Stryker identified the attack on March 11, and the damage pattern was unusual. Ordering, manufacturing and shipping went down together. Researchers at Halcyon reported that the attacker held administrator access to the company’s Microsoft Intune environment and used it to push remote wipe commands to phones and workstations enrolled in the platform.

Handala, an actor tracked as Iran-linked, claimed the intrusion and put its haul at 50 terabytes plus thousands of wiped machines, numbers nobody has confirmed. The mechanism is confirmed, and it matters more: an endpoint management console built to administer devices at scale can also destroy them at scale if the wrong person holds the admin role.

CISA and the FBI issued guidance on March 18 aimed at that layer. Enforce role-based access with minimum permissions, require phishing-resistant MFA on privileged accounts, and add a second administrative approval before high-consequence actions like a device wipe can run. Forrester analyst Paddy Harrington added that MFA on the management console alone cuts the odds of a simple account takeover.

For device makers the lesson is about identity. The attacker did not need an exploit in any medical product; admin credentials for the management plane were enough to take manufacturing offline at one of the largest orthopedics companies in the world.