Drooid Logo
Back to story perspectives

Full Breakdown

Iranian Hacker Group Handala Targets U.S. Company Stryker Amid Ongoing Conflict

3/20/2026, 10:36:23 AM

Overview of the Cyberattack

The FBI has taken action against Handala, an Iran-linked hacker group, which recently claimed responsibility for a significant cyberattack on Stryker, a Michigan-based Fortune 300 medical technology company. This incident marks the first notable cyberattack on a U.S. company since the onset of hostilities between the U.S. and Iran in February 2023. The FBI seized Handala's website, which had previously showcased the group's hacking exploits and hosted stolen files. The seizure was part of a broader effort to disrupt malicious cyber activities linked to foreign state actors.

Details of the Stryker Cyberattack

Handala's cyberattack on Stryker disrupted the company's order processing, manufacturing, and shipping operations. According to Stryker's filing with the Securities and Exchange Commission, the hackers accessed the company's Microsoft accounts, specifically targeting a program called Intune, which is used for managing corporate devices. Reports indicate that the hackers deleted data en masse from these devices, a tactic reminiscent of previous Iranian cyber operations that employed "wipers" to erase data from victims' networks.

Responses from Authorities

The Cybersecurity and Infrastructure Security Agency (CISA) has acknowledged the Stryker hack, urging companies to enhance security measures for their Microsoft Intune accounts. Nick Andersen, the acting director of CISA, noted that there has not been a significant increase in cyber threats since the conflict with Iran escalated. Gil Messing, Chief of Staff at Check Point, an Israeli cybersecurity firm, commented on the FBI's actions against Handala, stating that it could help mitigate the perception of Iran's cyber capabilities. He emphasized the importance of disrupting Handala's online presence, as much of their impact relied on publicizing their activities.

Criticism and Concerns

Despite the FBI's seizure of Handala's website, experts caution that this action may only provide a temporary solution. Messing described the situation as a "game of whack-a-mole," suggesting that Handala could quickly establish new channels to continue their operations. Additionally, while Handala has claimed responsibility for the Stryker attack, it has not announced any significant operations since, raising questions about the group's current capabilities and intentions.

Conflicting Reports and Gaps

While Handala has also claimed to have hacked Israeli company Verifone, Verifone has stated that it did not experience any attacks on its systems. This discrepancy highlights the challenges in assessing the actual impact of Handala's activities and the broader implications for cybersecurity in the context of ongoing U.S.-Iran tensions.

Verbatim Quotes

  • “Law enforcement authorities determined this domain was used to conduct, facilitate, or support malicious cyber activities on behalf of, or in coordination with, a foreign state actor,” — FBI Statement
  • “It’s an important step, as most of Handala’s work was to publish their work and create the physiological effect of the damage, even if exaggerated.” — Gil Messing, Chief of Staff, Check Point
  • “In the past they’ve managed to bypass takedown by bringing up new channels instead.” — Gil Messing, Chief of Staff, Check Point

The situation remains fluid as both the U.S. and Israel continue to engage in military actions against Iranian targets, while the cybersecurity landscape evolves in response to these geopolitical tensions.