Cybersecurity — 2026-03-26
DOJ Attributes Stryker Medical Cyberattack to Iran MOIS Operating as Handala Hacktivist
The US Department of Justice attributed the Handala hacktivist persona to Iran's Ministry of Intelligence and Security (MOIS) and seized four domains—Justicehomeland.org, Handala-Hack.to, Karmabelow80.org, and Handala-Redwanted.to—used for psychological operations including death threats to Iranian dissidents and solicitation of cartel violence. Handala claimed credit for a March 11 destructive cyberattack against medical technology firm Stryker, framed as retaliation for a February 28 missile strike on an Iranian school. Attackers compromised a Microsoft Intune administrator account, created a rogue Global Administrator, and issued remote wipe commands against corporate endpoints. Handala claimed over 200,000 devices wiped, but forensic analysis confirmed approximately 80,000 devices were erased between 0500-0800 UTC, including employee personal phones enrolled via BYOD. Stryker initially reported no malware was involved, but a subsequent investigation by Palo Alto Networks Unit 42 identified that a malicious file was used to run commands that allowed the attackers to conceal their activity. The attack disrupted ordering, manufacturing, and shipping across 79 countries. Handala also claimed exfiltration of 50 terabytes of Stryker data, though analysts assess these figures are likely inflated given Handala's documented pattern of exaggerating breach claims. As of March 26, Stryker has restarted electronic ordering and most manufacturing lines. Employee data breach lawsuits have been filed. CISA subsequently issued guidance urging enterprises to harden Intune configurations including least-privilege admin roles, phishing-resistant MFA, and multi-admin approval for sensitive actions like device wiping.
Analysis
The MOIS attribution confirms Iran is conducting offensive cyber operations against US commercial targets in parallel with kinetic operations. Targeting a medical device manufacturer and leveraging Microsoft Intune native wipe as a destructive tool, wiping 200,000 devices, shows MOIS turning legitimate enterprise management tools into weapons. Prior digest reported FBI domain seizures linked to the same Handala persona. This story is well-sourced across multiple independent primary reporters—DOJ press release, CISA alert, Krebs on Security, The Record, BleepingComputer, TechCrunch, and Cybersecurity Dive all conducted independent reporting. One notable evolution: the summary's claim that 'no malware was deployed' was accurate per initial reporting but was contradicted by Stryker's own March 24 update, where Unit 42 forensics identified a malicious file used to conceal attacker activity. The analyst note should use the forensic figure of ~80,000 wiped devices rather than Handala's inflated 200,000 claim, and analysts have flagged Handala's 50 TB exfiltration claim as likely exaggerated given the group's documented pattern of inflating breach figures for psychological effect.
2 sources
- Does Stryker's Cyberattack Response Reveal a Durable Edge in Operational Resilience? - Simply Wall St
- Justice Department Disrupts Iranian Cyber Enabled Psychological Operations - US Department of Justice
View in full brief →