Secured by Design - IAM & Cybersecurity Podcast
Great security solution are designed from the ground up..
Secured by Design is a podcast where Santosh shares practical insights, frameworks, and perspectives on identity security and other aspects of cybersecurity.
Each episode breaks down complex concepts into actionable ideas for professionals protecting digital identities, designing secure systems, and leading security initiatives.
Because true security is built and not bolted on...
Secured by Design - IAM & Cybersecurity Podcast
How Nation-States Target Critical Infrastructure: The Stryker Case Study
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Summary
This episode explores the March 2026 cyber attack on Stryker Corporation, a leading medical technology company, highlighting the attack's mechanics, motives, and lessons for organizations worldwide. Learn how nation-state actors target critical infrastructure and how to defend against such destructive threats.
Key Topics
- The timeline and impact of the Stryker cyber attack
- The role of nation-state actors and geopolitical motives
- Technical mechanics of the Wiper malware attack
- Lessons learned: privilege management, network segmentation, and threat intelligence
- Practical cybersecurity measures for organizations
Chapters
00:00 The Calm Before the Storm
02:28 Who are Stryker Corporation
04:07 What really happened?
08:36 Understanding the Attacker: Handala
10:15 How did they do it? Technical breakdown
14:15 Lessons Learned from the Stryker Incident
17:51 Some practical best practices
22:47 Closing thoughts
Keywords
cybersecurity, critical infrastructure, nation-state attack, Wiper malware, privilege management, zero trust, threat intelligence, healthcare cybersecurity
Let’s Stay Connected
📧 Email: santosh@getitrightsoln.co.uk
🔗 LinkedIn: linkedin.com/in/kssantosh
It's Wednesday morning, you beat the morning traffic and come into work a bit early. You got your coffee, you're settling in, and you reach out for your phone to check your messages. The screen is dead black. You turn to your laptop, as it boots, a logo flashes across the screen. But it isn't the usual one. It's some strange logo, and then there's total darkness. In seconds, the silence of your office is shattered by a wave of panic. It's not just your desk, it's not just your building. It's happening across the country. And 78 others. 56,000 employees' devices all wiped clean in a single surgical strike. There is no ransom notes. No one is asking for money. There's nothing to negotiate. This isn't a digital haste. It's a digital execution. This is not a scene from a trailer from for a new season of Mr. Rubo. It's exactly what happened to Striker Corporation on the 11th of March 2026. Welcome to Secure by Design, the podcast where we explore how identity and vital cybersecurity shape the foundations of our digital world. I'm Santosh, and in each episode, I'll share insights and practical perspectives on how we can build security into every layer of technology and business. From identity governance and zero trust to the latest in cloud and compliance. Let's dive into what it takes to design security that lasts. Today we are unpacking one of the most dramatic cyber attacks to hit a large corporation this decade. What happened, how it happened, and most importantly, what every organization, right from a small retailer or a consultancy to a large global manufacturer, can learn from it. Stick around, this one matters. Let's start with some context. Because if you are not in the healthcare industry, you might not immediately recognize the striker name. But there is a high chance that either you or someone close to you might have been touched by some products of theirs. Striker Corporation is headquartered in Michigan. They are one of the world's largest medical technology companies with revenues around $25 billion. They make the kind of equipment that quite literally keeps people alive, like surgical robots, like the Macro system used in knee and hip replacements, ambulance carts, hospital beds, emergency care systems, and products for the operating theater. They supply hospitals in roughly 75 countries and hold over 14,000 patents globally. All that said, what's more interesting is that they also have significant contracts with US Department of Defense and Department of Veteran Affairs. Add to that, in 2019, they acquired an Israeli medical technology company called Authospace. Why are we even talking about this information regarding the company? Well, that detail matters a lot to understanding why they were targeted. So a critical healthcare infrastructure company with links to the US military and Israeli acquisition operating in nearly every corner of the globe, that is the organization that was hit by the cyber attack. So let's walk through the timeline. The attack is understood to have started at around midnight Eastern time on Wednesday the 11th of March 2026, which is around 5 a.m. UK time. The devices were all wiped by 3:30 Eastern time or 8.30 UK time. So while most of us would have been asleep, devices across 79 countries were being erased. Later in the morning, Stryker identified what they described as a global network description to the Microsoft environment. Employees arriving at work at its major