Kevin Surace
2 minute read
What happened at Stryker today isn't a malware story. It's an identity story. And it's one the industry has seen before — the Sony hack, twelve years ago, followed a similar path. A dozen years later, the attack surface has changed. The fundamental failure hasn't.
Here's what the reporting tells us: Stryker's Microsoft environment was compromised at scale. No ransomware. No novel exploit. Handala claims 200,000 devices wiped, 50TB of data exfiltrated — and multiple sources point to Microsoft Intune as the likely mechanism. That matters, because Intune is a legitimate management platform. It's designed to remotely wipe enrolled devices across Windows, macOS, iOS, Android, and ChromeOS. In the wrong hands, your trusted control plane becomes the weapon. (BleepingComputer)
To use Intune this way, you need one thing: a privileged Microsoft identity. An Entra global admin. An Intune administrator. An account with equivalent authority.
How do you get it? The same ways that have always worked: phishing, session theft, AiTM attacks against legacy MFA, help desk social engineering, stolen admin credentials. Once you own the identity plane, you don't hack 200,000 assets one by one. You issue legitimate remote commands — and the infrastructure does the rest. (Krebs on Security)
This is also why Stryker reported no indication of ransomware or malware. When an attacker controls native administrative functions — wiping endpoints, disabling login surfaces, pushing destructive actions through trusted channels — they don't need conventional malware. They are the admin.
The attacker's branding reportedly appeared on login pages. That's not a ransomware signature. That's a flag planted at the identity layer.
Stryker generated over $25 billion in revenue in 2025. Roughly $68.8 million per day. Not all of that evaporates during an outage — but the exposure compounds fast when manufacturing, order flow, hospital support, field sales, and supply chain operations go dark globally. (Q4 Capital)
Realistic damage range: $150 million to $500 million. Potentially higher.
Recovery looks like this: initial containment in days. Partial operations restored in one to three weeks. Most users and devices functional in 30 to 90 days. Full rebuild — forensics, credential reset, re-enrollment, confidence restoration — six to twelve months.
The attacker was in for hours. Stryker pays for it for months.
It's a flaw in identity assurance.
The moment a credential can be stolen, relayed, or social-engineered — the moment a push notification can be fatigued, a session hijacked, a help desk bypassed — the entire control plane is available to anyone who can impersonate the person who holds it.
Token exists precisely here. Biometric-assured, device-bound, cryptographically enforced identity. Nothing to phish. Nothing to relay. No shared secret. No easy bypass. Real presence. Real biometrics. Real proof — tied to the human being, the device, and the session.
If the identity cannot be stolen, the admin cannot be impersonated. That is the difference between cleanup and prevention. Token deals in absolutes.
Attackers are accelerating. AI tooling has lowered the cost of sophisticated campaigns to near zero, while the scale of attacks has expanded across every phase of the attack chain — reconnaissance, initial access, lateral movement. The 2025 Tidal Cyber Threat Led Defense Report confirms what security leaders already understand: defenders no longer hold an inherent speed advantage. This is the Red Queen dynamic. Running harder sustains position. It does not advance it. But there is a more precise problem underneath the noise. Phishing and social engineering have changed structurally. Training-based defenses, however disciplined, are now insufficient by design. The architecture of the threat has shifted. The architecture of the response must follow.
The shift to a passwordless future is well underway. Tech giants like Apple, Google, and Microsoft have embraced passkeys, and for good reason. Passwords have long been the weakest link in cybersecurity—easily guessed, phished, stolen, or reused across accounts. Passkeys represent a serious improvement. They’re phishing-resistant, user-friendly, and eliminate the need to remember or manage credentials.
For decades, breach response centered on a single question: how did the malware get in? That question is no longer the right one. Recent advisories from CISA confirm what security leaders already see in their incident reports. A significant and growing share of breaches involve no malware at all. Attackers authenticate with legitimate credentials. They operate as trusted users. Detection tools built to catch malicious binaries see nothing — because the attacker is not behaving like malware. They are behaving like an employee.
Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.