The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued guidance instructing U.S. organizations to strengthen administrative controls in Microsoft Intune following a cyberattack on Stryker Corporation that involved data exfiltration and substantial data deletion.
Incident Overview
The incident involved Stryker Corporation, a U.S.-based medical technology company. A threat actor known as Handala is behind the attack that affected systems within Stryker’s Microsoft environment. The group is identified as a hacktivist organization with reported links to Iran’s Ministry of Intelligence and Security.
Handala stated that it removed 50 terabytes of data prior to initiating destructive actions. The group also reported deleting 12 petabytes of data from approximately 200,000 devices. The attack did not rely on traditional wiper malware. Instead, the attacker used the delete functionality within Microsoft Intune, a cloud-based endpoint management platform. Data from Windows devices, including laptops and mobile phones, were deleted.
The attacker gained access to the platform by compromising an administrator account. A new Global Administrator account was then established and used to carry out the data deletion activities across the environment.
CISA Alert and Security Measures
On March 18, 2026, CISA released an alert addressing malicious cyber activity targeting endpoint management systems. The alert referenced the March 11, 2026 cyberattack involving Stryker Corporation and confirmed that the company’s Microsoft environment was impacted.
CISA directed organizations to strengthen endpoint management configurations by applying Microsoft’s security guidance. This includes limiting administrative privileges by assigning only the permissions required for routine tasks through Microsoft Intune role-based access control.
Organizations are also directed to implement phishing-resistant multifactor authentication and maintain strict controls over privileged access. Microsoft Entra ID capabilities is recommended to restrict unauthorized execution of privileged actions within Microsoft Intune.
The guidance also includes implementing policies that require approval from more than one administrator before performing sensitive or high-impact actions. These actions include application changes, device wiping, script deployment, configuration updates, and role-based access control adjustments.
Healthcare providers should update their HIPAA training for employees with these cybersecurity recommendations in the guidance.
Threat Activity Context
The cyberattack occurred during ongoing military activity involving Iran, with public threats indicating potential retaliatory actions that may include cyber operations targeting U.S. organizations.
The Palo Alto Networks Unit 42 team reported an increase in cyber incidents associated with the conflict. Observed activity includes both data exfiltration and data destruction. While the Stryker incident involved misuse of Microsoft Intune to delete data, Iran-linked threat actors have also used wiper malware in other operations.
Unit 42 identified increased activity from groups connected to Iran, including both hacking groups and hacktivist organizations. The observed activity includes a rise in wiper-based attacks and spear phishing campaigns.
Operational Controls
Organizations are instructed to apply timely system patches, maintain reliable data backup processes, and ensure that disaster recovery and business continuity plans are tested. These controls address the risk of data destruction and support recovery following large-scale data loss events.
Image credit: photo for everything, Adobestock









