Skip to content
Case Studies4 min read

The Stryker Case: How Iran Turned Microsoft Intune Into a Weapon and Wiped 200,000 Devices Across 79 Countries

9 April 2026|AEGIDA Research Team

At 3:30 AM EST on March 11, 2026, the first wipe commands began propagating through Stryker Corporation's Microsoft Intune infrastructure. Three hours later, when 56,000 employees across 79 countries started their workday, they found their laptops, corporate phones, and tablets completely wiped. Black screens. No access. No email. No way to process orders, manage production, or coordinate distribution of life-saving medical devices. In less than three hours, a group of Iranian hackers had turned the company's device management system — a tool designed to protect devices — into the most efficient weapon ever used to destroy them.

The Attacker: Handala, the Hacktivist Face of Iranian Intelligence

Handala presents itself as a pro-Palestinian hacktivist group, first appearing in December 2023. But behind the hacktivist facade lies a state intelligence operation. Unit 42, Brandefense, and Microsoft assess with "high confidence" that Handala is one of several online personas maintained by Void Manticore — an Iranian state-linked threat actor operating since at least 2022, aligned with Iran's Ministry of Intelligence and Security (MOIS). The group is tracked as Banished Kitten, Cobalt Mystique, Red Sandstorm, and Void Manticore.

On March 19, 2026, the FBI seized Handala's data leak website and related domains. The DOJ called them "psychological operations" run by Iran's Ministry of Intelligence and Security. The U.S. government formally accused Iran's government of operating the group that hit Stryker.

Phase 1: Silent Infiltration — Months Before the Explosion

The attack didn't start on March 11. Check Point Research established that initial access was obtained months before the destructive phase. Researchers identified 278 sets of compromised Stryker credentials between October 2025 and March 2026. The likely method: credential theft through phishing or infostealer malware. Proofpoint documented active AiTM phishing campaigns by TA450 (MuddyWater, MOIS-linked with documented Handala overlap) targeting U.S. organizations as recently as March 8 — three days before the attack. AiTM phishing bypasses MFA by intercepting session tokens in real-time through an attacker-controlled proxy.

Phase 2: Escalation — From Employee to Cloud God

From initial access, attackers navigated Stryker's Microsoft Entra ID environment and compromised a Global Administrator account. Per KrebsOnSecurity, they created a new Global Administrator account after compromising an existing one. With Global Admin privileges, attackers accessed Microsoft Intune — the MDM platform managing 200,000+ devices worldwide. Intune is designed for administrators to configure, update, protect, and remotely wipe corporate devices. In an attacker's hands, it becomes the most efficient mass destruction weapon imaginable.

The Stryker attack introduces a new paradigm: the weapon isn't malware, isn't an exploit, isn't a custom wiper. The weapon is the company's own legitimate management tool. Intune did exactly what it was designed to do — wipe devices on administrator command. The problem: the "administrator" was an Iranian intelligence agent. CISA issued a specific alert (March 18, 2026) urging organizations to harden endpoint management configurations.

Phase 3: Execution — 200,000 Devices in 3 Hours

At 3:30 AM EST, attackers launched the wipe command through Intune. Between 5:00 and 8:00 UTC, approximately 80,000 Windows devices were wiped. Total claimed: 200,000+ devices across 79 countries. The electronic ordering system — handling $5.5 billion in quarterly revenue — went offline. The company shifted to manual order processing. Surgical procedures at hospitals depending on Stryker devices were delayed. Handala also claimed 50 TB of data exfiltration, though investigators found no evidence of exfiltration.

The Impact: Hospitals, Stock Market, and National Security

  • 200,000+ devices wiped across 79 countries in under 3 hours
  • $5.5 billion in quarterly orders processed manually for days
  • 22 days to full recovery (March 11 → April 2, 2026)
  • -9% stock drop: ~$9 billion in market cap evaporated in one day
  • Surgical procedures delayed at hospitals dependent on Stryker devices
  • FBI seized Handala leak sites on March 19
  • CISA issued specific alert on endpoint management hardening
  • SEC filing: recovery timeline "unknown" in early phases

The Most Important Lesson: Your MDM Is Your Greatest Vulnerability

Sygnia defined this as an "Identity Control Plane Attack" — an attack targeting not individual devices but the control plane governing them all. The identity control plane (Entra ID) and device management plane (Intune) became the single point of failure that, once compromised, enabled simultaneous destruction of the entire global infrastructure. This isn't an Intune bug or Microsoft vulnerability — it's an architectural flaw in how organizations configure and protect their management systems.

Every organization using an MDM (Intune, Workspace ONE, Jamf, SCCM) must ask: if an attacker gained Global Administrator privileges in our cloud environment, could they wipe all our devices with a single command? If the answer is yes — and in most cases it is — then the MDM is the organization's greatest vulnerability, not its greatest protection.

Operational Recommendations: How to Protect Your MDM

  1. 1.Dual-approval for destructive operations: require a second administrator's approval for any mass wipe on Intune. CISA explicitly recommends this in its March 18, 2026 alert.
  2. 2.Administrative role separation: don't use Global Administrator for daily operations. Create dedicated Intune roles with minimum necessary permissions (least privilege).
  3. 3.Rigorous Conditional Access for admins: require managed devices, hardware MFA (FIDO2/WebAuthn), verified geolocation, and dedicated Privileged Access Workstations (PAW).
  4. 4.Real-time monitoring of high-impact Intune operations: alert on any wipe command, any new Global Admin creation, any device policy modification, and any admin access from unrecognized IPs.
  5. 5.Identity Control Plane protection: implement Privileged Identity Management (PIM) with just-in-time privilege activation, continuous monitoring, and periodic access reviews.
  6. 6.Offline configuration backup: maintain offline backup of Intune configuration, policies, and device inventory.
  7. 7.Total-wipe response plan: include the specific scenario "all devices wiped" in incident response. How do you communicate without email? How do you coordinate 56,000 employees without IT systems? Stryker took 22 days.
  8. 8.MDM segmentation: segment the Intune environment by region, function, or criticality so that one segment's compromise doesn't enable global device fleet destruction.

Conclusion: The Day a Protection Tool Became a Weapon of Destruction

The Stryker attack of March 11, 2026 is an inflection point in cybersecurity history. Not for malware sophistication — there was no malware. Not for exploit complexity — there was no exploit. The attack is devastating in its simplicity: one compromised admin account, one legitimate wipe command, 200,000 devices erased. The genius lies in understanding that the most efficient way to destroy a global IT infrastructure isn't to attack it — it's to use the tool the company built to manage it.

The real question for every CISO, every CTO, every board is not "could this happen to us?" — it's "what would prevent us from ending up like Stryker if it happened tomorrow at 3:30 AM?" For most organizations, the answer is: nothing. And that is the problem the Stryker attack has exposed irreversibly.

Primary sources: KrebsOnSecurity (March 2026), BleepingComputer (March 2026), TechCrunch (March 17, 2026), Bloomberg (March 11, 2026), SecurityWeek (March 2026), NBC News (March 19, 2026), CISA Alert (March 18, 2026), Sygnia — "Identity Control Plane Attack", Guardz, Lumos, glueckkanja, Obsidian Security, Check Point Research, Unit 42, HIPAA Journal (April 2026), Stryker Corporation official communication, Yahoo Finance / Simply Wall St.