FBI shuts down Handala data leak site following Stryker cyberattack; Data breach related.
Mar 19, 2026 // 19:17 - Niko Dunn


After a major cyberattack on Stryker, a medical technology company, that deleted data from around 80,000 devices, the FBI has taken control of two websites used by the Handala hacktivist group.

The domains handala-redwanted[.]to and handala-hack[.]to, which were used by the hacktivist group, now display a notice saying the FBI seized them according to a warrant from the District Court for the District of Maryland.

The seizure message states: “The Federal Bureau of Investigation (“FBI”) has seized this domain with a warrant issued by a United States District Court for the District of Maryland as part of an FBI law enforcement action. Authorities found that this domain was used to conduct, support, or enable malicious cyber activities on behalf of, or in coordination with, a foreign state actor.”

“These activities might include unauthorized access to networks, targeting infrastructure, or other violations of US law.”

“To stop ongoing malicious cyber operations and prevent further misuse, the United States Government has taken control of this domain under a court-authorized warrant.”

Handala, also called Handala Hack Team, Hatef, or Hamsa, is a pro-Palestinian hacktivist group with alleged ties to Iran that emerged in December 2023. They reportedly have links to Iran’s Ministry of Intelligence and Security (MOIS). Their attacks have focused on Israeli organizations, using destructive malware to wipe data from Windows and Linux systems.

Although there has been no official announcement from law enforcement about the seizures, the domain name servers have been changed to those typically used by the FBI when seizing domains.

It is unknown if the FBI only seized the domains or if they also have access to the content and server logs of the websites.

This action follows Handala’s large-scale cyberattack on Stryker, a US medical technology company, where they compromised a Windows domain administrator account and created a new Global Administrator account to carry out their attack.

They then used the Microsoft Intune “wipe” command to reset approximately 80,000 devices, including computers and mobile devices, to factory settings. Employees’ personal devices managed by the company were also wiped.

Handala has acknowledged the seizures of their websites and the need for more “reliable infrastructure,” saying they are building new websites to announce their attacks.

A Telegram post from the group stated, “Considering recent events and the need for secure and stable infrastructure, we inform you that building a new digital base is a complex and lengthy process.”

“However, we are still dedicated to continuing our mission without disruption.”

After the attack, Microsoft and CISA provided guidance on strengthening Windows domains and securing Intune to help prevent similar attacks on other organizations.

#breach  #cyberattack  #data  #down  #fbi  #following  #handala  #leak  #news  #related.  #shuts  #site.  #stryker   —   News