
On the morning of March 11, 2026, employees at Stryker Corporation showed up to work and found they couldn’t access their work or, in some cases, personal files. Phones were wiped. Laptops were wiped. Everything connected to the company’s corporate network seemed to be gone. An Iran-linked hacktivist group called Handala had quietly gained access to Stryker’s systems and, in a matter of hours, erased data from tens of thousands of devices across 79 countries.
For those of us in West Michigan, this one hits close to home. Stryker is based in Portage, just a short drive from our offices in Holland.
Stryker has been transparent about the incident, publishing ongoing updates directly on their website as recovery progressed. Their own statement confirmed the attack disrupted order processing, manufacturing, and shipping across their global network; and that getting fully operational again was an around-the-clock effort involving third-party cybersecurity experts and several government agencies including the FBI, CISA,DHA, and HHS.
How Did It Happen?
Here’s where this story becomes a cautionary tale for every business, regardless of size.
The attackers didn’t deploy sophisticated malware. They didn’t find some exotic, hard-to-patch vulnerability. According to cybersecurity researchers and reporting from multiple outlets, Handala gained access to a Global Administrator account within Stryker’s Microsoft environment. A Global Administrator has essentially unlimited control; the ability to manage users, change policies, and issue commands to every connected device in the organization. Once they had that, they used Microsoft Intune, a legitimate device management tool that IT teams use to enforce security policies, to push a remote wipe command to every enrolled device simultaneously.
One of the most striking details reported: the global admin password was tied directly to an email address, meaning it was discoverable and targetable. There was no separation between the administrative account and a standard user credential. That single point of failure unlocked the entire kingdom.
Tens of Thousands of Devices. One Password.
Let that sink in for a moment. An organization with $22 billion in annual revenue, 53,000 employees, and operations in dozens of countries was brought to its knees, not because of a highly sophisticated nation-state cyberweapon, but because of credential management practices that any managed IT services provider would flag on day one.
Employees couldn’t log in. Manufacturing halted. Order processing went offline. In Maryland, paramedics lost access to a Stryker platform they rely on to transmit cardiac data to hospitals ahead of patient arrival. Surgeries were rescheduled. A voicemail at Stryker’s Michigan headquarters told callers the company was “experiencing a building emergency.”
It took weeks to fully recover.
What This Means for Your Business
You’re not Stryker. Your business probably isn’t being targeted by Iran’s Ministry of Intelligence. But the lesson here isn’t really about geopolitics; it’s about the basics.
The same vulnerabilities that made Stryker susceptible exist in small and mid-sized organizations every single day. Privileged accounts with weak or exposed credentials. No separation between admin-level access and standard email. No multi-factor authentication on critical systems. No secondary approval required before high-impact actions (e.g. wiping every device in the company).
Effective managed IT services address all of these systematically:
- Privileged access management like admin accounts that are separate from standard user accounts, disabled when not in use, and never tied to an email address that could be phished or compromised.
- Multi-factor authentication on all accounts, especially administrative ones.
- Endpoint management policies that require a second approver for destructive or high-impact actions.
- Continuous monitoring to catch unusual authentication activity before it becomes a catastrophe.
- Credential hygiene including regular audits to identify exposed or compromised passwords before attackers find them first.
Prevention Over Recovery
Stryker did recover. They confirmed full operational restoration across their global manufacturing network, with production ramping back to peak capacity. But it took weeks of around-the-clock work, involvement from the FBI and CISA, and the resources of a Fortune 300 company to get there. Most small and mid-sized businesses in West Michigan do not have that luxury. A breach of this nature could be existential.
The good news is that the vulnerabilities that made this attack possible are entirely preventable. If you’re not sure whether your organization’s admin accounts, access policies, and endpoint management are properly configured, that’s exactly the conversation we’re here to have. Contact Shoreline Technology Solutions for a free network assessment, before someone else finds the gaps first.

President / Network Architect
Mark Kolean always had a fascination with technology from the time he was 3 and his gift of the Atari 2600 to current. In 1990 at the age of 14 Mark got his first job in customer support for a mail order business supporting Tandy TSR-80 computer software shipped on cassette tape. A few years later Mark was building hundreds of 286, 386, and 486 computers for the new emerging DOS & Windows 3.1 computers that had exploded on the market.
After a college career studying business and technology Mark Started Shoreline Computer Systems in 1999 at the height of the dot.com boom with the looming crisis of the year2k bug just around the corner. In the early 2000’s a lot of work was done with early network systems including Lantastic, Novell, and Windows NT Server. Mark became a community contributor to the Small Business Specialist community that revolved around Small Business Server 2000-2011 which focused on single or dual server environments for businesses up to 50 in size. Networks during this time frame mostly had a break fix relationship in which work was billed only when a problem occurred.
In the 2010’s Microsoft released their first cloud based software called Microsoft BPOS which would in later become known as Microsoft Office 365. This introduced a new model in technology with pay as you go subscription services. Starting in 2013 Mark’s team at Shoreline Computer System rebranded as Shoreline Technology Solutions to focus on the transition to become proactive and less reactive to data backup and security needs. Starting in 2018 all customers are required to have a backup management plan in place as a center point with the full understanding that if STS isn’t watching the customer’s data, then no one is.
Now in Mark’s 22 years of business he is building a company emphasis of how to help customers retire servers and build networks completely in the cloud.

