$10M+

Healthcare breaches remain among the most costly incidents across all sectors.

60 days

HIPAA breach notification timelines make early detection operationally critical.

24/7

Continuous monitoring helps security teams contain compromise before lateral movement.

Stryker devices wiped through a compromised Intune account

A look at the cost of compromise

Attack + Goal

March 2026 on Stryker, $25B med-tech company. Goal was geopolitical disruption.

Result

200k devices wiped, cardiac transmission system offline, +5k employees sent home

Method

Likely spear phish and credential theft of a legitimate admin-level account; no malware or ransomware was used.

Financial Impact

Estimated $24–$40M in direct hardware cost, $15M–$50M in operational disruption, $62M–$140M in total direct and indirect costs (source)

In March 2026, Stryker, a $25B medical device maker, suffered a mass wipe of its entire device fleet. Attackers had gained access to their device management platform, Microsoft Intune, to issue a legitimate wipe command across 200,000 devices in 79 countries. Corporate laptops were erased. Personal phones enrolled through the company's BYOD program were factory reset, wiping employees' photos and personal apps along with corporate data. Paramedic teams even lost access to cardiac monitoring tools mid-shift and had to fall back to radio.

The wipe command came through Intune directly from a legitimate account with admin-level access, and it performed as it was designed to do.

The cost of an incident like this isn't only the operational disruption of each day spent recovering. It's the reputational damage. And it just takes one account. Credential abuse was the initial access vector in 22% of breaches in 2025 (Verizon).

Flag admin credentials shortly after they surface in a phishing kit, before they can be used to issue a wipe command.

Sources Tech Insider · Penligent · Cyber Security News · Verizon DBIR 2025

TagsATOHealthcareSupply Chain

How we Help

Healthcare Monitoring

Prebreach intelligence for hospitals, clinics, and research institutions.

Employee Credential Monitoring

Track compromised staff credentials from phishing and malware sources before unauthorized access to EHR and internal systems.

Session Cookie Theft Detection

Identify stolen authenticated sessions that can bypass MFA and accelerate account takeover.

Threat Actor Context

Correlate healthcare-targeted campaigns, malware families, and infrastructure for faster investigation and response.

Compliance-Ready Audit Trail

Use audit-logged investigations and evidence exports to support HIPAA and broader governance workflows.

Protect Your Healthcare Organization with DarkArmor

Detect credential compromise earlier and reduce patient data exposure risk.