manufacturing and innovation hub in Cork, in Ireland, and turning on the device found their laptops and mobile phones completely non-functional. There was no corporate communication mechanism available. Employees had to resort to using text messages and WhatsApp chat to figure out what is happening. As per media, the hackers had remotely wiped devices running Microsoft across Stryker's global network. The instructions sent to employees was simple. Disconnect from all networks immediately and do not turn company-issued devices. Think about how much chaos that message would cause for a company of this size. Stryker filed an 8K disclosure with US Securities and Exchange Commission on the same day as they are legally required to do form for material cybersecurity incidents like this. In that filing and in public statements, the company said they believed the incident was contained and critically there was no indications of ransomware or traditional malware. This was not a ransomware attack. This was something more destructive and in some ways more alarming. On employee login screens, staff reported seeing a logo they didn't recognize. It was a symbol of a group called Handala. The same group took to social media and Telegram, claiming full responsibility, boasting that they had wiped more than 200,000 servers, mobiles and devices and other systems and forced Stryker to shut down offices across 79 countries. They also claimed to have stolen 50 terabytes of data posing a significant future threat, exposing Stryker's employees and partners to phishing attacks, etc. Stryker's share price fell more than 9% immediately, wiping roughly $6 billion of market value at one point. Stryker's customer facing systems, including their electronic ordering platform, remained unavailable for days. Order processing, manufacturing, and shipping operations were all disrupted. As a major supplier to surgeries worldwide, the ripple effect into the hospital supply chains were immediate and concerning. The hackers never attacked a single hospital, but the fear that they might was enough. Hospitals trying to protect their own patients started cutting the ties to Stryker's system just in case. The US Department of Health and Human Services began trying to assess potential impacts on patient care. US Federal Agency CISA, the Cybersecurity and Infrastructure Security Agency, launched a formal investigation and deployed technical assistance. Now, it's worth noting that strikers connected medical devices, things like their macro surgical robo, life pack defibrillators, connected buds, were all confirmed unaffected. This was because they operated on an entirely independent network and infrastructure. That is genuinely important and worth acknowledging as a design win. But the corporate and operational infrastructure, that was devastating. Let's talk about Handala because understanding the attacker is essential to understanding the attack. On the surface, Handala presents themselves as a pro-Palestinian anti-Israel activist. They have been active and increasingly blatant since the start of the US-Israel-Iran conflict. They frequently post about their operations on Telegram and X with a theatrical flair. But security researchers have been watching this group carefully. And the general consensus is that Handala is not simply a group of ideologically motivated hackers. They suspect it to be a friend for void manticor, a threat actor directly associated with Iran's intelligence agency. Coming to the reason for why Stryker, the group's social media post cited retaliation for a missile strike on an elementary school in Iran, which allegedly killed at least 168 children. An incident under Pentagon investigation as we speak. Stryker's connection to an Israeli acquired company, its US defense and veterans affairs contracts, and its symbolic status as American critical healthcare infrastructure made it an ideal target for retaliatory operation. This represented the first public concrete example of Iranian cyber retaliation in the course of this conflict. A lot of cybersecurity analysts feel that this is unlikely to be an isolated incident and others will soon follow. Now, for those of you who want to understand the mechanics, I think understanding the how is essential to building good defenses. Let's talk about what researchers believe happened technically. As we mentioned earlier, this was a Viper attack, not ransomware. In a ransomware attack, the attacker encrypts your data and demands payment to restore it. In a viper attack, the goal is pure destruction. Data is permanently deleted. There is no negotiation, no recovery key. The intent is maximum operational damage. The striker attack targeted devices managed by Microsoft Intune. Here's the critical detail. Microsoft Intune is a legitimate, widely used enterprise mobile device management platform. It's the tool companies use to push software updates, enforce security policies, and yes, remotely wiped devices if, say, an employee loses a phone or a laptop. The attackers didn't deploy some novel malware. The understanding so far is that they somehow gained access to Intune Administrator or Global Administrator privileges and used the platform's own built-in remote wipe capability, turning it against Striker at massive scale. This is