Business Context and Reporting Period
Company: Stryker Corporation (SYK)
Filing Type: Form 8-K (Current Report)
Date of Report: March 23, 2026
Subject: Update on a previously disclosed cybersecurity incident (Item 7.01 Regulation FD Disclosure).
Key Financial Metrics
This filing does not contain specific financial data such as revenue, profit, cash flow, margins, debt, or liquidity figures. The report explicitly states that the Company has not yet determined whether the incident is reasonably likely to have a material impact on its financial condition or results of operations.
Material Changes and Incident Status
- Incident Nature: The investigation has confirmed the threat actor used a malicious file to run commands and hide activity. However, the file was not capable of spreading inside or outside the Company's environment.
- Ransomware Status: Management maintains the belief that the incident did not involve ransomware or malware capable of spreading.
- Scope of Impact: The incident caused disruption to the corporate network environment, including the Microsoft environment.
- Data Access: Current analysis has not identified evidence of the threat actor accessing customer, supplier, vendor, or partner systems. No malicious activity directed toward these third parties has been identified.
- Containment: The Company, working with third-party experts (including Palo Alto Networks Unit 42) and law enforcement, believes the incident is contained.
Outlook, Risks, and Management Commentary
Management Commentary: The investigation is ongoing. The Company is continuing to assess the scope, nature, and impact, including operational and financial consequences. Updates will be provided via the Company's website, superseding previous reports.
Risks and Contingencies:
- Potential adverse impact on revenue, operating income, and cash flows.
- Delays or difficulties in restoring systems and data integrity.
- Diversion of management attention from operations.
- Potential litigation, regulatory scrutiny, and reputational risk.
- Unauthorized release of data or use of data for fraudulent purposes.
Forward-Looking Statements: The filing includes standard disclaimers that actual results may differ materially from expectations due to the uncertainties surrounding the incident's full impact.
Investor Verification Checklist
- Verify the status of the "General Assurance Letter" (Exhibit 99.1) and "Company Statement" (Exhibit 99.2) attached to the filing.
- Monitor the Company's website for updates that supersede this report regarding the scope of the disruption.
- Watch for future filings (10-Q or 10-K) to determine if the incident results in a material financial impact or restatement of results.
- Assess the timeline for full restoration of the Microsoft environment and corporate network.
- Review subsequent communications for any indication of data exfiltration or third-party system access that was not initially detected.