An editorial reading by Jaded Security of the Stryker disclosures from March 2026. The point is not the attack. The attack was, by the company’s own account, almost embarrassingly simple. The point is the language the company reached for afterwards, and what that language is engineered to keep you from looking at.
On 11 March 2026, shortly after midnight Eastern, employees at Stryker around the world watched their corporate machines reboot themselves to factory settings. Roughly two hundred thousand devices across some seventy-nine countries, wiped. The login screens that came back up carried a cartoon of a barefoot boy with a slingshot, which anyone who has paid attention to the region’s hacktivism for the last decade will recognise as the calling card of Handala, an Iran-linked crew that does politics with a delete key. Personal phones enrolled in the company’s bring-your-own-device programme got the same treatment. Photos, eSIMs, the authenticator apps people used for their own banking, all gone. That detail did not make it into the reassuring parts of the post-mortem, and we will come back to why.
The company’s message to customers and its filings with the SEC are, on their own terms, models of crisis communication. They are calm. They are precise. And they are built almost entirely out of statements about things that did not happen.
The grammar of “no evidence”
Read the public language closely. “This was not a ransomware attack, and there is no evidence of malware deployed to our systems.” “At no point has our investigation identified malicious activity directed towards our customers, suppliers, vendors or partners.” “We believe the incident is contained.” “All Stryker products across our global portfolio remain safe to use.”
Every one of those is a negative. Not ransomware. No malware. No activity directed at partners. The sentences are constructed so that the load-bearing word is always something the company did not find. That is not an accident of style. It is the entire move. A statement that the investigation has “not identified” customer data being touched is not a statement that customer data was not touched. It is a statement about the current contents of a forensic report, which is a different thing, and the people who draft these sentences know it is a different thing. Absence of evidence gets dressed up in the suit that evidence of absence usually wears, and most readers do not check the tailoring.
What the negatives are doing, functionally, is steering attention away from the one enormous positive fact that nobody disputes: a single compromised administrative account let an outside crew pick up the company’s own device-management console and use it to brick two hundred thousand endpoints in a night. The attackers did not need a zero-day. They did not need bespoke malware. According to the company’s own forensic narrative they inserted a non-malicious file and ran commands through Microsoft Intune, the legitimate tool Stryker uses to manage its own fleet. The industry has a clean phrase for this now, “living off the cloud,” which is a polite way of saying the burglar used the homeowner’s keys and the homeowner’s alarm panel.
The letter attached to the filing
There is a tell in the 23 March disclosure that is worth sitting with. Stryker attached to its SEC filing a letter from an outside incident-response firm, Palo Alto’s Unit 42, stating that the available evidence indicated the activity was contained and the immediate risk mitigated. Read that as theatre and it makes perfect sense. A company telling its shareholders “we are fine” is interested marketing. The same sentence with a brand-name forensics firm’s logo on top of it is positioned as independent verification. It is not independent in any meaningful sense. The firm was hired by the company, scoped by the company, and is reporting on the evidence the engagement was structured to examine. “Currently available evidence indicates” is doing the same defensive work in the consultant’s letter that “no evidence” is doing in the press release. The function of the letter is to let the company outsource the confidence it cannot honestly assert in its own voice.
None of this is fraud. It is all technically accurate. That is exactly the problem the desk keeps coming back to. The disclosure regime rewards companies for saying true things in an order designed to produce a false impression, and the SEC’s cybersecurity rule, two years in, has done almost nothing to change that incentive.
Material to the quarter, immaterial to the year
Then there is the money. Stryker filed three times across two weeks, conceded the attack had a material impact on first-quarter earnings, and in the same breath told investors it did not expect any material impact on full-year guidance. This is the most reliably translated sentence in all of breach communications. It means: it hurt, the hurt is in a box, the box is this quarter, please do not adjust your model. Whether that is true depends entirely on what the fifty terabytes Handala claims to have walked out with actually contains, which is precisely the question the “no evidence directed at customers” construction is built to keep off the table for as long as legally possible. Materiality, as the desk has noted before, is whatever the legal team feels comfortable defending in the quarter they have to defend it.
What the post-mortem does not say
Strip the negatives away and what remains is not a story about a sophisticated adversary. It is a story about a management plane that trusts whoever is holding an admin token, and an admin token that ended up in the wrong hands by a route the company has been notably quiet about. Outside researchers have pointed at infostealer logs as the likely on-ramp, which would mean the credential that detonated a Fortune 500’s global fleet may have been sitting in a commodity stealer dump that sells for less than lunch. We do not know that for certain, and notably, neither the press release nor the filing offers a competing account of how the account was taken. The most consequential fact in the entire incident, how the keys were lost, is the one fact the careful language never reaches.
This is the part the persona of the careful corporate post-mortem cannot perform, because performing it would require the company to say “we got owned through credential hygiene and a management console with too much standing trust,” and no general counsel signs off on that sentence when “no evidence of malware” is available and equally true.
The slingshot is not new
Look, the crew on the other end of this was not doing anything the readers of this site have not watched before. Handala wiped, defaced, posted a manifesto, and claimed a data haul nobody can verify, which is the hacktivism script almost unchanged from the summer this site spent covering the last people who treated humiliation as the payload. The targets have moved up-market and the access vector has moved into the cloud control plane, but the logic is identical: embarrass a large institution, leave a logo, let the institution’s own panicked messaging do half the reputational damage for you. The interesting actor in 2026 is not the slingshot. It is the company’s media department, which is far more practised, and far more polished, than it was when this site was writing about who actually deserves the blame for these things fifteen years ago.
And lest anyone read this as a one-off, West Pharmaceutical Services ran a near-identical play roughly six weeks later: a “material cybersecurity attack,” data exfiltrated, systems encrypted, fully operational again, no expected impact on guidance, and no group ever claiming the hit, which in that grammar usually means the invoice was quietly paid. Same disclosure skeleton, different logo on the login screen. The post-mortem template has not changed since about 2005. Only the vendor name, the settlement count, and now the name of the cloud console that turned the lights off, change from one filing to the next.