Cyber & Privacy — 2026-03-31

Iran Cyber Campaign Escalates: FBI Director Breached, Stryker Wiped, Bomb Shelter Spyware Deployed

Iran's cyber operations have intensified alongside the kinetic campaign, with MOIS-linked Handala Hack emerging as the most prolific threat actor. The group breached FBI Director Patel's personal email, publishing photographs and 300+ messages, prompting a $10 million FBI bounty. Handala also wiped 200,000 devices at US med-tech company Stryker via Microsoft Intune. Israeli Android users received texts offering bomb shelter locations that instead deployed full-device spyware timed to missile strikes. Unit 42 tracked approximately 60 hacktivist groups active since operations began. Iran remains under a near-total internet blackout exceeding 27 days.

Analysis
The Patel email breach, reported in the prior cycle, is now paired with a $10M FBI bounty, indicating the bureau treats Handala as a strategic threat rather than a nuisance hacktivist group. The bomb shelter spyware tactic is operationally timed to missile strikes, weaponizing civilian fear as a delivery mechanism. With ~60 groups active and Iran's own internet at 1-4% connectivity, attribution remains heavily one-directional: Western targets are visible, Iranian damage assessment is effectively blacked out.
1 sources
  1. Hacked hospitals, hidden spyware: Iran conflict shows how digital fight is ingrained in warfare - Washington Post

View in full brief →

UNCLASSIFIED // OPEN SOURCE