Cyber & Intelligence — 2026-03-31

Iran-Linked Handala Group Claims Wiper Attack on Stryker, Sends 5,000 Workers Home in Ireland

Handala, linked to MOIS and assessed as a Void Manticore persona, claimed a destructive wiper attack on Stryker Corporation that allegedly erased 200,000 systems and sent 5,000 Irish workers home. The likely attack vector was compromised Microsoft Intune admin access enabling simultaneous fleet-wide device wipes. KELA warned Iranian state actors are increasingly blending espionage and ransomware operations.

Analysis
The Stryker attack attributed to Handala/Void Manticore demonstrates MOIS operational capability against hardened Western corporate targets. The claimed 200,000 systems wiped and 5,000 workers sent home in Ireland, if verified, would make this the most destructive single cyberattack of the Iran conflict. The scale figures originate from Handala's own claims; Stryker has not publicly confirmed the extent of damage, though workforce disruption in Ireland is independently corroborated.
3 sources
  1. Iranian hackers target US critical infrastructure through ransomware proxies, KELA warns - Industrial Cyber
  2. Medtech giant Stryker offline after Iran-linked wiper malware attack - BleepingComputer
  3. Iranian Hacktivists Strike Medical Device Maker Stryker in Severe Attack - Zero Day

View in full brief →

UNCLASSIFIED // OPEN SOURCE