The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned companies to secure the systems that manage their employees' devices after pro-Iranian hackers infiltrated the medical technology giant Stryker and wiped thousands of its phones, tablets and computers.
The agency announced Thursday that it is urging companies to take action and acknowledged that it is aware that hackers have used access to Stryker's Windows-based network to exploit the company's device endpoint systems, causing ongoing outages to the company's global operations.
In its advice, CISA said network administrators should ensure that certain user accounts with access to systems such as Microsoft Intune, which Stryker uses to remotely manage employee devices, can only make sensitive or high-impact changes (such as wiping a device) with the approval of a second administrator.
Stryker, which develops medical devices and equipment for hospitals, acknowledged on March 11 that its network had been hacked, saying it was experiencing a “global disruption.”
Although the company said the hackers did not deploy any malware or ransomware, the report said the hackers used their access to Stryker's internal systems to gain access to the Intune dashboard and remotely delete data stored on tens of thousands of employee devices connected to Stryker's network, including personal phones and computers.
Stryker later announced that it had contained the cyberattack and was restoring its systems. Stryker said the company's medical equipment remains operational, but its supply, ordering and shipping systems remain offline.
The striker has not disclosed a timeline for his recovery. The company did not respond to TechCrunch's request for comment.
A pro-Iranian hacktivist group known as Handara blamed last week's cyberattack on Stryker, claiming it was hacked in retaliation for U.S. airstrikes on Iranian schools that killed dozens of children. The hackers claimed to have stolen large amounts of data from the company's network, but did not immediately provide proof of that.
The FBI seized the Handala group's website on Wednesday, TechCrunch reported.

