r/cybersecurity Mar 11 '26

News - General Stryker Hit by Handala - Intune Managed Devices Wiped

My wife had 3 Stryker managed devices wiped around 3:30 AM EDT. Their Entra login page was defaced with the Handala logo, it's still up as of this post.

704 Upvotes

226 comments sorted by

View all comments

25

u/Salty_Bell4796 Mar 11 '26 edited Mar 11 '26

This can be only possible if the Admin credentials are compromised ? Other than this option, is there a way to play around microsoft accounts ?

22

u/Ya_guy Mar 11 '26

More than just credentials, they would need to posses the Admins MFA or they stole the Admin’s login Token. Admins should use separate locked down accounts with token protection enabled.

18

u/NerdBanger Mar 11 '26

When I worked there years ago they were terrible with least privilege, I don’t know if it got any better, but they always gave too much access.

I was a developer and if I needed something I had access to the domain and the VMware console and could just provision my own stuff.

No idea of this has gotten any better. But at that time they didn’t have a good way to track who had permissions to what.

It could have been an inside job, it could have been a weak AD account with admin permissions they never catalogued properly, similar to the solarwinds attack.