Back to blog
INTUNE SECURITY 21 Mar 2026

The Intune Stryker Breach — what happened and how to defend against it

How attackers wiped tens of thousands of devices through Microsoft Intune without deploying any malware, and what concrete steps CISA and Microsoft recommend to prevent the same from happening to you.

What happened

On March 11, 2026, Stryker Corporation — one of the world’s largest medical technology companies — was hit by a devastating cyberattack. The Iran-linked hacktivist group Handala claimed responsibility. They allegedly exfiltrated 50 terabytes of corporate data and then used the built-in remote wipe capability of Microsoft Intune to wipe tens of thousands of devices across 79 countries. No malware, no ransomware — just abuse of existing management tooling.

How the attack worked

The attackers followed an attack chain that demonstrates how dangerous a compromised admin account becomes when no additional security layers are in place:

1
Initial account compromise

The attackers gained access to an internal Stryker administrator account. The exact initial attack vector has not been publicly confirmed, but the result was access with elevated privileges.

2
Global Administrator account created

Using the compromised account, they created a new Global Administrator account in Entra ID. This gave them near-unlimited control over the entire Microsoft environment.

3
Data exfiltration

Before striking, the attackers allegedly exfiltrated 50 TB of corporate data — undetected.

4
Mass wipe via Intune

Through the Intune portal, they issued a remote wipe command against all enrolled devices. Laptops, desktops, and even personal phones enrolled through Stryker’s BYOD program were wiped — including photos, eSIMs, and authenticator apps.

The impact

The consequences were massive and extended far beyond the loss of devices:

Tens of thousands of devices wiped

Laptops, desktops, and mobile phones across 79 countries were wiped in one sweep using the legitimate Intune wipe function.

BYOD devices affected

Personal phones of employees were factory-reset too — photos, eSIMs, and authenticator apps were lost along with corporate data.

Supply chain disrupted

Ordering, shipping, and supply chain systems went offline. Operations and deliveries to hospitals were delayed.

50 TB of data stolen

In addition to the wipe, the attackers claimed to have exfiltrated 50 terabytes of corporate data.

Why this was possible

What stands out about this attack is that no malware was involved. The attackers purely abused the built-in functionality of Microsoft Intune. This raises the question: what was missing in the security posture?

  • No Multi-Admin Approval — A single admin was able to execute destructive actions like a mass wipe without requiring approval from a second administrator.
  • Overly broad admin permissions — The compromised account apparently had sufficient privileges to create a Global Admin, indicating insufficient role-based access control.
  • Insufficient monitoring — The creation of a new Global Admin account and the initiation of a mass wipe should have triggered alerts long before the damage was done.
  • BYOD without wipe protection — Personal devices in the BYOD program were hit with a full wipe instead of only corporate data being removed (selective wipe).

How to defend against this

Following this incident, CISA and Microsoft published concrete hardening guidelines. These are the measures you can implement today:

1 Enable Multi-Admin Approval

Configure access policies in Intune that require a second administrator to approve destructive actions. This means a remote wipe, script deployment, or RBAC role change will only execute after a second admin has signed off.

Intune Admin Center → Tenant administration → Multi-admin approval → Access policies

2 Phishing-resistant MFA for all admin accounts

Enable phishing-resistant MFA (FIDO2 keys, Windows Hello for Business, or certificate-based authentication) for all accounts with administrative privileges. Standard MFA via SMS or push notifications is not sufficient — these methods are vulnerable to MFA fatigue and adversary-in-the-middle attacks.

Entra ID → Protection → Conditional Access → Require authentication strength: Phishing-resistant MFA

3 Apply least privilege and RBAC

Use Intune’s built-in Role-Based Access Control to grant administrators only the minimum permissions they need. Nobody needs standing Global Admin rights for day-to-day management. Use Privileged Identity Management (PIM) for just-in-time activation of elevated roles with time limits and approval workflows.

4 Monitor and alert on admin actions

Set up alerts for the creation of new admin accounts, bulk device actions, and changes to Conditional Access policies. Use Microsoft Sentinel or Defender for Cloud Apps to automatically detect and block suspicious patterns such as a mass wipe outside business hours.

5 Rethink your BYOD policy

For BYOD devices, use App Protection Policies instead of full device enrollment. This way, in the event of an incident, you can remove only corporate data (selective wipe) without touching personal data. Employees will not lose their photos, eSIMs, or personal authenticator apps.

6 Conditional Access for privileged actions

Restrict access to the Intune Admin Center and destructive Graph API calls to compliant, managed devices from known locations. Combine this with sign-in risk policies so that suspicious login attempts are automatically blocked or require additional verification.

Conclusion

The Stryker breach demonstrates that your most powerful management tool can also be your largest attack surface. Microsoft Intune is designed to manage devices at scale — and that is exactly what the attackers did, only with destructive intent. The lesson is clear: treat your management plane as a tier-zero asset. Multi-Admin Approval, phishing-resistant MFA, least privilege, and proactive monitoring are no longer nice-to-haves. They are the minimum baseline.

Relevant technologies

Microsoft Intune Entra ID Conditional Access PIM RBAC FIDO2