CISA, FBI have engaged with Stryker staff after cyberattack, official says

<p>The Cybersecurity and Infrastructure Security Agency and the FBI have engaged with executives at Stryker as they work to assess and mitigate the fallout from a major hack of the medical technology giant last week that an Iran-aligned group took credit for, a top official said.</p>

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

<p>&ldquo;We&rsquo;ve engaged with them. Our teams have worked with them, as well as some of the FBI teams, and our regional personnel have been engaged with them,&rdquo; Nick Andersen, CISA&rsquo;s acting director, told reporters after he spoke at a McCrary Institute event on Tuesday. He didn&rsquo;t provide other updates.</p>

<p>The worldwide cyberattack wiped employees&rsquo; phones and prevented workers from accessing their computers and other remote work tools. The logo of Handala, a pro-Iran and pro-Palestinian hacking group, appeared on employee login pages, and the hacking collective&rsquo;s X account also claimed responsibility.</p>

<p>Andersen added that CISA is engaging further with sector-based industry groups on foreign cyber threats. On Iran, &ldquo;we still are seeing a steady state. [The groups have] not seen an increase in the rise of threat actor activity, which is fantastic,&rdquo; he said.</p>

<p>But he cautioned that &ldquo;we just can&rsquo;t take our eyes off of the fact that other adversaries continue to make maneuvers in this space. Cybercriminal groups continue to make moves within this space. It&rsquo;s not just about one nation-state at one particular point in time.&rdquo;</p>

<p>Stryker, one of the largest medical tech providers in the world, said last week it believed the incident was contained but the effects of the hack may continue causing &ldquo;disruptions and limitations of access&rdquo; to certain company information systems and applications supporting parts of their operations and functions.</p>

<p>Pro-Iran hacking groups frequently target the computer systems of nations considered adversaries to Tehran, namely the U.S. and Israel. In late 2023, during the Israel-Hamas war, another Iran-aligned hacking group defaced the interfaces of Pennsylvania water treatment systems that contained Israel-made Unitronics equipment.</p>

<p>Stryker acquired the Israeli medical technology firm OrthoSpace in 2019. It also has significant contracts with both the U.S. departments of Defense and Veterans Affairs.</p>

<p>It&rsquo;s widely believed that a <a href=“Stryker attack wiped tens of thousands of devices, no malware needed”>wiper attack</a> was used against Stryker&rsquo;s devices after the Handala group compromised a company Microsoft Intune administrative account. Intune is used to manage users&rsquo; access to company resources across their devices, and it can be used to remotely access specific computers or factory reset machines.</p>

<p>&ldquo;The real failure here is that our core systems still rely on &lsquo;God-like&rsquo; administrative keys that lack deep cryptographic validation,&rdquo; said Denis Mandich, a former CIA official and co-founder of Qrypt. &ldquo;We are essentially giving attackers a single point of failure that allows one compromised credential to execute a global factory reset.&rdquo;</p>

<p>&ldquo;All Stryker products across our global portfolio, including connected, digital, and life-saving technologies, remain safe to use,&rdquo; the company said in a <a href=“Customer Updates: Stryker Network Disruption | Stryker”>Sunday statement</a>, but it added that there may be supply chain disruptions as ordering systems come back online. The company also said the incident &ldquo;was not a ransomware attack, and there is no evidence of malware deployed to our systems.&rdquo;</p>

Article Link: CISA, FBI have engaged with Stryker staff after cyberattack, official says - Nextgov/FCW