In a company statement to customers, Stryker said the incident was limited to its internal Microsoft corporate environment and erased nearly 80,000 employee devices between 05:00 and 08:00 UTC on March 11.
KEY FACTS
- Incident internal Microsoft corporate environment disruption
- Scope nearly 80,000 employee devices wiped
- Malware no malware deployed on systems
- Operational impact electronic ordering offline, manual orders required
The attacker used the wipe command in Intune device wipe documentation to erase devices after compromising an administrator account and creating a new Global Administrator account.
Per the disclosure, all products including connected and digital technologies remain safe to use. Electronic ordering systems remain offline and customers must place orders manually through sales representatives while restoration continues.
Employees in multiple countries found managed devices remotely wiped overnight. Some personal devices that had been enrolled in the company network lost personal data during the wiping process.
A post linked to the Handala hacktivist group included claims of wiping more than 200,000 systems and taking 50 terabytes of data. Investigators found no indication that data was exfiltrated.
The Detection and Response Team (DART) and Palo Alto Unit 42 are conducting the investigation while restoration work focuses on resuming shipping and transactional services. Any orders placed before the incident will be honored and orders made during the disruption will be processed as systems are restored.
WHY IT MATTERS
The incident removed large numbers of managed endpoints and disrupted order processing without deploying malware, showing the operational risk posed by compromised administrative access to cloud device management tools.

