Disclosures and evidence

Revision 1 of 1 · Evidence cutoff Apr 9, 2026, 12:00 AM UTC

0 prior statements preserved · 24 statements added. Attributed source statements retain the source’s qualifications.

What the company disclosed

  1. Stryker stated: “On March 11, 2026, we experienced a cybersecurity attack which resulted in a global disruption to Stryker’s Microsoft environment. Upon detecting this incident, we quickly activated our incident response plan and launched an investigation with the support of external advisors and cybersecurity experts.”

  2. Stryker stated: “Early in our investigation, we believed there was no indication of ransomware or malware. Further into the course of our investigation, alongside Palo Alto Networks Unit 42 and other experts, we identified that the threat actor used a malicious file to run commands which allowed them to hide their activity while in our systems. To be clear, this file was not capable of spreading — either inside or outside of our environment. Most importantly, at no point has our investigation identified malicious activity directed towards our customers, suppliers, vendors or partners. Unit 42’s latest findings are included in a General Assurance Letter we received, which can be found below. This letter reaffirms our belief that this incident is contained and that analysis has not identified any evidence of the threat actor accessing customer, supplier, vendor and partner systems as a result of this incident.”

  3. Stryker stated: “Item 1.05 Material Cybersecurity Incidents. As previously disclosed in the Original Report and as further reported on two Item 7.01 Current Reports on Form 8-K, furnished to the SEC on March 12, 2026, and March 23, 2026 respectively, on March 11, 2026, the Company identified a cybersecurity incident, which when it occurred, caused disruptions to the Company’s business operations. Since then, the Company has worked diligently, together with third-party experts and law enforcement, to contain and neutralize the impact of the incident and restore operations. The Company’s investigation of the incident remains ongoing.”

Operational impact

  1. Stryker stated: “This incident has caused disruptions to order processing, manufacturing and shipping. However, we are working diligently to restore our systems and above all, we are committed to ensuring our customers can continue to deliver seamless patient care.”

  2. Stryker stated: “As a reminder, this incident did not affect the security or safety of our products or devices. All Stryker products across our global portfolio, including connected, digital, and life-saving technologies, remain safe to use. Some of our customers that utilize our personalized implants are experiencing some disruptions. We understand that some patient-specific cases scheduled for the week of March 16 have been rescheduled due to shipping delays we are experiencing. There is nothing more important to us than the customers and patients we serve, and we recognize the criticality of every procedure to every patient. We are working as quickly and safely as possible to reconcile orders, manufacture product and deliver to our customers so they can continue to provide seamless patient care. This is a 24/7 effort and the first priority of our entire organization.”

  3. Stryker stated: “Based on the information currently available to the Company, and assessment of both quantitative and qualitative factors that emerged in the weeks following the incident, the Company has determined that the incident had a material impact on its operations, with resulting impact to the Company’s financial results for the first quarter of 2026. In reaching this determination, the Company considered factors including the scope and duration of the operational disruption, the systems affected and the potential for customer, regulatory and other impacts.”

Reported data impact

  1. Stryker stated: “Early in our investigation, we believed there was no indication of ransomware or malware. Further into the course of our investigation, alongside Palo Alto Networks Unit 42 and other experts, we identified that the threat actor used a malicious file to run commands which allowed them to hide their activity while in our systems. To be clear, this file was not capable of spreading — either inside or outside of our environment. Most importantly, at no point has our investigation identified malicious activity directed towards our customers, suppliers, vendors or partners. Unit 42’s latest findings are included in a General Assurance Letter we received, which can be found below. This letter reaffirms our belief that this incident is contained and that analysis has not identified any evidence of the threat actor accessing customer, supplier, vendor and partner systems as a result of this incident.”

Response

  1. Stryker stated: “We believe the incident is contained, and we are prioritizing restoration of systems that directly support customers, ordering and shipping. Our internal teams, in partnership with third-party experts, reacted quickly to not only regain access but to remove the unauthorized party from our environment.”

  2. Stryker stated: “On March 11, 2026, we experienced a cybersecurity attack which resulted in a global disruption to Stryker’s Microsoft environment. Upon detecting this incident, we quickly activated our incident response plan and launched an investigation with the support of external advisors and cybersecurity experts.”

  3. Stryker stated: “Our investigation into the nature and scope of this incident remains ongoing and is in its early stages. We are collaborating with law enforcement and our government agency partners to share meaningful intelligence about this incident as we learn more.”

  4. Stryker stated: “Item 1.05 Material Cybersecurity Incidents. As previously disclosed in the Original Report and as further reported on two Item 7.01 Current Reports on Form 8-K, furnished to the SEC on March 12, 2026, and March 23, 2026 respectively, on March 11, 2026, the Company identified a cybersecurity incident, which when it occurred, caused disruptions to the Company’s business operations. Since then, the Company has worked diligently, together with third-party experts and law enforcement, to contain and neutralize the impact of the incident and restore operations. The Company’s investigation of the incident remains ongoing.”

Recovery updates

  1. Stryker stated: “As of this week, we are fully operational across our global manufacturing network. Production is moving rapidly toward peak capacity with discipline and stability, supported by restored commercial, ordering and distribution systems. Overall product supply remains healthy, with strong availability across most product lines, as we continue to meet customer demand and support patient care.”

