Editorial draft v2 · Evidence reader R1 · Evidence cutoff: April 9, 2026

Disclosures covered: Dated March 12, March 23, and April 1 statements in one captured customer page, plus the separately retained issuer-hosted amendment signed April 9. These are selected retrospective accounts, not independent historical captures of each page update.

Stryker's March 2026 cybersecurity incident disrupted order processing, manufacturing, and shipping in its Microsoft environment. Its customer updates documented both restoration and a change in the technical assessment: an early belief of no indication of ransomware or malware was followed by identification of a malicious file that the company said could not spread. The April amendment then recognized material operational impact and resulting first-quarter financial effects, while preserving a different assessment of full-year guidance. Customer updates · April amendment

Disruption and customer impact

The March 12 customer statement said the attack occurred March 11 and caused a global disruption to Stryker's Microsoft environment. The company activated its incident-response plan and investigated with external advisers and cybersecurity experts. Order processing, manufacturing, and shipping were affected. At that stage, Stryker described its investigation into the incident's nature and scope as early and ongoing, and said it was collaborating with law enforcement and government partners. Customer updates

Another passage on the retained customer page said product and device security and safety were unaffected and that Stryker products remained safe to use. It nevertheless acknowledged disruptions for customers using personalized implants: some patient-specific cases scheduled for the week of March 16 had been rescheduled because of shipping delays. Product-safety claims and delivery disruption address different questions and should remain separate. Customer updates

A revised technical account

In the March 23 update, Stryker said it believed the incident was contained and that its teams and outside experts had removed the unauthorized party. It explained that, early in the investigation, it had believed there was no indication of ransomware or malware. Further work with Palo Alto Networks Unit 42 and others identified a malicious file used to run commands and conceal activity. Stryker said the file could not spread inside or outside its environment. The later account qualifies the early belief rather than supporting a timeless statement that no malicious file existed. Customer updates

Stryker said its investigation had not identified malicious activity directed at customers, suppliers, vendors, or partners, or evidence of the actor accessing their systems through this incident. The customer page described an assurance letter as supporting that belief. This article attributes the assessment to Stryker's retained account; it does not claim an independent review of the letter or proof that no data was compromised anywhere. Customer updates

Restoration and the April amendment

The April 1 update said the global manufacturing network was fully operational, production was moving toward peak capacity, and commercial, ordering, and distribution systems had been restored. The separate amendment, signed April 9, expressly identifies itself as amending the March 11 Form 8-K and refers to the March 12 and March 23 reports. It likewise reported full manufacturing operation and restored commercial, ordering, and distribution systems, while saying the incident investigation remained ongoing. Customer updates · April amendment

The amendment said Stryker had determined that the incident materially affected operations, with resulting effects on first-quarter 2026 financial results. It considered the disruption's scope and duration, affected systems, and potential customer, regulatory, and other impacts. Separately, the company believed there had not been, and was not reasonably likely to be, a material impact on its 2026 full-year guidance. A quarterly effect and a qualified annual-guidance assessment can coexist; the source provides no numerical incident-loss amount here. April amendment

Editorial interpretation: this history shows changes in technical knowledge and the scope of impact assessments while restoration advanced. The amendment's scheduled April 30 earnings discussion is a forward-looking timetable, not evidence in this source window that the discussion occurred. A named actor, complete confidentiality assessment, and final financial effects remain unestablished by these selected passages. Customer updates · April amendment

Source scope

The amendment PDF is an issuer-hosted representation; native SEC acquisition and byte equivalence with EDGAR remain unverified.

Sources

  • Customer updates — dated sections March 12, March 23, and April 1, 2026; one retained page capture.

  • Amendment PDF — signed April 9, 2026; March 11 original report expressly identified in the amendment.

Disclosure history

Article draft version 2 · Evidence reader revision 1 · Evidence cutoff Apr 9, 2026, 12:00 AM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • Stryker Publisher posted April 1, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:53 PM UTC · Retained Oct 7, 2026, 7:53 PM UTC
    • One current captured document, not independent March/April source versions.
    • Do not remove early no-malware claim or upgrade scoped negatives to global absence.
    • Does not establish April 9 SEC amendment relationship or materiality assessment.
    • Independent issuer HTTPS origin, not native SEC acquisition or EDGAR byte-equivalence proof.
  • Stryker Publisher posted April 9, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 9:30 PM UTC · Retained Oct 7, 2026, 9:30 PM UTC5 PDF pages. Page/line citations refer to the extracted text representation.
    • Issuer-hosted filing representation; native SEC acquisition and EDGAR byte equivalence unverified.
    • Issuer CIK is subject association, not an invented SEC receipt.
    • PDF text-layer extraction covers every page; images/visual layout and scanned text are not reconstructed.
    • Page/line locators refer to the recorded extracted text representation, not PDF byte offsets.
    • PDF table cells do not establish financial units without separately verified source context.