what security researchers call a living off-the-land attack. The best way to think about it is this. Instead of trying to sneak a weapon past the guard at the castle gates, the attackers just walk right in and figure out how to use the swords that was already hanging on the wall. They use the company's own legitimate trusted software, the very tool we all use every day to do our jobs and weaponize them. Because the tools were legitimate, it was impossible to see the attack coming until it was way, way too late. That's why Stryker could accurately say there was no indication of ransomware or malware. If you think about it, technically from a traditional deduction standpoint, there wasn't. The attacker used legitimate administrative tooling. Before we jump into any conclusions, let me clarify firstly that this is not a vulnerability in Microsoft Intune per se. The product worked exactly as designed. The failure was in how privileged access to that product was controlled and monitored. And that is the lesson that should keep every IT and security leader up at night. The collateral damage in this are the users' personal devices, where by creating a work profile in it to check their corporate emails or teams on the go, these devices too came under the purview of Microsoft Intune. That meant when the wipe command was issued for all devices controlled by Intune, it did not distinguish between corporate and privately owned devices. And hence the personal devices were also fully wiped. As a result, those employees lost personal photos, private messages, eSIMs, and even the authenticated app that they could use for their own personal bank, email, etc. This attack became personal and incredibly destructive for them. How did the attackers get those admin credentials? That remains under active investigation as we speak. Phishing is the most common vector for credential theft. Supply chain compromises is another possibility. But what we know is that once they had the keys, they could use legitimate channels to wipe a globally distributed enterprise networks from the inside. Right. Let's go to what I think is the most important part of this conversation. What can organizations at every scale take away from what happened to Stryker? Lesson 1. Nation state and state-linked actors target critical infrastructure for geopolitical reasons, not financial ones. Stryker wasn't attacked for money. The attack was designed to destroy, disrupt, and send a message. Traditional ransomware defenses, while necessary, are not sufficient against this threat model. If your risk assessment only prices in financially motivated criminals, you have a dangerous blind spot. With the current geopolitical instability the world is undergoing, organizations are increasing their exposure to nation states who seek to disrupt and destroy. Lesson 2. Your management tooling is a target. The very platforms you use to manage and secure your estate, MDM systems, identity platform, cloud management consoles are extraordinarily high value targets for attackers. If an adversary gains admin access to your device management platform, they can do precisely what was done to Striker. Issue a wipe command to every device in your fleet. The blast radius of a compromised admin account in an NDM system is enormous. This is not theoretical. It has now happened publicly at scale. Lesson number three, I would say privileged access management is non-negotiable. The attack almost certainly hinged on obtaining administrator level credentials, whether through phishing, stolen credentials, or some other vector. Properly protected privileged accounts with multi-factor authentication, just-in-time access, and continuous monitoring would have raised their bar significantly. These are not exotic security controls. They are foundational. Lesson number four. If you notice, network segmentation and architectural resilience saved strikers' medical devices. The only saving grace in this attack was the fact that strikers connected medical devices like life pack systems, macro robots, and connected beds operate independently and were unaffected. This is not luck. It reflects architectural decision to isolate critical operational technology from corporate IT networks. This is a genuine lesson. Design your architecture so that a corporate IT compromise cannot cascade into your operational systems. Applying the same logic, it would be a good practice to perform any critical admin operations from a dedicated device that could have additional scrutiny applied. Lesson number five. Every organization should ask, given our business relationships, our geography, our customers, and our political profile, who might want to target us and why. Threat intelligence isn't just for large enterprises, it shapes the decisions you make about what to protect and how. So given everything we've just discussed, what should organizations actually do? Let me walk through the practical steps that security teams and leadership should be implementing or reviewing right now. Audit and restrict privilege access. Conduct an immediate audit of who holds global administrator and administrator rights across your Microsoft environment, Intune, Intra ID, and your cloud management consoles. Apply least privilege principles. People should have only