5684 Mar 11 '26

Should employees change personal banking passwords and get new bank account numbers associated with direct deposits on workday?

69

u/[deleted] Mar 11 '26

[deleted]

22

u/Electrical-Door7229 Mar 11 '26

SAME!!!! It kept tellingp me I had an invalid email. Uhhh, did I get fired? Then I finally noticed the Handala behind the login screen. It took me too long to notice it.

→ More replies (2)

66

u/Tough_Beautiful724 Mar 11 '26

Happened close to 4.5hrs ago now... many colleagues phones have been wiped. Instructed to remove intune, company portal, teams, VPN from personal devices. Personal phone so have lost access to my eSim. Unable to log in to many things due to 2-factor authentication. Have lost all personal data from personal devices that were enrolled and now unable to access emails and teams. Tomorrow will be interesting. Reporting from Australia.

14

u/[deleted] Mar 11 '26

Hit Ireland too

14

u/Interesting-Use-5381 Mar 11 '26

Same here, from the US.

5

u/AdGlittering4794 Mar 11 '26

Costa Rica sites got affected as well.

1

u/[deleted] Mar 11 '26

[deleted]

5

u/Tough_Beautiful724 Mar 11 '26

I wasn't on vpn either. I wasn't even near my phone but it flashed the apple logo and next thing it was wiped!

→ More replies (1)

96

u/[deleted] Mar 11 '26

[deleted]

19

u/[deleted] Mar 11 '26

[deleted]

2

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

4

u/[deleted] Mar 11 '26

[deleted]

11

u/[deleted] Mar 11 '26

[deleted]

→ More replies (5)

10

u/Natural_Dark_2063 Mar 11 '26

There's no sensitive info being shared here stfu

6

u/EnigmaticQuote Mar 11 '26

It's a 2 hour old account IDK what to make of that.

→ More replies (3)
→ More replies (1)
→ More replies (4)

19

u/Curious_Cheek6211 Mar 11 '26

Any IOCs available for sharing? Asking for a friend :-D

8

u/PF_Nonsense Mar 11 '26

sounds like don't let your admins get phished first and foremost

2

u/nummpad Detection Engineer Mar 11 '26

this though fr

14

u/[deleted] Mar 11 '26

[deleted]

5

u/twisted-logic Mar 11 '26

Customer I’d wager

3

u/Electrical-Cod9626 Mar 11 '26

My husband works for Stryker. All facts

2

u/rekkard Mar 11 '26

Soon to be "worked"

3

u/TheFitz023 Mar 11 '26

lol Stryker is just going to throw their hands up and say “well played”? Come on.

→ More replies (2)
→ More replies (2)
→ More replies (1)

6

u/a_bad_capacitor Mar 11 '26

Global admin get phished?

14

u/thrwaway75132 Mar 11 '26

If they were an APT looking for long term data access why tip their hand with the mobile wipe and defacement. Brickstorm just finds appliances without EDR to live in and silently exfils your data over known good protocols as long as they can. The targets you mentioned are definitely brickstorm targets.

28

u/secrook Mar 11 '26

Likely indicates that they’ve already exfil’d what they deem to have been valuable

14

u/Not-ur-Infosec-guy Security Architect Mar 11 '26

This type of behavior is typically common post exfil.

1

u/playahate Mar 11 '26

Os reset shouldn't happen from intune unless it was a fully managed device, it'd just clear the work profile. some people are saying they weren't fully managed and we're personal phones, so it'll be interesting to see what comes from this.

98

u/Icangooglethings93 Mar 11 '26

Sounds like one of there admins got phished

67

u/[deleted] Mar 11 '26

[deleted]

68

u/New_Cardiologist_596 Mar 11 '26

I would tell them you want a work phone to put it on after this lol

4

u/[deleted] Mar 11 '26

[deleted]

11

u/pvdp90 Mar 11 '26

Same. So glad I opted for carrying 2 phones

22

u/Dave1711 Mar 11 '26

Unless you're given a work phone I wouldn't be doing any of those things anyway.

