US-Israel Attack on Iran Escalates Geo-Poli-Cyber™ Warfare on US & West – Medical Technology Firm Devastaed Not by a Ransomeware Demand but a GPCyber™ Attack with Destruction Motivation. | Survivability News Report & Exclusive Analysis.

  • Home
  • Geo Poli Cyper
  • US-Israel Attack on Iran Escalates Geo-Poli-Cyber™ Warfare on US & West – Medical Technology Firm Devastaed Not by a Ransomeware Demand but a GPCyber™ Attack with Destruction Motivation. | Survivability News Report & Exclusive Analysis.

In a bold and highly coordinated cyber-attack, American medical technology giant Stryker was cyber attacked causing widespread devastation. The attack caused major disruption to its operations internationally and potentially compromised sensitive data.

Is it Really Just a Cyber-Attack as “Experts” Claim?

Stryker has confirmed that it is dealing with a “global network disruption” across its Microsoft environment, which is believed to be the entry point for the hackers. Responsibility for the attach was allegedly claimed by the Iranian-linked threat group Handala. The hackers claimed to have wiped out over 200,000 systems, servers, and Mobile devices across Stryker’s global operations, as well as stolen 50 terabytes of critical data.

Not a Cyber Attack but a Geo-Poli-Cyber™ (GPCyber™) Attack

Speaking about this attack, MLi Group chairman, and candidate for California Governor Khaled Fattal whose pledges include turning California from 4th to 3rd economy in the world to serve the People First, and to make California the best cyber-defended State in the Union and the world, said:

“For reporters, so called experts, and media outlets to describe the attack as a “step change in politically-motivated attacks focusing on destruction rather than extortion” is insulting to the intelligence of the public. I and the MLi Group have been talking about political, geopolitical and non-financial motivated cyber-attacks for about two decades. Fundamentally, if you can’t name the threat, you can’t mitigate the threat.”

Historical Facts

Khaled Fattal created the labels Geo-Poli-Cyber™ and GPCyber™ in 2012 and gave them clear definitions to distinguish them from financially motivated cyber-attacks in damage consequence and effective mitigation strategies and solutions.

Fattal literally wrote the ‘bible’ on political and geopolitical cyber-attack motivations.

His two-time international best-seller Survivability is today in its 3rd edition. Survivability’s Foreword was written by non-other than the father of Supply-Side Economics Dr. Arther Laffer.

 

Incompetent Misguided Expertise & Law Enforcement Advice on Geopolitics & Cyber Attack Motivation

In public reports, Stryker noted in its statement that there is “no indication of ransomware” involved in the attack. However, this aspect of the attack provides an insight into the underlying motivations, according to Huntress CISO Chris Henderson. “In this instance, the attack is ‘destructive, not ransomware’ and is a politically-motivated attack aimed solely at causing widespread disruption,” Henderson said.

Relevant Reading

 

“The target matters. Stryker manufactures critical medical devices used in operating rooms and ICUs worldwide,” Henderson said. “When a supplier of this scale goes offline, it doesn’t just impact their employees; it creates ripple effects across hospitals, surgical centers, and healthcare providers who depend on their equipment and support infrastructure.” Skip Sorrells, Field CTO-CISO at Claroty, echoed Henderson’s comments, noting that even prior to the Iran conflict hacktivist activities have been ramping up globally.

Relevant Reading:

 

 

 

Skip Sorrells, Field CTO-CISO at Claroty, echoed Henderson’s comments, noting that even prior to the Iran conflict hacktivist activities have been ramping up globally.

Security agencies including CISA and the UK’s National Cyber Security Centre (NCSC) have issued repeated warnings over the rise of hacktivist groups over the last two years.

In-Depth & Detailed Analysis

Fattal explained further: “This attack could have been prevented. So I will repeat again for the deaf to hear and listen what I wrote in my book – if you can’t name the threat, you can’t mitigate the threat.”

