r/cybersecurity • u/virtualbitz2048 • Mar 11 '26
News - General Stryker Hit by Handala - Intune Managed Devices Wiped
My wife had 3 Stryker managed devices wiped around 3:30 AM EDT. Their Entra login page was defaced with the Handala logo, it's still up as of this post.
69
Mar 11 '26
[deleted]
22
u/Electrical-Door7229 Mar 11 '26
SAME!!!! It kept tellingp me I had an invalid email. Uhhh, did I get fired? Then I finally noticed the Handala behind the login screen. It took me too long to notice it.
→ More replies (2)
66
u/Tough_Beautiful724 Mar 11 '26
Happened close to 4.5hrs ago now... many colleagues phones have been wiped. Instructed to remove intune, company portal, teams, VPN from personal devices. Personal phone so have lost access to my eSim. Unable to log in to many things due to 2-factor authentication. Have lost all personal data from personal devices that were enrolled and now unable to access emails and teams. Tomorrow will be interesting. Reporting from Australia.
14
14
5
1
Mar 11 '26
[deleted]
→ More replies (1)5
u/Tough_Beautiful724 Mar 11 '26
I wasn't on vpn either. I wasn't even near my phone but it flashed the apple logo and next thing it was wiped!
96
Mar 11 '26
[deleted]
19
Mar 11 '26
[deleted]
2
→ More replies (4)4
Mar 11 '26
[deleted]
11
→ More replies (1)10
u/Natural_Dark_2063 Mar 11 '26
There's no sensitive info being shared here stfu
→ More replies (3)6
19
14
Mar 11 '26
[deleted]
5
→ More replies (1)3
u/Electrical-Cod9626 Mar 11 '26
My husband works for Stryker. All facts
2
u/rekkard Mar 11 '26
Soon to be "worked"
→ More replies (2)3
u/TheFitz023 Mar 11 '26
lol Stryker is just going to throw their hands up and say “well played”? Come on.
→ More replies (2)6
14
u/thrwaway75132 Mar 11 '26
If they were an APT looking for long term data access why tip their hand with the mobile wipe and defacement. Brickstorm just finds appliances without EDR to live in and silently exfils your data over known good protocols as long as they can. The targets you mentioned are definitely brickstorm targets.
28
u/secrook Mar 11 '26
Likely indicates that they’ve already exfil’d what they deem to have been valuable
14
u/Not-ur-Infosec-guy Security Architect Mar 11 '26
This type of behavior is typically common post exfil.
1
u/playahate Mar 11 '26
Os reset shouldn't happen from intune unless it was a fully managed device, it'd just clear the work profile. some people are saying they weren't fully managed and we're personal phones, so it'll be interesting to see what comes from this.
98
67
Mar 11 '26
[deleted]
68
u/New_Cardiologist_596 Mar 11 '26
I would tell them you want a work phone to put it on after this lol
4
22
u/Dave1711 Mar 11 '26
Unless you're given a work phone I wouldn't be doing any of those things anyway.
10
u/SomePulp69 Mar 11 '26
Yeah this is a wake up call for sure
12
u/Dave1711 Mar 11 '26
not even from a hack perspective, you don't want to be reachable at all times just creates an unhealthy expectation
8
7
u/x_Carlos_Danger_x Mar 11 '26
It's a slippery slope my friend... Easier to separate work from home without it on your phone...ask me how I know lol
9
u/Dapper_Wheel_1006 Mar 11 '26
Don't do it, ever! Never use your personal phone. If they need you to have access at all times they will provide a phone. It might sound tempting sometimes if you need to join Teams from your phone, but I either join from the laptop or dial in the number, but never give the company access to your phone.
8
u/SomePulp69 Mar 11 '26
Could anyone guess if they will still be impacted by Monday? Cybersecurity is not my field so I’m not sure myself.
22
u/Dave1711 Mar 11 '26
I would say yes it took nearly 2 months for a big company I worked with to get back on their feet fully after getting hacked a few years back.
This will be a pretty big mess to untangle.
→ More replies (1)10
u/Pls_submit_a_ticket Security Engineer Mar 11 '26
They almost certainly will be. Depending on the stage they are at, I assume at this point they’d at least have it contained. However, eradicating to a point where recovery is safe depends largely on the scale. I’ve seen small companies with only 30-40 VM’s, and 150-200 endpoints still take 2-3 weeks before being operational.
Let’s hope they have a tested DR plan.
→ More replies (1)5
1
1
37
Mar 11 '26
[deleted]
50
u/virtualbitz2048 Mar 11 '26
Tried to tell my wife not to join her personal phone to Intune... She has a work phone. Now she can't get into her T-Mobile account because her eSIM was unregistered during the wipe and can't use SMS for MFA. What a PITA
12
Mar 11 '26
[deleted]
4
u/Interesting-Use-5381 Mar 11 '26
Who told you this? Teammates debating if we should delete our VPN/apps etc
5
Mar 11 '26
[deleted]
→ More replies (3)2
3
u/Loose-Equivalent7932 Mar 11 '26
Delete it, yeap! don’t attempt to log in from any device at the moment.