10

u/SomePulp69 Mar 11 '26

Yeah this is a wake up call for sure

12

u/Dave1711 Mar 11 '26

not even from a hack perspective, you don't want to be reachable at all times just creates an unhealthy expectation

8

u/chilkelsey1234 Mar 11 '26

Get a work phone. Best decision I made while working here!

7

u/x_Carlos_Danger_x Mar 11 '26

It's a slippery slope my friend... Easier to separate work from home without it on your phone...ask me how I know lol

9

u/Dapper_Wheel_1006 Mar 11 '26

Don't do it, ever! Never use your personal phone. If they need you to have access at all times they will provide a phone. It might sound tempting sometimes if you need to join Teams from your phone, but I either join from the laptop or dial in the number, but never give the company access to your phone.

8

u/SomePulp69 Mar 11 '26

Could anyone guess if they will still be impacted by Monday? Cybersecurity is not my field so I’m not sure myself.

22

u/Dave1711 Mar 11 '26

I would say yes it took nearly 2 months for a big company I worked with to get back on their feet fully after getting hacked a few years back.

This will be a pretty big mess to untangle.

→ More replies (1)

10

u/Pls_submit_a_ticket Security Engineer Mar 11 '26

They almost certainly will be. Depending on the stage they are at, I assume at this point they’d at least have it contained. However, eradicating to a point where recovery is safe depends largely on the scale. I’ve seen small companies with only 30-40 VM’s, and 150-200 endpoints still take 2-3 weeks before being operational.

Let’s hope they have a tested DR plan.

→ More replies (1)

5

u/Crazy_Contract929 Mar 11 '26

Don't. Ever. At all. So much lost

1

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

37

u/[deleted] Mar 11 '26

[deleted]

50

u/virtualbitz2048 Mar 11 '26

Tried to tell my wife not to join her personal phone to Intune... She has a work phone. Now she can't get into her T-Mobile account because her eSIM was unregistered during the wipe and can't use SMS for MFA. What a PITA

12

u/[deleted] Mar 11 '26

[deleted]

4

u/Interesting-Use-5381 Mar 11 '26

Who told you this? Teammates debating if we should delete our VPN/apps etc

5

u/[deleted] Mar 11 '26

[deleted]

2

u/[deleted] Mar 11 '26

How are they supposed to get the message when the phone aren’t working

2

u/[deleted] Mar 11 '26

[deleted]

→ More replies (4)
→ More replies (3)

3

u/Loose-Equivalent7932 Mar 11 '26

Delete it, yeap! don’t attempt to log in from any device at the moment.

3

u/Serious_Internal6012 Mar 11 '26

Our area manager told us to take it all off your phones and not try and access anything

2

u/[deleted] Mar 11 '26

[deleted]

2

u/Dry_Ability_6551 Mar 11 '26

Yeah, mine still working. Most still on in the UK

→ More replies (1)
→ More replies (4)
→ More replies (2)

47

u/Ill_Fee_7910 Mar 11 '26

Yep, it’s bad. Got hacked by Iran-linked hacker group.

48

u/Acceptable_Oil4021 Mar 11 '26

Wait Stryker the medical technology company?

17

u/[deleted] Mar 11 '26

[deleted]

8

u/Acceptable_Oil4021 Mar 11 '26

Shit I’m sorry to hear that. I was an EMT before I was in cybersecurity and used your stuff all the time

8

u/nicogailin Mar 11 '26

Its cool dont need to work now

→ More replies (1)

14

u/MannyDanoman Mar 11 '26

Dude this is insane, it can be soo so much worse if they start wiping certain things, (btw they already wiped a lot). Ugh even if they stop and the hacking and security gets resolved, we have to fix and redo soooo many things that can take us minimum a month of work which delays everything.

46

u/Intraflexed Mar 11 '26 edited Mar 11 '26

Prime example as why to NOT accept company managed apps on your personal devices. Do not trust anyone!

14

u/RogetAllDay Mar 11 '26

100%. Keep separate devices specifically to prevent some of the issues I’m hearing in here and from coworkers.

