Cybersecurity & Privacy — 2026-03-19

Iran-Linked Handala Group Wipes 200,000 Stryker Devices in Retaliatory Cyber Attack

Iranian hacktivist group Handala compromised Stryker's Microsoft Intune administrator account and pushed a coordinated wipe to over 200,000 systems across 79 countries, exfiltrating 50TB of data. The MOIS-affiliated group claimed retaliation for the Minab school strike that killed 175 people. The Register reports the attack is 'just the beginning' of Iran's retaliatory cyber campaign against US companies.

Analysis
Prior INTSUM covered the initial Stryker breach. The Register's March 18 reporting characterizes this as 'just the beginning' of Iran's retaliatory cyber campaign. Combined with Unit 42's threat brief, the Handala/Void Manticore operation sets the template for MOIS-directed attacks on US commercial targets.

View in full brief →

UNCLASSIFIED // OPEN SOURCE