Stryker’s Cybersecurity Lawsuit and Q1 Earnings Fallout

Employees have filed at least six proposed class actions in the Stryker cyberattack lawsuit wave that followed the March 11, 2026, breach of the medical device maker’s Microsoft environment, alleging the Portage, Michigan company failed to protect personal data that hackers claim to have stolen. A separate law firm investigation is also examining whether Stryker’s board breached its fiduciary duties in overseeing the company’s cybersecurity practices.

The Employee Class Actions

By late April 2026, at least six employee lawsuits had been filed against Stryker Corporation over the incident. Two frame the litigation.

Mesmer v. Stryker Corporation (1:26-cv-832), filed March 13, 2026, is a proposed class action alleging negligence. The complaint says Stryker failed to implement “reasonable and appropriate” cybersecurity measures and did not comply with basic information security standards or Federal Trade Commission guidelines. It identifies the attackers as a group called Handala and alleges that 50 terabytes of data were extracted, including names, dates of birth, Social Security numbers, employment information, and private health information.1ClassAction.org. Data Breach Lawsuit Alleges Stryker Failed to Protect Private Info From March 2026 Cyberattack

Fredrickson v. Stryker Corporation (1:26-cv-00878) was filed on March 17, 2026, in the U.S. District Court for the Western District of Michigan by plaintiff Joseph Fredrickson, with a jury demand.2Law360. Fredrickson v. Stryker Corporation3PACER Monitor. Fredrickson v. Stryker Corporation Filing At least one of the plaintiffs in the broader wave is a current Stryker employee.4WWMT. Stryker Cyberattack Lawsuits: Several Allege Failure to Protect Sensitive Data

Legal teams were still evaluating whether class certification is warranted, and Stryker declined to comment on the pending litigation.4WWMT. Stryker Cyberattack Lawsuits: Several Allege Failure to Protect Sensitive Data

The Board Investigation

On April 22, 2026, Berger Montague PC announced it was investigating Stryker’s board of directors for potential breaches of fiduciary duty tied to the board’s oversight of cybersecurity and data protection practices.5Newsfile Corp. Berger Montague PC Investigates Stryker Corporation’s Board of Directors for Breach of Fiduciary Duty No shareholder derivative or securities fraud lawsuit had been filed as of the available reporting.

What the Plaintiffs Say Was Stolen

The plaintiffs’ data-theft allegations rest on claims made by the attackers themselves. Handala said it had exfiltrated 50 terabytes of data from Stryker’s systems, and the Mesmer complaint tracks that figure and describes the categories of personal and health information allegedly taken.1ClassAction.org. Data Breach Lawsuit Alleges Stryker Failed to Protect Private Info From March 2026 Cyberattack

What Stryker’s Investigation Found

Stryker’s account is different. Working with Palo Alto Networks’ Unit 42 and other forensic experts, the company said it found no evidence that customer, supplier, vendor, or partner systems were accessed, and no evidence that the threat actor directed malicious activity outside Stryker’s internal Microsoft environment.6Stryker. A Message to Our Customers NHS England reported that Stryker had been “unable to confirm if any data was stolen,” while noting that the affected servers appeared to be internal infrastructure rather than product-facing systems.7NHS England. Stryker Medical Cyber Attack Disruption Supply Medical Equipment Consumables

The gap between the attackers’ 50-terabyte claim and the investigation’s findings has not been resolved publicly. The plaintiffs will need to prove exfiltration and compromise of their personal information; Stryker has consistently said its investigation has not identified evidence supporting that conclusion.

How the Attack Happened

The negligence claims turn on how Stryker was breached. The attackers did not use ransomware or exploit a software flaw. They compromised a Windows domain administrator account, created a new Global Administrator account, and used those credentials to reach Microsoft Intune, the legitimate cloud-based endpoint management platform Stryker used to manage its device fleet.8Paubox. Stryker Says Cyberattack Impacted Q1 Earnings, Brought Lawsuits From inside Intune, they issued remote wipe commands against roughly 80,000 devices across 79 countries.9Push Security. Stryker Handala Report

Corporate laptops were wiped clean. Personal devices enrolled in Stryker’s bring-your-own-device program were factory reset, destroying photos, banking apps, and authenticator tokens. Login pages were defaced with the Handala logo.9Push Security. Stryker Handala Report Paddy Harrington of Forrester said the attack required the acquisition of high-level administrative privileges and was not an inherent vulnerability in Intune itself. Microsoft declined to comment on the incident.10Cybersecurity Dive. Stryker Attack Device Management Microsoft Iran

Handala, which cybersecurity researchers link to Iran’s Ministry of Intelligence and Security, said the attack was retaliation for a February 28 missile strike on an Iranian school that killed at least 175 people, and referred to Stryker as a “Zionist-rooted corporation,” apparently referencing the company’s 2019 acquisition of Israeli firm OrthoSpace.11Krebs on Security. Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

Operational and Financial Damage

The wipe shut down Stryker’s commercial ordering and distribution systems. The company could not process orders, manufacture on schedule, or ship products. CommonSpirit Health confirmed that a “small number of surgical cases were rescheduled” because Stryker could not deliver the necessary components, and Mass General Brigham and Providence restricted their connectivity to Stryker’s systems as a precaution.12Becker’s Hospital Review. Stryker Cyberattack Delays Surgeries, Feds Urge Tighter Cybersecurity13U.S. Securities and Exchange Commission. Stryker Corporation Form 8-K/A14Motley Fool. Stryker SYK Q1 2026 Earnings Transcript

The financial hit landed with the first-quarter results on April 30. Net sales came in at $6.02 billion, up 2.6% from the prior year but more than $300 million below the $6.33 billion analysts had expected. Adjusted earnings per share were $2.60, down 8.5% year over year and 38 cents below the $2.98 consensus.15MassDevice. Stryker Results Miss After Q1 Cyberattack Adjusted gross margin fell to 63.6%, down 190 basis points, and adjusted operating margin dropped to 21.1%, down 180 basis points.14Motley Fool. Stryker SYK Q1 2026 Earnings Transcript

CFO Preston Wells attributed the earnings decline to “limited sales growth and lost manufacturing absorption related to the cyber incident, as well as tariffs and increased interest expense.”14Motley Fool. Stryker SYK Q1 2026 Earnings Transcript15MassDevice. Stryker Results Miss After Q1 Cyberattack16Yahoo Finance. Stryker Shares Fall 2.5%

The SEC Materiality Timeline

Stryker’s disclosures moved in stages, a sequence that is likely to matter to any shareholder claim. The initial Form 8-K on March 11, 2026, reported a “global disruption to the Company’s Microsoft environment” but said the company had “not yet determined whether the incident is reasonably likely to have a material impact.”17U.S. Securities and Exchange Commission. Stryker Corporation Form 8-K A follow-up filing on March 23 added investigation details but again deferred the materiality question.18U.S. Securities and Exchange Commission. Stryker Corporation Form 8-K

On April 9, 2026, Stryker filed an amended Form 8-K/A declaring that the cyberattack “had a material impact on its operations, with resulting impact to the Company’s financial results for the first quarter of 2026,” citing “the scope and duration of the operational disruption, the systems affected and the potential for customer, regulatory and other impacts.” The company also said it did not expect the incident to materially affect full-year guidance.13U.S. Securities and Exchange Commission. Stryker Corporation Form 8-K/A Those filings were made under the SEC’s cybersecurity disclosure rules adopted in July 2023, which require public companies to disclose material cybersecurity incidents on a current basis.19U.S. Securities and Exchange Commission. Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure