HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
STRYKER CORPORATION
bd_1968f2ada13078eb · schema v1 · pii pii-v1
Full breach record for STRYKER CORPORATION →Stryker Corporation, a medical technology company, reported a cybersecurity incident where an unauthorized third party accessed internal systems between May 14 and June 10, 2024, exfiltrating personal information including names, dates of birth, and medical data. Stryker discovered the activity on June 10, 2024, engaged forensic experts, notified law enforcement, and contained the incident. This supplemental notice to the Maryland Attorney General reports 41 affected Maryland residents, offering 24 months of credit monitoring.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_5542195d27f13492Vermont State AGfiled 2024-10-31(378d gap)Verified
- bd_c5f81247abfc0a81Indiana State AGfiled 2024-10-31(378d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-375726.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2025
- Raw hash
- 1c5ed54b98b02088429e8def4bb1929d7c3214d4daf92ba42c50160699788fa6
Reporting entity
- Name
- Norton Rose Fulbright US LLPnorm: norton rose fulbright us
- Domain
- nortonrosefulbright.com
Victim entity
- Name
- STRYKER CORPORATIONnorm: stryker
- Domain
- stryker.com
Incident
- Discovered
- Jun 10, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2024
- Affected individuals
- 41
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 months(521 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.