Handala claimed 200,000+ Stryker devices wiped across 79 countries
Assessment
The figure of "more than 200,000 systems, servers and mobile devices" erased across offices in 79 countries comes directly from a manifesto Handala Hack itself posted to Telegram, as reported by KrebsOnSecurity. It is an attacker's self-reported claim of the scale of its own attack, not a number independently confirmed by Stryker, by an incident-response firm, or by a government agency. Krebs' reporting corroborates real operational disruption (a Stryker facility in Cork, Ireland sending home over 5,000 workers; a "building emergency" voicemail at US headquarters; employees told to uninstall Intune), but the specific 200,000-device and 79-country figures remain attacker-supplied and should be treated as a claimed upper bound, not a confirmed total. The American Hospital Association stated it had no confirmed reports of US hospital disruption at the time of initial reporting.
Where this claim appeared
KrebsOnSecurity · 2026-03-11
https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/What “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Handala Hack's HEAVYGRAM Backdoor (CHOSEN BRICK) Spies on Iranian Dissidents via Telegram C2Think this assessment is wrong? Report an error.