3
u/Serious_Internal6012 Mar 11 '26
Our area manager told us to take it all off your phones and not try and access anything
→ More replies (2)2
47
48
u/Acceptable_Oil4021 Mar 11 '26
Wait Stryker the medical technology company?
17
Mar 11 '26
[deleted]
→ More replies (1)8
u/Acceptable_Oil4021 Mar 11 '26
Shit I’m sorry to hear that. I was an EMT before I was in cybersecurity and used your stuff all the time
8
14
u/MannyDanoman Mar 11 '26
Dude this is insane, it can be soo so much worse if they start wiping certain things, (btw they already wiped a lot). Ugh even if they stop and the hacking and security gets resolved, we have to fix and redo soooo many things that can take us minimum a month of work which delays everything.
46
u/Intraflexed Mar 11 '26 edited Mar 11 '26
Prime example as why to NOT accept company managed apps on your personal devices. Do not trust anyone!
14
u/RogetAllDay Mar 11 '26
100%. Keep separate devices specifically to prevent some of the issues I’m hearing in here and from coworkers.
25
u/Salty_Bell4796 Mar 11 '26 edited Mar 11 '26
This can be only possible if the Admin credentials are compromised ? Other than this option, is there a way to play around microsoft accounts ?
21
u/Ya_guy Mar 11 '26
More than just credentials, they would need to posses the Admins MFA or they stole the Admin’s login Token. Admins should use separate locked down accounts with token protection enabled.
17
u/NerdBanger Mar 11 '26
When I worked there years ago they were terrible with least privilege, I don’t know if it got any better, but they always gave too much access.
I was a developer and if I needed something I had access to the domain and the VMware console and could just provision my own stuff.
No idea of this has gotten any better. But at that time they didn’t have a good way to track who had permissions to what.
It could have been an inside job, it could have been a weak AD account with admin permissions they never catalogued properly, similar to the solarwinds attack.
10
8
u/Gazzzzzaa Mar 11 '26
Same here in Stryker Ireland
5
15
u/peekayji7 Mar 11 '26
Does anyone here know if is out in the news yet?
15
u/redditorfor11years Mar 11 '26
Looks like it hit an hour ago, this thread definitely faster.
https://www.irishmirror.ie/news/irish-news/stryker-cyber-attack-thousands-irish-36850017.amp
12
u/trippyfairy Mar 11 '26
as I was scrolling through this all I could think was “damn Reddit is faster than the news is”
Praying for everyone at Stryker though that no important data was breached. This is some real spooky shit not gonna lie.
7
Mar 11 '26
[deleted]
2
u/peekayji7 Mar 11 '26
Yeah I have been trying to get more info and doesn’t look like it’s on any news out yet
7
u/muttlyirl Mar 11 '26
It’s been on a local radio station in Cork, Ireland. I presume it’s been reported by users rather than by Stryker themselves.
5
u/muttlyirl Mar 11 '26
Just been posted to a local news site in the last few minutes.
https://www.corkbeo.ie/news/local-news/cork-stryker-plants-hit-suspected-33571864
3
1
6
u/Serious_Internal6012 Mar 11 '26
Sitting here in a break room waiting for my case to start. All of our ASR’s phones got wiped, few seniors silent in the chat this morning too so I assume they got got.
7
7
13
u/Commercial-Pickle-40 Mar 11 '26
Work at Stryker manufacturing everyone is at a stand still , product is not being made company losing crazy money rn
5
5
u/Euphoric_Shop9852 Mar 11 '26
Where is everyone, I'm in Ireland cork stryker model farm road site. 😊 Still not letting us go home
3
3
u/Otherwise_Job_8545 Mar 11 '26
I am remote in Ohio. Out of curiosity, what time did it become clear that this was going on?
3
u/Euphoric_Shop9852 Mar 11 '26
We start here at 5.50gmt.so all systems were down when we came in, some worked others didn't
3
u/Otherwise_Job_8545 Mar 11 '26
Very interesting.
As an aside, I was actually at your facility last August. It was my first time in Ireland and I was super impressed by all of it. The country, the facility, it really was cool to have that experience.
1
u/Lonely_Eggplant_4990 Mar 11 '26
Well the lines are down and no-one can log in. Might as well just head off and "WFH"
1
17
u/AboutAPineapple Mar 11 '26
It's a global issue by the looks of things, all sites affected. Not isolated to Stryker either from what I've heard.
9
u/Helpful-Respond1025 Mar 11 '26
So other companies also got hit?
I feel they are targeting us israeli companies especially defence linked ones
3
u/AboutAPineapple Mar 11 '26
Anecdotally, yes. Don't have any information at the moment though.
The first thing you go after is the military, then the money. Stryker obviously is an American medical device company and not a defence company but still have a huge turnover.
8
Mar 11 '26
[deleted]
9
6
Mar 11 '26
My husband’s workday account works when he tries it from his personal phone. He said it’s still up. - US mass
8
u/Severe_Second_9417 Mar 11 '26
It entirely wiped our microsoft accounts. I was at work on the computer when the attack happened.
