Attack + Goal
March 2026 on Stryker, $25B med-tech company. Goal was geopolitical disruption.
Result
200k devices wiped, cardiac transmission system offline, +5k employees sent home
Method
Likely spear phish and credential theft of a legitimate admin-level account; no malware or ransomware was used.
Financial Impact
Estimated $24–$40M in direct hardware cost, $15M–$50M in operational disruption, $62M–$140M in total direct and indirect costs (source)
In March 2026, Stryker, a $25B medical device maker, suffered a mass wipe of its entire device fleet. Attackers had gained access to their device management platform, Microsoft Intune, to issue a legitimate wipe command across 200,000 devices in 79 countries. Corporate laptops were erased. Personal phones enrolled through the company's BYOD program were factory reset, wiping employees' photos and personal apps along with corporate data. Paramedic teams even lost access to cardiac monitoring tools mid-shift and had to fall back to radio.
The wipe command came through Intune directly from a legitimate account with admin-level access, and it performed as it was designed to do.
The cost of an incident like this isn't only the operational disruption of each day spent recovering. It's the reputational damage. And it just takes one account. Credential abuse was the initial access vector in 22% of breaches in 2025 (Verizon).
Flag admin credentials shortly after they surface in a phishing kit, before they can be used to issue a wipe command.