  2. Stryker stated: “As of the date of this Amendment, the Company is fully operational across its global manufacturing network and commercial, ordering and distribution systems have been restored.”

Dates and disclosures

  1. Stryker stated: “04/01/2026 10:45 a.m. ET”

  2. Stryker stated: “03/23/2026 8:30 a.m. ET”

  3. Stryker stated: “03/12/2026 9:13 p.m. ET”

  4. Stryker stated: “UNITED STATESSECURITIES AND EXCHANGE COMMISSION WASHINGTON, D.C. 20549 FORM 8-K/A (Amendment No.1) CURRENT REPORTPursuant to Section 13 or 15(d)of the Securities Exchange Act of 1934 Date of Report (Date of earliest event reported): March 11, 2026 Stryker Corporation (Exact name of Registrant as Specified in Its Charter) Michigan 001-13149 38-1239739 (State or Other Jurisdictionof Incorporation) (CommissionFile Number) (IRS EmployerIdentification No.) 1941 Stryker Way Portage, Michigan 49002 (Address of Principal Executive Offices) (Zip Code) Registrant’s Telephone Number, Including Area Code: (269) 385-2600 (Former Name or Former Address, if Changed Since Last Report) Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions: ☐ Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425) ☐ Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12) ☐ Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b)) ☐ Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c)) Securities registered pursuant to Section 12(b) of the Act: Title of each class TradingSymbol(s) Name of each exchangeon which registered Common Stock, $.10 Par Value SYK New York Stock Exchange 2.125% Notes due 2027 SYK27 New York Stock Exchange 3.375% Notes due 2028 SYK28 New York Stock Exchange 0.750% Notes due 2029 SYK29 New York Stock Exchange 2.625% Notes due 2030 SYK30 New York Stock Exchange 1.000% Notes due 2031 SYK31 New York Stock Exchange 3.375% Notes due 2032 SYK32 New York Stock Exchange 3.625% Notes due 2036 SYK36 New York Stock Exchange Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter).”

  5. Stryker stated: “Dated: April 9, 2026 By: /s/ Tina S. French Name: Tina S. French Title: Corporate Secretary”

  6. Stryker stated: “Item 7.01 Regulation FD Disclosure. The Company is scheduled to report earnings for its first quarter of fiscal year 2026 on April 30, 2026, where it will discuss its financial results and components of its full-year guidance in further detail.”

Disclosure evolution

  1. Stryker stated: “Explanatory Note This Amendment No.1 (the “Amendment”) amends the Current Report on Form 8-K filed by Stryker Corporation (the “Company”) with the Securities and Exchange Commission (the “SEC”) on March 11, 2026 (the March 11, 2026, 8-K referred hereinto as the “Original Report”).”

Qualifications and uncertainty

  1. Stryker stated: “Early in our investigation, we believed there was no indication of ransomware or malware. Further into the course of our investigation, alongside Palo Alto Networks Unit 42 and other experts, we identified that the threat actor used a malicious file to run commands which allowed them to hide their activity while in our systems. To be clear, this file was not capable of spreading — either inside or outside of our environment. Most importantly, at no point has our investigation identified malicious activity directed towards our customers, suppliers, vendors or partners. Unit 42’s latest findings are included in a General Assurance Letter we received, which can be found below. This letter reaffirms our belief that this incident is contained and that analysis has not identified any evidence of the threat actor accessing customer, supplier, vendor and partner systems as a result of this incident.”

  2. Stryker stated: “Our investigation into the nature and scope of this incident remains ongoing and is in its early stages. We are collaborating with law enforcement and our government agency partners to share meaningful intelligence about this incident as we learn more.”

  3. Stryker stated: “Item 1.05 Material Cybersecurity Incidents. As previously disclosed in the Original Report and as further reported on two Item 7.01 Current Reports on Form 8-K, furnished to the SEC on March 12, 2026, and March 23, 2026 respectively, on March 11, 2026, the Company identified a cybersecurity incident, which when it occurred, caused disruptions to the Company’s business operations. Since then, the Company has worked diligently, together with third-party experts and law enforcement, to contain and neutralize the impact of the incident and restore operations. The Company’s investigation of the incident remains ongoing.”

  4. Stryker stated: “The Company believes that the incident has not had, and is not reasonably likely to have, a material impact on the Company’s 2026 full-year guidance.”

Disclosure sources and provenance

  • Stryker Publisher posted April 1, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:53 PM UTC · Retained Oct 7, 2026, 7:53 PM UTC
    • One current captured document, not independent March/April source versions.
    • Do not remove early no-malware claim or upgrade scoped negatives to global absence.
    • Does not establish April 9 SEC amendment relationship or materiality assessment.
    • Independent issuer HTTPS origin, not native SEC acquisition or EDGAR byte-equivalence proof.
  • Stryker Publisher posted April 9, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 9:30 PM UTC · Retained Oct 7, 2026, 9:30 PM UTC5 PDF pages. Page/line citations refer to the extracted text representation.
    • Issuer-hosted filing representation; native SEC acquisition and EDGAR byte equivalence unverified.
    • Issuer CIK is subject association, not an invented SEC receipt.
    • PDF text-layer extraction covers every page; images/visual layout and scanned text are not reconstructed.
    • Page/line locators refer to the recorded extracted text representation, not PDF byte offsets.
    • PDF table cells do not establish financial units without separately verified source context.

Evidence limitations

  • Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
  • Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.