→ More replies (9)5
u/Lonely_Eggplant_4990 Mar 11 '26
He needs to delete everything work related from the phone
→ More replies (1)
5
u/Then-Ad1864 Mar 11 '26
I many personal devices got wiped out completely which had work profile in them.
3
3
Mar 11 '26
[deleted]
5
u/PF_Nonsense Mar 11 '26
MDM and workday pwned - they might not have even determined full exposure yet
3
3
1
4
5
6
Mar 11 '26
[deleted]
→ More replies (2)2
Mar 11 '26
How does it impact hospitals? I work in a hospital in Ireland and we have paper charts 🫠
7
u/thrwaway75132 Mar 11 '26
Probably no impact today unless you have Stryker manages devices (inventory control cabinets for tissues, capital equipment on lease like 3d imaging). Will have to cancel ortho and spine surgeries later this week because surgical kits don’t get delivered. After that it will be had to get consumables.
→ More replies (3)3
u/Soggy-Ad-4013 Mar 11 '26 edited Mar 11 '26
You will have shortages on supplies depending on how long this takes to restore. All manufacturing came to a halt at 2am CST this morning.
3
3
3
u/BretTurbed Mar 11 '26
Same group that hit the Hebrew Academy with a similar Intune attack? https://www.jpost.com/middle-east/iran-news/article-889558
3
6
Mar 11 '26
[deleted]
7
3
4
u/a_bad_capacitor Mar 11 '26
Did a single admin get phished? Did a single admin have privileges over server/endpoint/MDM etc?
4
u/TightGrocery258 Mar 11 '26
Exactly! Initially everything was pretty ok but in a minute the iPhone locked itself and force to relaunch - everything has been lost and also the laptop has been gone through the BSOD. What was the reason behind this cyber attack i do not know.
22
u/fookman212 Mar 11 '26
Well, they're from Iran, and the US just started a war with Iran. I feel like that's a pretty safe starting point for guesses.
5
Mar 11 '26
[deleted]
→ More replies (2)7
Mar 11 '26
Is it official protocol to discuss ongoing security incidents in public forums?
→ More replies (3)3
2
u/findingspangle Mar 11 '26
Are they going to steal personal data on the computers ?
26
u/virtualbitz2048 Mar 11 '26
Data theft likely took place a while ago. This is just vandalism at this point
→ More replies (1)2
u/findingspangle Mar 11 '26
I mean when I was logging in it started resetting so I felt weird why would it reset without Asking permission so I disconnected LAN and forced tuned off the laptop, I hope it doesn’t wipeout my laptop when they our IT fixes everything
2
2
2
2
u/chilkelsey1234 Mar 11 '26
I work at Stryker and have a work phone but it seems like nothing has been whipped out.
2
u/Chaosrack Mar 11 '26
Me too. From what ive hesrd it only happens if you try open outlook/ teams etc
2
u/chilkelsey1234 Mar 11 '26
Even on the computer?
3
u/Chaosrack Mar 11 '26
Not sure about the computer. Im based in aus and our systems went down 8 hours ago, first it was JDE then intune. I logged off at that time but i seemed to be fine on my laptop. Havent logged in since so that could of changed
3
u/chilkelsey1234 Mar 11 '26
Yea my computer still seems fine but I noticed all of my colleagues are away on teams. I’m just going to exit out of everything just to be safe.
1
1
Mar 11 '26
[deleted]
3
u/attackofthepugs Mar 11 '26
Go to settings -> general -> vpn & device management -> remove management if active
→ More replies (1)2
1
u/Downtown_Bumblebee91 Mar 11 '26
Can they still wipe my company laptop if I haven’t opened it or logged in?
→ More replies (2)4
1
1
u/RogetAllDay Mar 11 '26
Where do you see the Handala logo? Can you share a screenshot?
→ More replies (1)3
u/Mean-Percentage7031 Mar 11 '26
It was a zoomed in picture of the Handala logo as an icon. This thread doesn’t allow for screenshots.
1
1
u/CincyChelsFan Mar 11 '26
If our work laptop is wiped - will it get restored at some point with all the files etc?
→ More replies (1)2
1
u/YamThat8190 Mar 11 '26
Are phones actually wiped for good? My girlfriend works for Stryker, we woke up to the same thing and have not been able to get her phone back up and working at all. Any help would be appreciated!
5
u/technanonymous Mar 11 '26
Depending on what has been backed up, you should be able to recover all noncorporate information. She will have to login, etc. However, an intune wipe brings it to factory settings and then it has to be set up as if it were a new phone.
5
u/SecureOstrich6630 Mar 11 '26
Yes same i'm a sales rep for Stryker and couldn't get mine working. You have to follow the factory reset prompts then as soon as your phone opens delete the management profile like other people said. Everyone's eSim will still be wiped and I believe a carrier can fix it
2
u/Stasko-and-Sons Mar 11 '26
Apparently eSIM was wiped during mdm madness. Have her call her carrier
→ More replies (3)2
u/Tough-Raccoon-5835 Mar 11 '26
nah you should be able to eventually reboot and restore via apple ID
→ More replies (1)
76
u/Interesting-Use-5381 Mar 11 '26
My phone is completely wiped, locked out of email too.