8-KRegulation FDExhibits & Filings

STRYKER CORP 8-K Report, Regulation FD Disclosure (Mar 23, 2026)

Filed March 23, 2026For Securities:SYK

Summary

Stryker Corporation (SYK) has filed a Form 8-K on March 23, 2026, providing an update on a previously disclosed cybersecurity incident. The company, with the assistance of third-party experts including Palo Alto Networks' Unit 42 and law enforcement, has been working to contain and mitigate the impact of the incident and restore operations. Initial findings suggest the threat actor used a malicious file to execute commands and hide activity, but this file was not capable of spreading. As of the report date, Stryker has not identified malicious activity directed at its customers, suppliers, vendors, or partners, and a General Assurance Letter (Exhibit 99.1) from its advisors reaffirms the belief that the incident is contained and no evidence of threat actor access to external systems has been found. However, the incident did cause disruptions to Stryker's corporate network environment, specifically including its Microsoft environment. The full scope, nature, and potential operational and financial impact of the incident are still under ongoing assessment, and the company has not yet determined if it will have a material impact.

Key Highlights

  • 1Stryker Corporation (SYK) provided an update on a cybersecurity incident first disclosed on March 11 and 12, 2026.
  • 2The company has engaged third-party cybersecurity experts, including Palo Alto Networks' Unit 42, and law enforcement to investigate.
  • 3Investigation indicates a malicious file was used for command execution and activity concealment, but this file was not capable of spreading.
  • 4No malicious activity directed at customers, suppliers, vendors, or partners has been identified to date.
  • 5A General Assurance Letter (Exhibit 99.1) supports the company's belief that the incident is contained and external systems were not compromised.
  • 6Disruptions occurred within Stryker's corporate network, including its Microsoft environment.
  • 7The full financial and operational impact is still under assessment, and materiality has not yet been determined.

Frequently Asked Questions

The company's investigation, supported by third-party experts, indicates the incident is contained, and they have not identified evidence of the threat actor accessing customer, supplier, vendor, or partner systems as a result of this incident.

The filing states that the threat actor used a malicious file to run commands and hide activity within Stryker's systems, but this file was not capable of spreading. As of the filing date, no malicious activity directed at external parties or their systems has been found. However, the full scope of data impact is still under investigation.

Stryker is still assessing the full scope, nature, and potential operational and financial impact of the incident. The company has not yet determined whether the incident is reasonably likely to have a material impact.

The incident caused disruption to Stryker's corporate network environment, which specifically included its Microsoft environment. The investigation into the full extent of the disruption is ongoing.