ACS Blog

 

Iran-Linked Hackers Used Microsoft Intune to Wipe 200,000 Stryker Devices — What SMBs Should Learn

Apr 2, 2026 | Nerds News

A single compromised admin account at medical device giant Stryker gave Iran-linked hackers access to Microsoft Intune, where they remotely wiped over 200,000 devices across 79 countries. No malware. No ransomware. Just a stolen password and a legitimate IT management tool turned into a weapon. Here is why this matters for every business that uses Intune.

What Happened

CISA issued an advisory after Iran-linked threat actors compromised a single Intune admin account at Stryker, a major medical device manufacturer. Using that one account, they triggered a remote wipe command through Microsoft Intune — the same tool IT departments use to manage and secure devices — across Stryker’s global device fleet. Over 200,000 devices were wiped in 79 countries.

The attackers did not need sophisticated malware or zero-day exploits. They used a legitimate administrative tool with legitimate credentials. The damage was not data theft — it was pure destruction of productivity and operational capability at a massive scale.

What This Means for Your Business

If your business uses Microsoft Intune to manage devices, this is your wake-up call. The attack vector was not a software vulnerability — it was a human one. A single admin account without proper protections gave attackers the keys to wipe an entire global device fleet. CISA is now urging all organizations to audit Intune admin privileges and enable multi-factor authentication on every admin account.

Ask yourself: how many people in your organization have Intune admin access? Do all of those accounts have MFA enabled? Would you know immediately if someone triggered a mass device wipe? These are the questions that separate prepared businesses from vulnerable ones.

The Bottom Line

Review who has admin access to your Intune environment today. Enable MFA on every single admin account, no exceptions. Your device management tools are only as secure as the credentials that control them.

This story was covered on the latest episode of Nerds News. Read the full episode recap.

Not sure who has admin access to your environment? Schedule a free IT consultation and we will audit it together.