INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
FBI seizes Handala site after Stryker cyberattack
| 2026-03-19 16:14 CRITICAL HIGH RANSOMWARE & EXTORTION DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
The FBI seized two websites used by the Handala hacktivist group on March 19, 2026, after a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices. The attack was reportedly linked to Iran's Ministry of Intelligence and Security (MOIS) and targeted Israeli organizations with malware designed to wipe Windows and Linux devices. The seized domains display a seizure notice stating they were used to conduct malicious cyber activities in coordination with a foreign state actor, specifically the United States Government has taken control of this domain to disrupt ongoing malicious cyber operations and prevent further exploitation.
Technical Mitigations AI-generated
• Patch Microsoft Intune to prevent exploitation of Global Administrator account
• Use a secure domain administrator account and monitor for suspicious activity
• Implement robust Windows hardening measures, such as disabling unnecessary services
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ns•••••.gov
ns•••••.gov
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
December 2023
Threat actors behind the Stryker cyberattack compromised a Windows domain administrator account and created a new Global Administrator account to issue destructive malware.
Click on any entity below to view its context and source!
infrastructure
Windows
This action follows Handala's
massive cyberattack on US medical giant Stryker
, in which they compromised a Windows domain administrator account and created a new Global Administrator account to use in their attack.
These attacks targeted Israeli organizations with destructive malware designed to wipe Windows and Linux devices.
"
After the attack,
Microsoft
and
CISA
released guidance on hardening Windows domains and securing Intune to prevent similar attacks at other companies.
infrastructure
Linux
These attacks targeted Israeli organizations with destructive malware designed to wipe Windows and Linux devices.
infrastructure
80,000 devices
They then issued the Microsoft Intune "
wipe
" command to factory reset approximately 80,000 devices, including computers and mobile devices.
2026/03/19
The FBI seized the Handala data leak site as part of a law enforcement action following a destructive cyberattack by the group on medical technology giant Stryker.
Click on any entity below to view its context and source!
infrastructure
80,000 devices
The FBI has seized two websites used by the Handala hacktivist group after the threat actors conducted a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
This action follows Handala's
massive cyberattack on US medical giant Stryker
, in which they compromised a Windows domain administrator account and created a new Global Administrator account to use in their attack.
These attacks targeted Israeli organizations with destructive malware designed to wipe Windows and Linux devices.
"
After the attack,
Microsoft
and
CISA
released guidance on hardening Windows domains and securing Intune to prevent similar attacks at other companies.
Metrics
infrastructure
80,000
Devices
The FBI has seized two websites used by the Handala hacktivist group after the threat actors conducted a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices.
They then issued the Microsoft Intune "
wipe
" command to factory reset approximately 80,000 devices, including computers and mobile devices.
Metrics
infrastructure
Linux
Affected Product
These attacks targeted Israeli organizations with destructive malware designed to wipe Windows and Linux devices.
Intelligence Sources
BleepingComputer
2026-03-19
FBI seizes Handala data leak site after Stryker cyberattack
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:22
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
attribution
Attributing Entity
the Federal Bureau of Investigation
authority
6x
organisation
Identified Entity
Stryker
entity
2x
source region
Origin Country
United States
country
2x
target region
Target Country
United States
country
2x
industry
Targeted Sector
Government
sector
2x
infrastructure
Affected Product
Windows
software
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
Contextual Telemetry
Context Block
6 METRICS
timeline
Temporal Reference
December 2023
date
infrastructure
Devices
80,000
devices
tactic
Cyber Operation Type
Data Leak
tactic
general metric
Red Report
2,026
red report
general metric
Malicious Samples
1,100,000
malicious samples
general metric
Top Techniques
10
top techniques
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.