{"id":199369,"date":"2026-03-11T22:30:34","date_gmt":"2026-03-12T02:30:34","guid":{"rendered":"https:\/\/tetrabulletin.com\/?p=199369"},"modified":"2026-03-11T22:30:34","modified_gmt":"2026-03-12T02:30:34","slug":"iran-appears-to-have-conducted-a-significant-cyberattack-against-a-u-s-company-a-first-since-the-war-started","status":"publish","type":"post","link":"https:\/\/tetrabulletin.com\/?p=199369","title":{"rendered":"Iran appears to have conducted a significant cyberattack against a U.S. company, a first since the war started"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div>\n<p id=\"anchor-715404\" class=\"body-graf\">An Iran-linked hacker group has claimed responsibility for a cyberattack on a medical tech company in what appears to be the first significant instance of Iran\u2019s hacking an American company since the start of the war between the countries.<\/p>\n<p id=\"anchor-a22ac8\" class=\"body-graf\">The company, Stryker, which is headquartered in Michigan, produces a range of medical equipment and technology.<\/p>\n<p id=\"anchor-bdefcc\" class=\"body-graf\">Historically, Iran has conducted some of the most infamous \u201cwiper\u201d cyberattacks on national enemies, aiming to simply erase all data on computers\u2019 networks. Victims include <a href=\"https:\/\/www.cfr.org\/cyber-operations\/compromise-of-saudi-aramco-and-rasgas\" target=\"_blank\">Saudi Aramco<\/a>, Saudi Arabia\u2019s national oil company, in 2012, and the <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2014-12-11\/iranian-hackers-hit-sheldon-adelsons-sands-casino-in-las-vegas\" target=\"_blank\">Sands Casino in 2014<\/a>.<\/p>\n<p id=\"anchor-b80ce9\" class=\"body-graf\">Since the war started, some established hacker groups sympathetic to Iranian leadership have claimed minor attacks, but most have been relegated to briefly altering the appearance of a website, and none have appeared to have had major impact. Some tech and cybersecurity companies, including Google, and the email cybersecurity company Proofpoint have told NBC News that they have largely seen Iran\u2019s hackers conducting espionage related to the war.<\/p>\n<p id=\"anchor-5f1f9f\" class=\"body-graf\">But that appears to have changed Wednesday, with what appears to have been a different type of attack that also deleted information from devices. A Stryker employee, who requested to not be identified because they are not authorized to speak for the company, said that employee\u2019s work-issued phones stopped working, grinding work and communications with colleagues to a standstill. <\/p>\n<figure class=\"styles_inlineImage__FvnTh styles_medium__MEKii\" id=\"anchor-86afd3\"><picture class=\"styles_image__i32F7\" data-testid=\"picture\" data-flavor=\"fit\" data-original-height=\"1667\" data-original-width=\"2500\"><source media=\"(min-width: 1000px)\" srcset=\"https:\/\/media-cldnry.s-nbcnews.com\/image\/upload\/t_fit-560w,f_avif,q_auto:eco,dpr_2\/rockcms\/2026-03\/260311-stryker-vsb-2130-c72474.jpg 2x, https:\/\/media-cldnry.s-nbcnews.com\/image\/upload\/t_fit-560w,f_auto,q_auto:best\/rockcms\/2026-03\/260311-stryker-vsb-2130-c72474.jpg 1x\"\/><source media=\"(min-width: 320px)\" srcset=\"https:\/\/media-cldnry.s-nbcnews.com\/image\/upload\/t_fit-760w,f_avif,q_auto:eco,dpr_2\/rockcms\/2026-03\/260311-stryker-vsb-2130-c72474.jpg 2x, https:\/\/media-cldnry.s-nbcnews.com\/image\/upload\/t_fit-760w,f_auto,q_auto:best\/rockcms\/2026-03\/260311-stryker-vsb-2130-c72474.jpg 1x\"\/><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/media-cldnry.s-nbcnews.com\/image\/upload\/t_fit-760w,f_auto,q_auto:best\/rockcms\/2026-03\/260311-stryker-vsb-2130-c72474.jpg\" alt=\"Stryker\" height=\"1667\" width=\"2500\"\/><\/picture><figcaption class=\"caption styles_caption__TCewG\" data-testid=\"caption\"><span class=\"caption__container\" data-testid=\"caption__container\">Stryker, based in Michigan, produces a range of medical equipment and technology.<\/span><span class=\"caption__source\" data-testid=\"caption__source\">Smith Collection \/ Gado via Getty Images file<\/span><\/figcaption><\/figure>\n<p id=\"anchor-b6bb24\" class=\"body-graf\">Handala Team has claimed responsibility for the Stryker hack in statements on its Telegram and X accounts. The group routinely brags about its exploits on the social media platforms, which have in recent days taken down previous versions of their accounts.<\/p>\n<p id=\"anchor-c738b1\" class=\"body-graf\">Specifics of how the hack was conducted are not clear. But public evidence of the hack points to the likelihood that hackers gained access to the company\u2019s Microsoft Intune account, which the employee confirmed Stryker uses. From there, Handala appears to have wiped some employees\u2019 devices back to factory settings, an expert said.<\/p>\n<p id=\"anchor-0cf948\" class=\"body-graf\">\u201cThey seem to have obtained access to the Microsoft Intune management console. This is a solution for managing corporate devices,\u201d said Rafe Pilling, the director of threat intelligence at the cybersecurity company Sophos, which has tied Handala to Iran\u2019s Intelligence Ministry.<\/p>\n<p id=\"anchor-25e9a9\" class=\"body-graf\">\u201cOne of the features is the ability to remotely wipe a device if it\u2019s lost\/stolen etc. Looks like they triggered that for some or all of the enrolled devices,\u201d he said.<\/p>\n<p id=\"anchor-e6573e\" class=\"body-graf\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/intune\/intune-service\/remote-actions\/device-wipe?pivots=windows\" target=\"_blank\">Microsoft\u2019s website<\/a> describes the remote wipe feature as \u201ccommonly used when a device needs to be retired, repurposed, reset for troubleshooting, or securely erased if lost or stolen.\u201d<\/p>\n<p id=\"anchor-8f7674\" class=\"body-graf\">In a statement on its website Wednesday, Stryker said that the disruption was due to a cyberattack but that its own systems were not directly hacked and that ransomware \u2014 a common type of cybercrime that can also significantly disrupt companies\u2019 networks \u2014 was not a factor.<\/p>\n<p id=\"anchor-118f47\" class=\"body-graf\">\u201cStryker is experiencing a global network disruption to our Microsoft environment as a result of a cyber attack. We have no indication of ransomware or malware and believe the incident is contained,\u201d the statement said.<\/p>\n<p id=\"anchor-bb891b\" class=\"endmark body-graf\">The company did not respond to a request for further details. Microsoft did not respond to a request for comment.<\/p>\n<\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/www.nbcnews.com\/world\/iran\/iran-appears-conducted-significant-cyberattack-us-company-first-war-st-rcna263084\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] An Iran-linked hacker group has claimed responsibility for a cyberattack on a medical tech company in what appears to be the first significant instance of Iran\u2019s hacking an American company since the start of the war between the countries&#8230;.<\/p>\n","protected":false},"author":1,"featured_media":199370,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[32],"tags":[],"class_list":["post-199369","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-world"],"_links":{"self":[{"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=\/wp\/v2\/posts\/199369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=199369"}],"version-history":[{"count":0,"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=\/wp\/v2\/posts\/199369\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=\/wp\/v2\/media\/199370"}],"wp:attachment":[{"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=199369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=199369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tetrabulletin.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=199369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}