Skip to main content

International Threats: Medtech Giant Offline Following Significant Cyber Attack Wiping Out Corporate Systems Globally

March - April 2026

 

 

Stryker Corporation, a multi-billion-dollar medical technology company, suffered a global outage to its IT systems and Microsoft environment in March due to a geo-politically motivated cyber attack. The attack caused the company’s networks to be disrupted in many of its bases of operation around the world which affected manufacturing, order processing and shipping. Thousands of employees lost access to corporate systems, and some devices were rendered inoperable.

Although attributed to a well-established Iran-linked hacker group, Handala, the attack method did not involve sophisticated malware, but rather, abused a legitimate tool used within the organisation with subpar configurations applied enabling the attackers to execute significantly damaging commands on Stryker’s corporate environment.

Initially, the attackers gained access to a compromised account. This account had permissions to send wipe commands to all connected devices using the corporation’s Microsoft Intune implementation, effectively turning a legitimate tool into a kill switch.

The company later reported the incident as contained, but full restoration of services was by no means immediate with many operations having issues well over a week after the initial attack, and in May stated that the attack had meaningfully impacted first-quarter results.

Cyber-attackers have heavily pivoted to social engineering, unauthorised access using legitimate credentials and abusing the tools already baked into the target’s corporate environment as opposed to solely using malicious code and exploits. This stresses the growing reliance on, and requirement of, third-party supplier assurances, effective access controls and secure configuration of legitimate tools and platforms used within organisations.

Security tools exist that can support detection and response to anomalous, malicious or unexpected behaviour but these tools can only do so much, requiring organisations to take all aspects of operations into account.

 

Prominent Decentralised Finance (DeFi) Company Suffers Huge Losses Due to Exploited Configuration Oversight

In April, cyber criminals stole approximately $292 million from the cryptocurrency firm Kelp DAO in a multifaceted, yet ultimately preventable, security incident. Unlike the sophisticated zero-day exploits often associated with high-profile breaches, this attack stemmed from a fundamental verification weakness. When combined with other techniques, this flaw enabled the unauthorised minting (creation) of cryptocurrency and the subsequent transfer of funds to wallets controlled by the attackers.

Kelp DAO relied on a ‘1-of-1’ verifier configuration, meaning that any instruction submitted to the DeFi system required only a single verification to be accepted, providing other validation systems in the network were out of action. This approach effectively provided attackers with a considerably unobstructed path to submit malicious instructions. By pairing this verification weakness with a carefully orchestrated Distributed Denial-of-Service (DDoS) attack, the adversaries were able to execute their malicious instructions as valid. This ultimately allowed them to generate and exfiltrate millions of dollars in value.

The third-party service used to transmit the malicious instructions later stated that the incident could have been prevented had Kelp DAO implemented a multi-verification mechanism, which was readily available. Kelp DAO, however, maintains that its chosen configuration aligned with the documentation provided by the third-party vendor and was therefore considered acceptable at the time.

This incident emphasises how poorly designed, misunderstood, or complacently managed security configurations can lead to significant consequences. The notion that “this will do” is insufficient when it comes to security, particularly in an environment where threat actors can readily exploit weak controls without encountering additional defensive layers. It is essential for businesses to avoid simply adopting default configurations without first assessing the associated security implications, and instead ensure that security considerations are embedded into the design and implementation of their business processes.