Data-wiping attacks threaten supply chains
- July 27, 2026
- Steve Rogerson

Data-wiping attacks that destroy company systems and backups rather than hold them for ransom are a growing cyber-security threat facing the supply-chain industry, according to Texas-based third-party logistics provider Source Logistics.
The warning follows a March 2026 breach at medical technology company Stryker in which attackers used a legitimate device management tool to wipe tens of thousands of devices remotely.
Source Logistics’ cyber-security strategy centres on reducing the kind of elevated account access that made the Intune-based wipe possible at Stryker. The company prioritises phishing-awareness training for employees and limits the number of accounts with administrative privileges, since data-wiping attacks typically require elevated access to succeed.
Source Logistics also undergoes third-party review of its cyber-security posture, including annual audits and is working towards a formal NIST-aligned security framework. The company’s technology platform is built on a SaaS-first, API-first model, which it says allows it to adapt its security posture more quickly than legacy, in-house warehouse management systems.
According to reports, the Iranian hacking group Handala Hack Team claimed responsibility for the Stryker attack in March, alleging it had impacted more than 200,000 systems. The Wall Street Journal reported (www.wsj.com/politics/national-security/hack-on-u-s-medical-company-shows-reach-of-irans-cyber-capabilities-85999878) the attackers gained global administrator-level access within Stryker’s Microsoft environment and used Microsoft Intune, a legitimate device management tool, to issue remote wipe commands to an estimated 80,000 enrolled devices over a roughly three-hour window. Stryker later confirmed the incident was not a ransomware attack and that no malware was deployed to its systems.
Security researchers at Outpost24, the parent company of cyber-security firm Specops Software (specopssoft.com), identified 278 compromised credentials tied to the stryker.com domain between October 2025 and March 2026, including 83 in the weeks immediately preceding the attack. The finding shows that stolen credentials, rather than malware, are increasingly the way attackers gain entry for destructive attacks such as this one.
“It’s called a data-wiping attack, and it’s relatively new,” said Bart Bullard, chief technology officer of Source Logistics. “Instead of trying to hold a company hostage, attackers are just out to do damage. In the Stryker case, they went after the backup servers, too, which is why it reportedly took the company weeks to fully restore its systems. There are two types of technology leaders: ones who think audits are painful, and ones who think audits help them protect the company. I’m the second kind. I want auditors to find my problems so I can fix them. That’s a lot better than explaining why you didn’t do something in the middle of an attack. My job is to make it so operations never even know they’re being protected; if I do my job right on phishing training and on limiting elevated accounts, we’re not exposed to this kind of attack in the first place.”
Data-wiping attacks add to a broader set of threats facing logistics and warehouse operators, including cargo theft and physical security failures, that Source Logistics said it was addressing through its ongoing technology investments as the company completes a company-wide warehouse management system rollout.
Founded in 1999, Source Logistics (www.sourcelogistics.com) provides tailored logistics and supply chain operations, including omni-channel distribution, warehousing, transportation and value-added services for dry, ambient, cold and frozen packaged goods.










