When Identity Systems Fail, the Whole Business Feels It
It is believed that the hackers broke into Stryker’s systems via stolen administration credentials, harvested via infostealer malware. It’s a telling example of how dependent modern enterprise has become on identity systems.
With the identity layer encompassing everything from application access to remote connections, daily operations can come screeching to a halt when these systems are compromised. Employees can’t log in, applications can’t start, administrative access becomes impossible and VPNs fail. For this reason, identity has become the modern security perimeter, stretching from Active Directory into the cloud through platforms such as Entra ID, Okta and Ping Identity.
Today, hackers understand identity systems’ vital role and are quick to target them to launch attacks. In fact, according to Palo Alto Networks’ 2026 Unit 42 Global Incident Response Report, identity weaknesses were part of nearly 90% of their investigations. In addition, a recent Semperis survey of 1,100 IT and security professionals found that 75% of healthcare organizations expect artificial intelligence to make identity attacks more common — yet only 27% are very confident they could recover if an AI agent exposed admin credentials.
As the Stryker incident demonstrates, the consequences of an identity-driven attack are widespread. Even with the breach contained, Stryker still faced significant operational disruptions and financial consequences. In a filing to the U.S. Securities and Exchange Commission, the company told investors that “the incident had a material impact on its operations, with resulting impact to the company’s financial results for the first quarter of 2026.”
Downstream Businesses Also Feel the Impact
The fallout from an identity-based attack doesn’t end with the initial target. Modern enterprises are increasingly interconnected, and with national supply chains dependent on continuous service delivery, one compromised identity can set off a chain reaction of disruption beyond the original breach. In healthcare, those disruptions can jeopardize patient care.
The effects spiral when bad actors move deeper into critical systems, but the dangers start much earlier when security teams blind themselves to unseen identity vulnerabilities. Common attack vectors include stolen credentials and weaknesses in platforms such as Active Directory and cloud identity services.
Without visibility into identity systems, security teams can’t easily spot suspicious activity or initiate crisis response processes to halt and contain threats. If healthcare organizations get caught up in the mix, even small delays in incident response can lead to downstream patient care risks.
EXPLORE: AI identity security is the next evolution of identity and access management.
3 Steps To Strengthen Identity Resilience in Healthcare
Companies that adopt an “assume breach” mindset will be better prepared to respond to threats when they occur. Resilience starts with assuming identity will be targeted, but it becomes real when organizations can spot weakness early, rehearse response and remediate faster. This is true cyber resilience.
Operating with an “assume breach” approach also means staying vigilant. If a compromise is detected in one portion of a network, it’s wise to assume there may be others still hidden. Quick containment, investigation and response are key to limiting impact and maintaining trust in high-risk environments. Healthcare organizations should also monitor unauthorized changes occurring in their Active Directory infrastructure and have real-time visibility into changes to elevated network accounts and groups, as well as a fast means of performing a clean recovery.
The potential for the weaponization of AI agents inside healthcare systems only compounds the challenge facing defenders. Semperis’s research also found that only two-thirds of healthcare organizations fully register, authenticate and authorize AI identities — leaving a significant portion of the sector with limited visibility into the agents operating on their networks.
For healthcare organizations, one compromised identity can lead to disruptions in patient care, and disruptions across a vast network of companies that feed into an organization’s supply chain. Prioritizing true identity resilience will stop the chain reaction at its source and increase an organization’s overall security.
