CISA warns to secure Intune after Stryker hack

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA warned companies on Thursday to secure fleet-device management systems after pro-Iran hackers broke into Stryker and mass-wiped thousands of employee phones, tablets, and computers, causing ongoing global outages.
- CISA's guidance specifically recommends that administrator accounts with access to tools like Microsoft Intune require a second administrator's approval before executing sensitive actions such as wiping devices.
- Stryker confirmed on March 11 that it had been hacked and was experiencing "global disruption"; the company said no malware or ransomware was deployed, but hackers abused Intune dashboard access to remotely delete data on tens of thousands of devices, including employees' personal phones and computers.
- Stryker has contained the cyberattack and is restoring systems, but its supply, ordering, and shipping systems remain offline, and the company has not provided a recovery timeline.
- Handala, a pro-Iran hacktivist group, claimed responsibility for the attack, citing retaliation for a U.S. air strike on a school in Iran, and alleged it stole reams of data from Stryker's network without immediately providing evidence.
- The FBI seized Handala's website on Wednesday, per TechCrunch reporting.
Why it matters: The Stryker breach exposes a critical weakness in how enterprises use Intune: a single compromised admin account can trigger mass device wipes across tens of thousands of endpoints with no second pair of eyes. CISA's call for dual-admin approval on destructive actions directly addresses how the attack played out, meaning any organization managing employee devices via Intune now faces urgent pressure to implement that safeguard.



