Drooid Logo
Back to story perspectives

Full Breakdown

FBI Seizes Websites of Iran-Linked Hacker Group Following Stryker Cyberattack

3/20/2026, 12:30:34 PM

Overview of the Cyberattack on Stryker

The FBI recently seized two websites associated with the pro-Iranian hacker group Handala, which claimed responsibility for a significant cyberattack on Stryker, a Michigan-based medical technology company. This incident marks the first major cyberattack on a U.S. company since the onset of hostilities between the U.S. and Iran in February 2023. Handala, believed to be linked to Iran's Ministry of Intelligence and Security, asserted that it wiped data from over 200,000 devices within Stryker's network, disrupting the company's operations globally.

Details of the Attack

The cyberattack, which occurred on March 11, 2023, reportedly involved the exploitation of Stryker's Microsoft Intune system, a tool used for managing employee devices. Handala claimed to have deleted vast amounts of data and accessed sensitive information, although Stryker has stated that it found no evidence of malware being deployed. The company confirmed that the attack disrupted its order processing, manufacturing, and shipping capabilities, leading to delays in surgeries and other medical services.

Official Responses and Mitigation Efforts

In response to the attack, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning urging organizations to enhance their endpoint security, particularly regarding Microsoft Intune. CISA recommended implementing role-based access control, phishing-resistant multi-factor authentication, and requiring multiple approvals for high-impact administrative actions. The FBI's seizure of Handala's websites was framed as a necessary action to disrupt ongoing malicious cyber operations linked to a foreign state actor.

Criticism and Opposition

Experts have noted that while the seizure of Handala's websites is a significant step, it may only provide a temporary solution. Gil Messing, Chief of Staff at Check Point, remarked that such actions often lead to a "whack-a-mole" scenario, where groups like Handala can quickly re-establish their online presence. Additionally, Nariman Gharib, a cyber-espionage investigator, emphasized that while the takedown disrupts Handala's operations, it does not eliminate the threat posed by Iranian cyber actors.

Conflicting Reports and Gaps

There are discrepancies regarding the extent of the data loss and the impact of the attack. Handala claimed to have wiped 12 petabytes of data and stolen 50 terabytes, while Stryker has not confirmed the total amount of data affected. Furthermore, while Handala asserted that the attack was in retaliation for U.S. military actions in Iran, Stryker has not publicly detailed the motivations behind the attack.

What's Next

As investigations continue, Stryker is focused on restoring its systems and ensuring the integrity of its operations. The FBI's actions against Handala signal a broader strategy to disrupt foreign-backed cyber operations, particularly in the healthcare sector, which has been increasingly targeted in recent years. The situation remains fluid, with potential for further developments as both Stryker and federal agencies work to mitigate the fallout from this cyber incident.

Verbatim Quotes

  • “This act of digital aggression only serves to highlight the fear and anxiety our actions have instilled in the hearts of those who oppress and deceive,” — Handala
  • “It’s an important step, as most of Handala’s work was to publish their work and create the physiological effect of the damage, even if exaggerated.” — Gil Messing, Chief of Staff, Check Point
  • “Their organizational and management structure is currently disrupted, and at any moment, members of this group may be targeted by missile strikes, just like other cyber forces of the regime,” — Nariman Gharib, Cyber-Espionage Investigator