the access they need for as long as they need. Implement just-in-time privilege access management so that admin rights are not persistently available, even to authorized administrators. Enforce phishing resistant MFA everywhere if possible. If not, at least for privileged users. Not SMS-based codes. Those can be intercepted. Use hardware security keys or pass key-based authentication for all privileged accounts. Compromise credentials with MFA in place are dramatically harder to weaponize. Place defensive controls around your MDM platform. Your mobile device management system should be treated as a crown duel. Add conditional access policies so that MDM admin functions can only be performed from specific trusted devices and locations. Set up anomaly detection so that bulk wipe commands or unusual administrative actions trigger immediate alerts and require secondary approval. Implement dual control or four ice principle for all critical processes. This will require another admin user to verify and approve protected actions. This can prevent from both compromised account-based attack like what we saw as well as accidental misconfiguration. This also increases the accountability and auditability since there is clear documentation of who initiated the process and who approved it. Implement ITDR, identity, threat, detection and response. This is a relatively emerging category of security tooling, specifically designed to detect abuse of legitimate identity and access management platforms. Traditional endpoint detections won't catch an attacker using your own admin tools against you. ITDR tools look for anomalous administrative behavior like a bulk wipe command and flag it in real time. We will cover this in detail in a dedicated podcast episode in the near future. Invest in network segmentation and zero trust architecture. Critical operation systems. In striker's case, they are medical devices. In yours, it might be production systems, OT environments, or critical data stores. They should be architecturally isolated. A zero trust model means that compromise of one segment does not automatically grant access to another. This is the principle that protected Stryker's devices. Maintain and test offline and immutable backups. A wiper attack destroys data. Your ability to recover depends entirely on your backup strategy. Backups must be offline or air gapped, not reachable via the same administrative credentials that could be compromised. And they must be tested regularly. There's no point in having backups if you have not tested the backup, whether it works fine. Knowing you have backups and knowing they work are two different things. Run geopolitically informed threat intelligence. Subscribe to credible threat intelligence services that track nation state and state linked actors. If your organization has attributes like government contracts, ties to geopolitical Politically sensitive countries, critical infrastructure status that might make you a target of ideologically or geopolitically motivated actors, your security portion needs to reflect that. Test your incident response and business continuity plans. To the credit, Stryker activated the cybersecurity response plan and engaged external advisors quickly. That matters, but the time to discover gaps in your business continuity plan is not during an incident. Run tabletop exercises, simulate a viper attack, find out how long it actually takes to restore operations from backup. The answer might actually surprise you. The striker attack is a watershed moment. It represents a documented, confirmed, large-scale destructive cyber attack by an Iranian state-linked group against a major US healthcare and critical infrastructure company. It is the first of its kind in this conflict, and experts are already warning it will not be the last. What makes it particularly instructive is the attack vector. Not zero-day exploits, not sophisticated custom malware, but legitimate administrative tools turned against their own owners. The attackers didn't need to break down the front door. They found a key under the mat. The message for every organization, public or private, a small retailer or a FTSE 250 company, small charity or global enterprise, is this. And when they choose to act, the results can be instantaneous and devastating. That said, the defenses against these are already available for us to implement. Prior to access management, phishing resistant MFA, MDM controls, network segmentation, offline backups, threat intelligence, they're all foundations. Build them. Let me close with a question. The attackers who took down Striker only needed to find out one way in. One open window. One stolen password. The most important question for our organizations right now is this. How many open windows do we have? We need to answer that and we need to answer it today. Because our ability to function depends on it. Thanks for listening to Secured by Design. If today's episode gave you something to think about, subscribe and follow on your favorite streaming platforms for more discussions on identity and cybersecurity. Please feel free to share it with your team. You can also connect with me on LinkedIn for updates and new episode releases. Until next time, stay secure, stay resilient, and stay secured by design.