6 min read

When 200,000 Devices Go Dark – Stryker Attack

What the Stryker Attack Reveals About Distributed Asset Visibility

On March 11, 2026, Stryker – a $25 billion medical device company with 56,000 employees in 61 countries – was brought to a near standstill. Attackers wiped devices across 79 countries, disrupted manufacturing and shipping globally, and allegedly made off with 50TB of data. The root cause wasn’t a novel zero-day. It was administrative access to a device management tool most organizations trust completely.

The Stryker attack is a turning point. Not because it was technically sophisticated – but because of what it exposes about how unprepared most organizations are to see, understand, and respond to threats that move across distributed device estates at scale.

What Actually Happened at Stryker

Iran-linked threat group Handala claimed responsibility for the attack, which researchers at Halcyon and Check Point have been investigating. According to their findings, the attackers gained Microsoft Intune administrator or global administrator credentials  and then used Intune exactly as designed: to push commands to enrolled devices.

Those commands were remote wipes.

Stryker told employees to disconnect from all networks and power off company devices. By then, the damage was already global. Order processing, manufacturing, and shipping were disrupted across dozens of countries. Stryker’s CEO confirmed the company had “contained” the incident in a LinkedIn post – but the restoration phase had barely begun.

The cloud environments (AWS, GCP) were unaffected. The Microsoft-managed device estate was not.

This is a critical distinction. The attack didn’t breach Stryker’s perimeter in a traditional sense. It moved laterally through the device management layer – the very layer designed to give IT centralized control.

The Real Blind Spot: Not Knowing What’s Out There

Here’s the question every security leader should be asking after Stryker: If an attacker started wiping devices on your network right now, how long would it take you to know which devices were affected – and which weren’t?

For most organizations, that answer is uncomfortable. Security tools are good at monitoring what they already know about. Managed endpoints have agents. Corporate infrastructure has monitoring. But the actual device estate – across branch offices, remote workers, partner environments, and distributed infrastructure – is rarely mapped with the completeness or speed that an incident response demands.

In a distributed attack like Stryker’s, the difference between a contained incident and a catastrophic one is measured in minutes. And minutes require that you already know exactly what’s on your network before the alert fires.

Why Distributed Networks Make This Harder

A company operating across 79 countries — or even one with 300 remote workers spread across home networks – faces the same fundamental problem: device inventory doesn’t stay current.

Devices come online and go offline. Employees add personal machines to work environments. IoT devices are deployed and forgotten. VMs spin up for projects and never get deprovisioned. In each of these scenarios, the gap between “what IT thinks is on the network” and “what’s actually on the network” grows wider – and more dangerous.

When an incident like Stryker’s occurs, that gap becomes a liability. You can’t triage what you can’t see. You can’t quarantine a device you didn’t know existed. And you can’t accurately scope the blast radius of a wipe command if your asset inventory is six months out of date.

How 4Remote Network Edition Addresses This Problem

4Remote’s Network edition is purpose-built for exactly this scenario: distributed environments where complete, current device visibility isn’t optional.

Using 4Remote’s asset aggregation function, security and IT teams get a continuously updated, consolidated view of every device across their network – including remote workers, branch offices, and distributed infrastructure. When a device connects to a monitored network segment, 4Remote discovers it, classifies it, and adds it to the asset inventory in near real-time.

But visibility alone isn’t enough in a crisis. What matters is speed of access to that information.

4Remote’s Network edition includes a fast, filterable device search that allows teams to locate specific devices within a distributed estate quickly and efficiently. Search by device type, OS, network segment, risk score, patch status, or any combination of attributes. In a scenario where a wipe command has been deployed or a compromised credential is being used to move laterally, knowing *exactly* which devices on *which* networks are in scope, within seconds, is the difference between a targeted response and a blind one.

This isn’t about replacing your existing MDM or endpoint management tools. It’s about filling the gap those tools leave: the devices they don’t manage, the segments they can’t see, and the distributed edges where incidents start but go undetected.

What Stryker’s Response Tells Us About Preparedness

Stryker’s response was, by most accounts, competent. They activated incident response plans, engaged external forensic experts, coordinated with CISA and law enforcement, and the CEO communicated publicly within days. AWS and GCP environments were unaffected and workloads on those platforms continued operating.

But 56,000 employees were idled. Global manufacturing was disrupted. The financial impact, while likely manageable for a $25B company, is still being assessed.

The lesson isn’t that Stryker failed. It’s that even a well-resourced, globally operating enterprise can be brought to a halt when an attacker gains privileged access to the device management layer – and that the speed of response depends entirely on how well the organization knows its own device estate before the incident begins.

Key Takeaways

The Stryker attack used legitimate admin tools as weapons – Microsoft Intune was used to wipe devices, not traditional malware. This is a pattern security teams need to plan for.
Distributed device visibility is a prerequisite for effective incident response – you cannot scope, contain, or recover from an attack on devices you didn’t know existed.
Asset aggregation across distributed networks enables faster triage – a consolidated, searchable device inventory isn’t a nice-to-have; it’s an operational requirement in a multi-location environment.
Speed of access matters as much as completeness – being able to search and filter your full device estate by segment, type, or risk attribute in seconds shortens the window between detection and containment.
Unmanaged and remote devices compound the problem – employees’ home networks, IoT devices, and shadow IT assets remain invisible to most security stacks, and they represent an attacker’s preferred staging ground.

See What’s on Your Network – Before an Attacker Does

The Stryker incident is a sharp reminder that distributed device estates require distributed device intelligence. Whether you’re managing a global enterprise or a team of 100 remote workers, the question is the same: can you find any device on your network, right now, in under 60 seconds?

4Remote’s Network edition gives security and IT teams continuous asset discovery, aggregated device intelligence, and fast, filterable search across distributed environments – so when an incident occurs, you’re responding to facts, not guesses.