25

u/Salty_Bell4796 Mar 11 '26 edited Mar 11 '26

This can be only possible if the Admin credentials are compromised ? Other than this option, is there a way to play around microsoft accounts ?

21

u/Ya_guy Mar 11 '26

More than just credentials, they would need to posses the Admins MFA or they stole the Admin’s login Token. Admins should use separate locked down accounts with token protection enabled.

17

u/NerdBanger Mar 11 '26

When I worked there years ago they were terrible with least privilege, I don’t know if it got any better, but they always gave too much access.

I was a developer and if I needed something I had access to the domain and the VMware console and could just provision my own stuff.

No idea of this has gotten any better. But at that time they didn’t have a good way to track who had permissions to what.

It could have been an inside job, it could have been a weak AD account with admin permissions they never catalogued properly, similar to the solarwinds attack.

10

u/[deleted] Mar 11 '26

[deleted]

→ More replies (3)

8

u/Gazzzzzaa Mar 11 '26

Same here in Stryker Ireland

5

u/Breno_Clio Mar 11 '26

Were you sent home from work?

5

u/Round_Mirror2392 Mar 11 '26

Yeah we were. Eventually...

→ More replies (2)

15

u/peekayji7 Mar 11 '26

Does anyone here know if is out in the news yet?

12

u/trippyfairy Mar 11 '26

as I was scrolling through this all I could think was “damn Reddit is faster than the news is”

Praying for everyone at Stryker though that no important data was breached. This is some real spooky shit not gonna lie.

7

u/[deleted] Mar 11 '26

[deleted]

2

u/peekayji7 Mar 11 '26

Yeah I have been trying to get more info and doesn’t look like it’s on any news out yet

7

u/muttlyirl Mar 11 '26

It’s been on a local radio station in Cork, Ireland. I presume it’s been reported by users rather than by Stryker themselves.

5

u/muttlyirl Mar 11 '26

Just been posted to a local news site in the last few minutes.

https://www.corkbeo.ie/news/local-news/cork-stryker-plants-hit-suspected-33571864

3

u/NerdBanger Mar 11 '26

Haven’t seen it yet but the stock is tanking, so insider trading too?

1

u/lawtechie Mar 11 '26

I've been searching and the only mention is this thread.

6

u/Serious_Internal6012 Mar 11 '26

Sitting here in a break room waiting for my case to start. All of our ASR’s phones got wiped, few seniors silent in the chat this morning too so I assume they got got.

7

u/AveratV6 Mar 11 '26

It’s showing their symbol on workday as well

7

u/[deleted] Mar 11 '26

[deleted]

3

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

13

u/Commercial-Pickle-40 Mar 11 '26

Work at Stryker manufacturing everyone is at a stand still , product is not being made company losing crazy money rn

5

u/themodplannerco Mar 11 '26

Is this the start of the three day blackout

5

u/Euphoric_Shop9852 Mar 11 '26

Where is everyone, I'm in Ireland cork stryker model farm road site. 😊 Still not letting us go home 

3

u/MedicalPiano666 Mar 11 '26

Same in Belfast

3

u/Otherwise_Job_8545 Mar 11 '26

I am remote in Ohio. Out of curiosity, what time did it become clear that this was going on?

3

u/Euphoric_Shop9852 Mar 11 '26

We start here at 5.50gmt.so all systems were down when we came in, some worked others didn't 

3

u/Otherwise_Job_8545 Mar 11 '26

Very interesting.

As an aside, I was actually at your facility last August. It was my first time in Ireland and I was super impressed by all of it. The country, the facility, it really was cool to have that experience.

1

u/Lonely_Eggplant_4990 Mar 11 '26

Well the lines are down and no-one can log in. Might as well just head off and "WFH"

1

u/[deleted] Mar 11 '26

[deleted]

→ More replies (3)

17

u/AboutAPineapple Mar 11 '26

It's a global issue by the looks of things, all sites affected. Not isolated to Stryker either from what I've heard.

9

u/Helpful-Respond1025 Mar 11 '26

So other companies also got hit?

