The News: A massive cyberattack recently hit medical technology giant Stryker, resulting in the remote wiping of nearly 80,000 devices—including laptops, servers, and even employee mobile phones. The most shocking part? The hackers didn’t use a single piece of malware or a virus. Instead, they compromised an administrator account and used the company’s own “wipe” command within Microsoft Intune (the tool used to manage remote devices) to erase everything between 5:00 and 8:00 AM.
The Expert Take: This is a wake-up call for any business using “Cloud Management” tools. We often think of hackers as people who “install” bad things on our computers, but this incident proves that the greatest risk is often identity. By gaining “Global Admin” privileges, the attackers turned a helpful management tool into a digital weapon.
For our SMB clients, this is a clear example of the NIST CSF 2.0 “Protect” (PR.AC) category—Identity Management and Access Control. If you have “Admin” accounts that aren’t locked down with the highest level of security, you are essentially leaving the “Self-Destruct” button on your front desk for anyone to press.
3 Critical Lessons for Your Business:
- BYOD is a Hidden Risk: Some Stryker employees lost personal photos and data because their personal phones were enrolled in the company network. If you allow “Bring Your Own Device” (BYOD), ensure your policy strictly separates personal and business data.
- MFA is Non-Negotiable for Admins: Most experts believe this started with a compromised admin password. If your IT manager or “Global Admin” isn’t using phishing-resistant MFA (like a security key), your entire company is one password away from being wiped.
- Test Your Backups: When 80,000 devices go blank, “cloud syncing” isn’t enough. You need a disaster recovery plan that assumes your primary management system might be the thing that fails you.
Original reporting via: BleepingComputer
