// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / Microsoft
Breach Record

Microsoft

DISCLOSED 2026-03-13 · RANSOMWARE · RANSOMWARE

Medtech company Stryker suffered a cyberattack claimed by Iran-linked group Handala, disrupting order processing, manufacturing, and shipping. The attack abused Microsoft Intune to push remote wipe commands to endpoints, bypassing traditional endpoint security. Stryker stated the incident is contained to its internal Microsoft environment with no malware or ransomware detected.

The record

What we know

Disclosed
2026-03-13
Attack vector
Ransomware
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other ransomware breaches on file

This page is the permanent ColdRecon entry for the Microsoft disclosure. It updates if new public reporting emerges. All tracked breaches →

Microsoft just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →