A consolidated class action lawsuit filed by eight current and former employees against Stryker following the company’s March 2026 cyberattack has been voluntarily dismissed without prejudice after Stryker sought dismissal on the grounds that the plaintiffs lacked standing.
Lawsuit Dismissed Following Motion to Dismiss
The consolidated litigation arose after eight current and former Stryker employees alleged that their personal information had been compromised during the March 2026 cyberattack against the medical technology company. The individual lawsuits were filed shortly after Stryker publicly disclosed the incident and were later combined into a single action, In re Stryker Corporation Cyberattack Litigation, in the U.S. District Court for the Western District of Michigan, Southern Division.
On June 22, 2026, Stryker filed a motion requesting dismissal of the lawsuit. The company argued that the plaintiffs lacked standing because its forensic investigation had not identified evidence that their personally identifiable information (PII) had been compromised during the incident.
On June 29, 2026, the plaintiffs voluntarily dismissed the consolidated lawsuit. U.S. District Court Judge Hala Jarbou signed an order dismissing the claims without prejudice. The dismissal allows the claims to be filed again if Stryker later determines that the plaintiffs’ PII was compromised in the cyberattack.
Cyberattack Details
The March 2026 cyberattack was attributed to the Iranian hacktivist group Hamdala. The attack targeted Stryker following military action involving the United States and Israel in Iran.
During the incident, the attackers breached certain Stryker systems, exfiltrated approximately 50 terabytes of data, and permanently erased approximately 12 petabytes of data across about 200,000 company devices. The attack disrupted company operations and left multiple systems unavailable for several weeks.
Stryker stated that the incident did not involve devices or systems connected to its customers. However, the electronic ordering system and other related systems used by customers were affected by the disruption.
Plaintiffs’ Allegations and Stryker’s Response
The employees began filing lawsuits within approximately 48 hours after Stryker announced the cyberattack, before the company’s investigation had concluded.
The plaintiffs alleged that information including their names, Social Security numbers, financial account information, medical insurance data, and driver’s license information were compromised. Their lawsuit asserted claims including unjust enrichment, negligence, negligence per se, breach of implied contract, intrusion upon seclusion, declaratory judgment, and breach of confidence.
Stryker stated that its forensic investigation found no evidence that any of the plaintiffs’ PII had been compromised during the cyberattack.
According to Stryker, searches of the compromised files identified business email addresses belonging to two plaintiffs but without personally identifiable information. The company also stated that none of the plaintiffs received notification that their PII had been involved in the incident.
In its motion to dismiss, Stryker argued that the alleged injuries were speculative. The company stated that six plaintiffs claimed the misuse of their PII but did not provide sufficient details connecting that alleged misuse to the March 2026 cyberattack.
Stryker also stated that its investigation found the plaintiffs’ PII had been exposed in numerous previous data breaches, including Social Security numbers. According to the company’s motion, two plaintiffs had information exposed in at least 20 previous data breaches.
Regulatory Status
Stryker reported the cyberattack to the U.S. Securities and Exchange Commission. At the time of publication, the company had not issued breach notifications to state attorneys general or to the HHS Office for Civil Rights in compliance with HIPAA rules.