He further emphasized, “This event is a clear case of a Geo-Poli-Cyber™ (GPCyber™) attack not just a cyber-attack. It also showcases why Stryker’s ‘best-Practices’, the cyber security strategy it was advised on and which it followed as gospel, and its best-in-class cyber security solutions used, could not defend or mitigate this  attack.”

 

Fattal then concluded: “Security agencies such CISA and the UK’s National Cyber Security Centre (NCSC) are part of the problem. They warn of escalations but continue failing to offer specific guidance on how to defend and mitigate against such risks, threats and attacks other then recommending stakeholders become more vigilant, tighten up their cyber best practices, or allocating bigger budgets to buy more ransomware solutions.”

Further Escalation in Geo-Poli-Cyber™ Warfare on US & West Expected 

Escalation in Geo-Poli-Cyber™ Warfare on US & West should be not only expected planned for as a result of the US-Israel Attack on Iran. Fattal added. “This is a grave development. Regardless of whether Handala was involved, or not. this situation is similar to the rise in the huge rise Geo-Poli-Cyber™ (GPCyber™) attacks since the Russia-Ukraine war between the two nations and between their allies globally.”

 

Relevant Reading:

 

 

About Stryker & the Attack

Stryker is a leading developer of surgical equipment, neurotechnology, and orthopedic implants, has offices in 79 countries and employs over 50,000 people worldwide. The attack has had a significant impact on the company’s operations, with reports suggesting that offices in Ireland have been severely disrupted.

The company’s Cork facility, which is its largest innovation and manufacturing hub outside the US, has been particularly affected. A source close to the company told the Irish Mirror that “nobody can

work” and that the entire company has been brought to a standstill.

Targeting of Microsoft products is a common tactic for Handala, which has been active since at least December 2023. A 2024 threat intelligence report from Cisco Talos and Splunk’s Threat Research Team specifically highlighted the group’s activities on this front, typically using “wiper” malware to destroy company data.

“The Handala Hacking Team is notable for employing a wide range of sophisticated tactics and techniques, including data theft, phishing extortion, website defacement, and destructive attacks leveraging custom wiper malware that targets Windows and Linux environments,” the duo said in a blog post.

Stryker noted in its statement that there is “no indication of ransomware” involved in the attack. However, this aspect of the attack provides an insight into the underlying motivations, according to Huntress CISO Chris Henderson.

 

“Attacks like this unfortunately aren’t surprising,” Sorrells said. “Even before the latest geopolitical tensions, hacktivist activity targeting healthcare and other critical infrastructure had been steadily increasing, and that trend makes organizations like medical device manufacturers and hospitals more likely to be caught in the crossfire.”

Escalation in Geo-Poli-Cyber™ Warfare on US & West Expected US-Israel Attack on Iran

Escalation in Geo-Poli-Cyber™ Warfare on US & West should be not only expected planned for as a result of the US-Israel Attack on Iran. Fattal added. “This is a grave development. Regardless of whether Handala was involved, or not. this situation is similar to the rise in the huge rise Geo-Poli-Cyber™ (GPCyber™) attacks since the Russia-Ukraine war between the two nations and between their allies globally.”

Relevant Reading:

MLi Survivability MasterClass™ Series in Capitals & Cities Near you with 100% Money Back Guarantee. | Identify, Address & Effectively Mitigate your Unmitigated Risks. Find out more!

Previous Post
Newer Post

Leave A Comment

2026
What Are
Geo-Poli-
Cyber™ Risks?

What Is Geo-Poli-Cyber™?

MLi Group created the terms Poli-Cyber™ and Geo-Poli-Cyber™ (GPC™) in 2012 and 2013 based on the philosophy that if you cannot identify and name the threat, you cannot mitigate that threat.

Geo-Poli-Cyber™ attacks are political, ideological, terrorist, extremist, ‘religious’, and/or geo-politically motivated.

More Sinister Than Financial Motivations

Geo-Poli-Cyber™ attacks are significantly different from financially motivated cyber-attacks in damage, scale, magnitude as well as in risk mitigation strategies and solutions.

Click to read more