The Handala Hack, attributed to the Iran-linked Handala group, carried out a destructive wiper attack against Stryker Corporation on March 11, 2026. This incident primarily focused on wiping data rather than exfiltration, and the claims of broader attacks on 27 companies or links to 'Minab’s Innocents' lack substantiation. The attack was a direct compromise of Stryker's Microsoft Entra ID (Azure AD) and Intune environment via credential theft.
While the attacker claimed exfiltration of up to 12 PB of data, primarily corporate data, there is no verified evidence of specific Personally Identifiable Information (PII) including SSN, medical records, or financial data exposure. Approximately 56,000 employees were temporarily displaced, though attacker claims of impacting over 200,000 devices across 79 countries are unverified. States affected include Michigan, with disruptions also in Cork, Ireland, but no specific state-level breakdowns are available beyond the US headquarters. The company has not provided a detailed public statement regarding data exposure, and no official breach notification letters or notifications to individuals have been reported. It remains unclear if any sensitive customer or employee data was compromised.
Details about the full scope of this incident can still emerge. Official notices may be delayed.