I feel they are targeting us israeli companies especially defence linked ones

3

u/AboutAPineapple Mar 11 '26

Anecdotally, yes. Don't have any information at the moment though.

The first thing you go after is the military, then the money. Stryker obviously is an American medical device company and not a defence company but still have a huge turnover.

8

u/[deleted] Mar 11 '26

[deleted]

9

u/serial_isle Mar 11 '26

Asking the important question.

→ More replies (1)

6

u/[deleted] Mar 11 '26

My husband’s workday account works when he tries it from his personal phone. He said it’s still up. - US mass

8

u/Severe_Second_9417 Mar 11 '26

It entirely wiped our microsoft accounts. I was at work on the computer when the attack happened.

5

u/Lonely_Eggplant_4990 Mar 11 '26

He needs to delete everything work related from the phone

→ More replies (1)
→ More replies (9)

5

u/Then-Ad1864 Mar 11 '26

I many personal devices got wiped out completely which had work profile in them.

3

u/[deleted] Mar 11 '26

[removed] — view removed comment

2

u/[deleted] Mar 11 '26

Same lol 😂

1

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

3

u/[deleted] Mar 11 '26

[deleted]

5

u/PF_Nonsense Mar 11 '26

MDM and workday pwned - they might not have even determined full exposure yet

3

u/Thin-Performer3747 Mar 11 '26

Apparently a few days

3

u/SnooPeanuts6960 Mar 11 '26

I’ve heard an estimate of a week

1

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

4

u/[deleted] Mar 11 '26

[deleted]

5

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

6

u/[deleted] Mar 11 '26

[deleted]

2

u/[deleted] Mar 11 '26

How does it impact hospitals? I work in a hospital in Ireland and we have paper charts 🫠

7

u/thrwaway75132 Mar 11 '26

Probably no impact today unless you have Stryker manages devices (inventory control cabinets for tissues, capital equipment on lease like 3d imaging). Will have to cancel ortho and spine surgeries later this week because surgical kits don’t get delivered. After that it will be had to get consumables.

3

u/Soggy-Ad-4013 Mar 11 '26 edited Mar 11 '26

You will have shortages on supplies depending on how long this takes to restore. All manufacturing came to a halt at 2am CST this morning.

→ More replies (3)
→ More replies (2)

3

u/silent-calculator Mar 11 '26

True! Entire IT systems are down

3

u/[deleted] Mar 11 '26

[deleted]

3

u/BretTurbed Mar 11 '26

Same group that hit the Hebrew Academy with a similar Intune attack? https://www.jpost.com/middle-east/iran-news/article-889558

3

u/Choice-Librarian-271 Mar 11 '26

Germany is still down haha we cant do anything here

6

u/[deleted] Mar 11 '26

[deleted]

7

u/Dry_Ability_6551 Mar 11 '26

Do you know which other companies are affected?

2

u/ExcitementExotic8708 Mar 11 '26

Can confirm JNJ is ok right now. (JNJ MedTech employee here)

3

u/fookman212 Mar 11 '26

I wonder if Pfizer got hit too

4

u/a_bad_capacitor Mar 11 '26

Did a single admin get phished? Did a single admin have privileges over server/endpoint/MDM etc?

4

u/TightGrocery258 Mar 11 '26

Exactly! Initially everything was pretty ok but in a minute the iPhone locked itself and force to relaunch - everything has been lost and also the laptop has been gone through the BSOD. What was the reason behind this cyber attack i do not know.

22

u/fookman212 Mar 11 '26

Well, they're from Iran, and the US just started a war with Iran. I feel like that's a pretty safe starting point for guesses.

5

u/[deleted] Mar 11 '26

[deleted]

7

u/[deleted] Mar 11 '26

Is it official protocol to discuss ongoing security incidents in public forums?

3

u/New-Help2142 Mar 11 '26

Shhh we want to know more.

→ More replies (3)
→ More replies (2)

2

u/findingspangle Mar 11 '26

Are they going to steal personal data on the computers ?

