News

FBI Seizes Two Websites Linked to Pro-Iranian Group Handala

  • Jeffrey Burt--securityboulevard.com
  • published date: 2026-03-19 00:00:00 UTC

None

<p>The FBI this week seized the two websites belong to pro-Iranian hacktivist organization that claimed responsibility for the <a href="https://securityboulevard.com/2026/03/iranian-hackers-attack-u-s-company-stryker-in-escalation-of-cyber-war/" target="_blank" rel="noopener">data-wiping attack</a> on U.S. medical tech company Stryker and is among the most actives of the myriad threat groups that mobilized when the U.S. and Israeli air strikes on Iran began more than two weeks ago.</p><p>The two domains – one Handala used as a data leak site and another to target people with possible links to Israeli defense contractors – now feature seizure announcements from the FBI about the seizures. Neither the agency nor the Justice Department (DOJ) has released statements about the move.</p><p>That said, announcements themselves say the sites were seized pursuant to a U.S. Federal Court warrant, adding that “law enforcement authorities determined this site was used to conduct, facilitate, or support malicious cyber activities on behalf, of or in coordination with, a foreign state actor. These activities may include unauthorized network intrusions, infrastructure targeting, or other violations of United States law.”</p><p>According to reports, the Handala group on its official Telegram channel confirmed that websites were seized and taken offline, adding that the action was a “desperate attempt to silence our voice.”</p><p>“This act of digital aggression only serves to highlight the fear and anxiety our actions have instilled in the hearts of those who oppress and deceive,” the hackers wrote, <a href="https://techcrunch.com/2026/03/19/fbi-seizes-pro-iranian-hacking-groups-websites-after-destructive-stryker-hack/" target="_blank" rel="noopener">according to TechCrunch</a>. “Although they attempt to erase the evidence and hide their crimes through censorship and intimidation, their actions only confirm the impact of our mission. The pursuit of justice cannot be stopped by taking down a website, the movement for truth will persist and grow stronger.”</p><p>The news site also noted that Handala’s X site also was suspended.</p><h3>A Widening Cyberthreat Surface</h3><p>This comes amid a surge of cyberthreats in retaliation for the bombings of Tehran and other places in the country, and as Iran – through kinetic warfare and through cyberspace – also targeted other countries in the Middle East deemed to be aligned with the United States.</p><p>CloudSEK security intelligence analysts said that <a href="https://www.cloudsek.com/blog/ai-the-iran-us-conflict-and-the-threat-to-us-critical-infrastructure" target="_blank" rel="noopener">within hours of the start of the bombing</a> by the United States and Israel, more than <a href="https://securityboulevard.com/2026/03/pro-iranian-hacktivists-join-nation-state-groups-in-targeting-u-s-israel-others/" target="_blank" rel="noopener">60 pro-Iranian hacktivists gangs</a> mobilized to join nation-state threat groups run by Iran’s Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS).</p><p>Akamai researchers wrote that in the <a href="https://securityboulevard.com/2026/03/cyberattacks-spike-245-in-the-two-weeks-after-the-start-of-war-with-iran/" target="_blank" rel="noopener">first two weeks of the war</a>, they saw a <a href="https://www.akamai.com/blog/security/fortify-network-security-emerging-geopolitical-cyberthreats" target="_blank" rel="noopener">245% jump</a> in attempts by threat actors to attack critical institutions and businesses around the world.</p><h3>Multiple Targets</h3><p>Handala, which has been active since 2023 and has targeted Israeli organizations with data-wiping and other attacks, has become among the most active of the threat actors. Flashpoint, which has been tracking the activity in both the kinetic fighting and the battle in cyberspace, noted the group has taken credit for attacks, such as a data-wipe and exfiltration operation against the Hebrew University of Jerusalem – saying it erased more than 48 TB of data and exfiltrated 23 TB of confidential information – and claiming to have leaked 100,000 personal emails from the former head of Mossad’s research organization.</p><p>However, it was last week’s attack on Stryker – which has headquarters in Portage, Michigan, but about 56,000 employees around that world and generated more than $25 billion in net sales last year – that stands out. Handala said it was able to erase the data from about 80,000 corporate and personal devices – including computers, servers, and mobile devices – in which the attackers were able to get into the network by compromising a Windows domain administrator account and using a command in Microsoft Intune to force a factory reset on them. No malware was needed</p><p>Since the attack, <a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117" target="_blank" rel="noopener">Microsoft</a> and <a href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization?utm_source=IranHardening202603&amp;utm_medium=GovDelivery" target="_blank" rel="noopener">CISA</a> has published steps organizations should take strengthen Intune management controls. In addition, Stryker has been giving <a href="https://www.stryker.com/us/en/about/news/2026/a-message-to-our-customers-03-2026.html" target="_blank" rel="noopener">updates about its efforts</a> to restore and better protect its devices.</p><h3>Pressure Is On Defenders</h3><p>Brian Bell, CEO of <a href="https://fusionauth.io/" target="_blank" rel="noopener">FusionAuth</a>, which makes authentication and user management software, said that the attack on Stryker showed that authentication and authorization are not the same thing and that companies going forward will need to make adjustments to protect themselves.</p><p>“Attackers didn’t need to break in,” Bell said about the Stryker incident. “They walked through the front door with compromised credentials. The missing safeguard is contextual: organizations need systems that can recognize when a privileged action is anomalous and require additional verification at that moment, not just at login. … The FBI’s seizure of Handala’s infrastructure is welcome, but the next group will find a new front door. The architectural fix has to happen on the defender’s side.”</p><div class="spu-placeholder" style="display:none"></div><div class="addtoany_share_save_container addtoany_content addtoany_content_bottom"><div class="a2a_kit a2a_kit_size_20 addtoany_list" data-a2a-url="https://securityboulevard.com/2026/03/fbi-seizes-two-websites-linked-to-pro-iranian-group-handala/" data-a2a-title="FBI Seizes Two Websites Linked to Pro-Iranian Group Handala"><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Ffbi-seizes-two-websites-linked-to-pro-iranian-group-handala%2F&amp;linkname=FBI%20Seizes%20Two%20Websites%20Linked%20to%20Pro-Iranian%20Group%20Handala" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Ffbi-seizes-two-websites-linked-to-pro-iranian-group-handala%2F&amp;linkname=FBI%20Seizes%20Two%20Websites%20Linked%20to%20Pro-Iranian%20Group%20Handala" title="LinkedIn" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Ffbi-seizes-two-websites-linked-to-pro-iranian-group-handala%2F&amp;linkname=FBI%20Seizes%20Two%20Websites%20Linked%20to%20Pro-Iranian%20Group%20Handala" title="Facebook" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_reddit" href="https://www.addtoany.com/add_to/reddit?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Ffbi-seizes-two-websites-linked-to-pro-iranian-group-handala%2F&amp;linkname=FBI%20Seizes%20Two%20Websites%20Linked%20to%20Pro-Iranian%20Group%20Handala" title="Reddit" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_email" href="https://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2026%2F03%2Ffbi-seizes-two-websites-linked-to-pro-iranian-group-handala%2F&amp;linkname=FBI%20Seizes%20Two%20Websites%20Linked%20to%20Pro-Iranian%20Group%20Handala" title="Email" rel="nofollow noopener" target="_blank"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share"></a></div></div>