Editorial draft v2 · Evidence reader R1 · Evidence cutoff: April 9, 2026
Disclosures covered: Dated March 12, March 23, and April 1 statements in one captured customer page, plus the separately retained issuer-hosted amendment signed April 9. These are selected retrospective accounts, not independent historical captures of each page update.
Stryker's March 2026 cybersecurity incident disrupted order processing, manufacturing, and shipping in its Microsoft environment. Its customer updates documented both restoration and a change in the technical assessment: an early belief of no indication of ransomware or malware was followed by identification of a malicious file that the company said could not spread. The April amendment then recognized material operational impact and resulting first-quarter financial effects, while preserving a different assessment of full-year guidance. Customer updates · April amendment
Disruption and customer impact
The March 12 customer statement said the attack occurred March 11 and caused a global disruption to Stryker's Microsoft environment. The company activated its incident-response plan and investigated with external advisers and cybersecurity experts. Order processing, manufacturing, and shipping were affected. At that stage, Stryker described its investigation into the incident's nature and scope as early and ongoing, and said it was collaborating with law enforcement and government partners. Customer updates
Another passage on the retained customer page said product and device security and safety were unaffected and that Stryker products remained safe to use. It nevertheless acknowledged disruptions for customers using personalized implants: some patient-specific cases scheduled for the week of March 16 had been rescheduled because of shipping delays. Product-safety claims and delivery disruption address different questions and should remain separate. Customer updates
A revised technical account
In the March 23 update, Stryker said it believed the incident was contained and that its teams and outside experts had removed the unauthorized party. It explained that, early in the investigation, it had believed there was no indication of ransomware or malware. Further work with Palo Alto Networks Unit 42 and others identified a malicious file used to run commands and conceal activity. Stryker said the file could not spread inside or outside its environment. The later account qualifies the early belief rather than supporting a timeless statement that no malicious file existed. Customer updates
Stryker said its investigation had not identified malicious activity directed at customers, suppliers, vendors, or partners, or evidence of the actor accessing their systems through this incident. The customer page described an assurance letter as supporting that belief. This article attributes the assessment to Stryker's retained account; it does not claim an independent review of the letter or proof that no data was compromised anywhere. Customer updates
Restoration and the April amendment
The April 1 update said the global manufacturing network was fully operational, production was moving toward peak capacity, and commercial, ordering, and distribution systems had been restored. The separate amendment, signed April 9, expressly identifies itself as amending the March 11 Form 8-K and refers to the March 12 and March 23 reports. It likewise reported full manufacturing operation and restored commercial, ordering, and distribution systems, while saying the incident investigation remained ongoing. Customer updates · April amendment
The amendment said Stryker had determined that the incident materially affected operations, with resulting effects on first-quarter 2026 financial results. It considered the disruption's scope and duration, affected systems, and potential customer, regulatory, and other impacts. Separately, the company believed there had not been, and was not reasonably likely to be, a material impact on its 2026 full-year guidance. A quarterly effect and a qualified annual-guidance assessment can coexist; the source provides no numerical incident-loss amount here. April amendment
Editorial interpretation: this history shows changes in technical knowledge and the scope of impact assessments while restoration advanced. The amendment's scheduled April 30 earnings discussion is a forward-looking timetable, not evidence in this source window that the discussion occurred. A named actor, complete confidentiality assessment, and final financial effects remain unestablished by these selected passages. Customer updates · April amendment
Source scope
The amendment PDF is an issuer-hosted representation; native SEC acquisition and byte equivalence with EDGAR remain unverified.
Sources
Customer updates — dated sections March 12, March 23, and April 1, 2026; one retained page capture.
Amendment PDF — signed April 9, 2026; March 11 original report expressly identified in the amendment.