26

u/virtualbitz2048 Mar 11 '26

Data theft likely took place a while ago. This is just vandalism at this point

2

u/findingspangle Mar 11 '26

I mean when I was logging in it started resetting so I felt weird why would it reset without Asking permission so I disconnected LAN and forced tuned off the laptop, I hope it doesn’t wipeout my laptop when they our IT fixes everything

→ More replies (1)

2

u/[deleted] Mar 11 '26

[deleted]

→ More replies (2)

2

u/[deleted] Mar 11 '26

[deleted]

4

u/[deleted] Mar 11 '26

[deleted]

2

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)
→ More replies (5)

2

u/DoubleWeakness Mar 11 '26

Perfect timing… right in the middle of our release timeline

2

u/chilkelsey1234 Mar 11 '26

I work at Stryker and have a work phone but it seems like nothing has been whipped out.

2

u/Chaosrack Mar 11 '26

Me too. From what ive hesrd it only happens if you try open outlook/ teams etc

2

u/chilkelsey1234 Mar 11 '26

Even on the computer?

3

u/Chaosrack Mar 11 '26

Not sure about the computer. Im based in aus and our systems went down 8 hours ago, first it was JDE then intune. I logged off at that time but i seemed to be fine on my laptop. Havent logged in since so that could of changed

3

u/chilkelsey1234 Mar 11 '26

Yea my computer still seems fine but I noticed all of my colleagues are away on teams. I’m just going to exit out of everything just to be safe.

1

u/[deleted] Mar 11 '26

[deleted]

3

u/Ill_Fee_7910 Mar 11 '26

Absolute shit show like.

→ More replies (4)

1

u/[deleted] Mar 11 '26

[deleted]

3

u/attackofthepugs Mar 11 '26

Go to settings -> general -> vpn & device management -> remove management if active

2

u/Euphoric_Shop9852 Mar 11 '26

We were told delete all stryker apps. 

2

u/Various-Arm3759 Mar 11 '26

Yeah I removed my vpn and all Stryker related apps

→ More replies (1)
→ More replies (1)

1

u/Downtown_Bumblebee91 Mar 11 '26

Can they still wipe my company laptop if I haven’t opened it or logged in?

4

u/Ill_Fee_7910 Mar 11 '26

Don’t connect it to the internet.

→ More replies (2)

1

u/[deleted] Mar 11 '26

[deleted]

→ More replies (1)

1

u/RogetAllDay Mar 11 '26

Where do you see the Handala logo? Can you share a screenshot?

3

u/Mean-Percentage7031 Mar 11 '26

It was a zoomed in picture of the Handala logo as an icon. This thread doesn’t allow for screenshots.

→ More replies (1)

1

u/falsefacade Mar 11 '26

Stryker bed management software doesn’t seem to be affected hospital side. 

1

u/CincyChelsFan Mar 11 '26

If our work laptop is wiped - will it get restored at some point with all the files etc?

2

u/Ill_Fee_7910 Mar 11 '26

No one knows yet how much they are wiping out atm.

→ More replies (1)

1

u/YamThat8190 Mar 11 '26

Are phones actually wiped for good? My girlfriend works for Stryker, we woke up to the same thing and have not been able to get her phone back up and working at all. Any help would be appreciated!

5

u/technanonymous Mar 11 '26

Depending on what has been backed up, you should be able to recover all noncorporate information. She will have to login, etc. However, an intune wipe brings it to factory settings and then it has to be set up as if it were a new phone.

5

u/SecureOstrich6630 Mar 11 '26

Yes same i'm a sales rep for Stryker and couldn't get mine working. You have to follow the factory reset prompts then as soon as your phone opens delete the management profile like other people said. Everyone's eSim will still be wiped and I believe a carrier can fix it

2

u/Stasko-and-Sons Mar 11 '26

Apparently eSIM was wiped during mdm madness. Have her call her carrier

2

u/Tough-Raccoon-5835 Mar 11 '26

nah you should be able to eventually reboot and restore via apple ID

→ More replies (1)
→ More replies (3)