Secure your Microsoft system or suffer the same fate as Stryker – US tells companies to secure corporate accounts
- CISA warns US firms after Stryker Intune wipe
- Urges stronger endpoint management configs, least privilege, MFA, multi-admin approvals
- FBI and Microsoft coordinating to counter Handala-linked Iranian hacktivists
The US Cybersecurity and Infrastructure Security Agency (CISA) is urging businesses in the country to harden their endpoint management system configurations and avoid suffering the same fate as Stryker.
If you haven’t been paying attention, an Iranian hacking collective called Handala broke into Stryker, (allegedly) stole 50 terabytes of data, and then used a compromised Microsoft Intune admin account to wipe almost 80,000 company devices in just a few hours.
The company was literally forced to operate on pen and paper due to the severity of the disruption.
Article continues below
Defending against Handala
Earlier this week, CISA issued a new alert, saying it is “aware of malicious cyber activity targeting endpoint management systems of US organizations based on the cyberattack against Stryker”. It urged businesses to bolster their defenses using Microsoft’s recommendations, and stressed it was coordinating with the FBI to identify additional threats.
Microsoft’s recommendations include:
- Using principles of least privileges for admin roles
- Using Intune’s role-based access control to assign minimum permissions necessary
- Enforcing phishing-resistant multi-factor authentication
- Using Microsoft Entra ID to block unauthorized access
- Configuring access policies to require Multi Admin Approval in Microsoft INtune
- Setting up policies that require a second admin account’s approval for sensitive and high-impact changes
“The principles of these recommendations can be applied to Intune and more broadly to other endpoint management software,” CISA added.
Although it is not confirmed, many security researchers believe the attack on Stryker is the result of US and Israeli aggression against Iran. Handala claimed that in its operation “over 200,000 systems, servers, and mobile devices have been wiped, and 50 terabytes of critical data have been extracted.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The group is being described as “hacktivists linked to Iran’s Ministry of Intelligence and Security”, targeting mostly Israeli organizations around the world.
Via Bloomberg

The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
CISA warns US firms after Stryker Intune wipe Urges stronger endpoint management configs, least privilege, MFA, multi-admin approvals FBI and Microsoft coordinating to counter Handala-linked Iranian hacktivists The US Cybersecurity and Infrastructure Security Agency (CISA) is urging businesses in the country to harden their endpoint management system configurations and avoid…
Recent Posts
- ICYMI: here’s the week’s 7 biggest tech news stories from WWDC 2026 to Trump’s not-so-made-in-America phone
- Rivian’s CEO on Tesla’s Cybertruck, Ferrari’s Luce, and What Happens If the R2 Fails
- OpenAI is facing investigation from a group of state attorneys general
- Here’s How AI Agents Can Protect EV Chargers
- Anthropic blocks all customers’ access to Fable 5 and Mythos 5
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023