Iran-Linked Hackers Claim Responsibility for Cyberattack on US Medical Device Giant Stryker
An Iran-linked hacking group has claimed responsibility for a cyberattack that disrupted systems at medical device manufacturer Stryker, raising concerns about escalating cyber retaliation targeting U.S. organisations.

Cyberattack disruption targeting Stryker medical technology company linked to Iranian hacking group.
A hacking group believed to be linked to Iran has claimed responsibility for a cyberattack targeting Stryker, a major U.S.-based manufacturer of medical devices and healthcare technologies.
The group, operating under the name Handala, posted messages on its Telegram channel asserting that it carried out the attack as retaliation for recent geopolitical tensions involving Iran.
Network Disruptions Reported Across Systems
Stryker confirmed that the incident caused disruptions across parts of its global network infrastructure.
In a regulatory filing, the Michigan-based company said some internal systems experienced temporary limitations and outages, and the timeline for full restoration remains uncertain.
The company stated that it has not identified ransomware or malicious encryption, and believes the incident has been contained while investigations continue.
Employees and contractors also reported unusual system behavior, including login pages displaying symbols associated with the hacking group. However, these reports have not been independently verified.
Hackers Claim Retaliation Motive
The Handala group said the attack was conducted in response to a strike on a school in the southern Iranian city of Minab.
According to statements shared on the group’s messaging channel, the cyber operation was intended as retaliation for what they described as ongoing attacks against Iran.
The incident comes amid growing concerns that Iranian-affiliated cyber groups may increase operations targeting Western organisations during periods of geopolitical conflict.
Experts Warn of Escalating Cyber Retaliation
Cybersecurity specialists say the attack reflects a broader trend of state-aligned hacking groups using disruptive cyber operations as geopolitical retaliation.
Cynthia Kaiser, senior vice president at the Halcyon Ransomware Research Center and a former FBI cyber official, warned that such incidents could become more frequent.
According to Kaiser, destructive cyberattacks — including data deletion and system disruption — are increasingly used by proxy groups to target companies linked to rival nations.
Global Operations Impacted
Stryker employs more than 56,000 people and operates in over 60 countries, making it one of the world’s largest healthcare technology companies.
Following news of the cyber incident, the company’s stock experienced a decline, with shares falling approximately 3.6 percent in market trading.
Meanwhile, officials from the White House stated that U.S. authorities are actively monitoring potential cyber threats affecting critical sectors and private companies.
Law enforcement agencies including the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency have not yet publicly commented on the incident.
Growing Role of Cyber Operations in Geopolitics
Security researchers from Check Point say the Handala group has been linked to multiple cyber operations in recent years, including data leaks, disruptive attacks, and politically motivated hacking campaigns.
Experts believe the group may operate with connections to Iran’s intelligence apparatus, highlighting the increasing role of cyber capabilities in international conflicts.
The attack underscores the growing risk that corporations may become targets of geopolitical cyber retaliation, particularly during periods of heightened global tensions.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.