{"id":28265,"date":"2026-03-19T15:34:30","date_gmt":"2026-03-19T15:34:30","guid":{"rendered":"https:\/\/microvibenews.com\/?p=28265"},"modified":"2026-03-19T15:34:30","modified_gmt":"2026-03-19T15:34:30","slug":"fbi-seizes-pro-iranian-hacking-groups-websites-after-destructive-stryker-hack","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=28265","title":{"rendered":"FBI seizes pro-Iranian hacking group&#8217;s websites after destructive Stryker hack"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">The FBI seized and took down two websites linked to the pro-Iranian hacktivist group Handala, which last week <a href=\"https:\/\/techcrunch.com\/2026\/03\/11\/stryker-hack-pro-iran-hacktivist-group-handala-says-it-is-behind-attack\/\">claimed responsibility for a destructive cyberattack<\/a> against the U.S. medical tech giant Stryker.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">As of Thursday, the contents of a website where Handala publicized its hacks, as well as another website that the group used to dox dozens of people over their alleged ties to the Israeli military and defense contractors, such as Elbit Systems and NSO Group, were replaced by a banner announcing the law enforcement action.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The seizure announcement did not say why the FBI and the Justice Department took down the websites. But the language in them appears to indicate U.S. authorities believed these sites were run by hackers linked to a foreign government.<\/p>\n<p class=\"wp-block-paragraph\">\u201cLaw enforcement authorities determined this domain was used to conduct, facilitate, or support malicious cyber activities on behalf of, or in coordination with, a foreign state actor,\u201d read the seizure announcement. \u201cThe United States Government has taken control of this domain to disrupt ongoing malicious cyber operations and prevent further exploitation.\u201d<\/p>\n<p class=\"wp-block-paragraph\">TechCrunch confirmed the website\u2019s seizure by examining its nameserver records, which now point to servers controlled by the FBI.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The FBI and the Justice Department did not immediately respond to TechCrunch\u2019s request for comment.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" height=\"383\" width=\"680\" src=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?w=680\" alt=\"A website takedown and seizure notice by the FBI and the U.S. Department of Justice, which replaced the contents of two websites linked to the pro-Iranian hacktivist group Handala.\" class=\"wp-image-3104002\" srcset=\"https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png 1280w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=150,84 150w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=300,169 300w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=768,432 768w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=680,383 680w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=1200,675 1200w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=430,242 430w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=720,405 720w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=900,506 900w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=800,450 800w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=668,375 668w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=1097,617 1097w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=708,398 708w, https:\/\/techcrunch.com\/wp-content\/uploads\/2026\/03\/handala-hackers-fbi-website-seizure.png?resize=50,28 50w\" sizes=\"auto, (max-width: 680px) 100vw, 680px\"\/><figcaption class=\"wp-element-caption\"><span class=\"wp-element-caption__text\">A website takedown and seizure notice by the FBI and the U.S. Department of Justice, which replaced the contents of two websites linked to the pro-Iranian hacktivist group Handala. (Image: TechCrunch)<\/span><span class=\"wp-block-image__credits\"><strong>Image Credits:<\/strong>TechCrunch \/ Getty Images<\/span><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">In a series of announcements posted on the group\u2019s official Telegram channel on Thursday, Handala acknowledged its websites were taken offline, calling the seizures \u201ca desperate attempt to silence our voice.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis act of digital aggression only serves to highlight the fear and anxiety our actions have instilled in the hearts of those who oppress and deceive,\u201d the hackers wrote. \u201cAlthough they attempt to erase the evidence and hide their crimes through censorship and intimidation, their actions only confirm the impact of our mission. The pursuit of justice cannot be stopped by taking down a website, the movement for truth will persist and grow stronger.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Handala\u2019s <a rel=\"nofollow\" href=\"https:\/\/x.com\/HPRNEW\">X account<\/a> was also recently suspended.<\/p>\n<p class=\"wp-block-paragraph\">The group did not respond to a message sent to their official chat account.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Handala <a rel=\"nofollow\" href=\"https:\/\/www.wired.com\/story\/handala-hacker-group-iran-us-israel-war\/\">has been active<\/a> at least since the October 7, 2023 attacks by Hamas, and is believed to have ties with the Iranian regime. Last week, the group claimed the attack on U.S. medical company Stryker, which has over 56,000 employees across dozens of countries. The hackers said the hack was in retaliation for <a rel=\"nofollow\" href=\"https:\/\/apnews.com\/article\/iran-us-school-hegseth-trump-2ffff06808f7a584b0a03831897ab0b8\">the U.S. government missile strike<\/a> that hit an Iranian school, killing at least 175 people, most of them children.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Last year, Stryker signed <a rel=\"nofollow\" href=\"https:\/\/www.war.gov\/News\/Contracts\/Contract\/Article\/4243673\/contracts-for-jul-14-2025\/\">a $450 million contract<\/a> to supply medical devices to the Department of Defense.<\/p>\n<p class=\"wp-block-paragraph\">Handala reportedly broke into an internal Stryker administrator account, gaining <a rel=\"nofollow\" href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/admin\/add-users\/about-admin-roles?view=o365-worldwide\">near-unlimited access<\/a> to the company\u2019s Windows network. At that point, the hackers allegedly took over Stryker\u2019s Intune dashboards, a tool that was designed to allow the company to manage employee laptops and mobile devices remotely, which included the ability to delete data.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">With access to these dashboards, the hackers were reportedly able to wipe devices owned by both the company and its own employees.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">On Tuesday, Stryker <a href=\"https:\/\/techcrunch.com\/2026\/03\/17\/stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices\/\">said it is still restoring its computers and internal network<\/a> following the hack.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Nariman Gharib, a U.K.-based Iranian activist and independent cyber-espionage investigator, told TechCrunch that the takedowns are good news.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTheir organizational and management structure is currently disrupted, and at any moment, members of this group may be targeted by missile strikes, just like other cyber forces of the regime,\u201d Gharib told TechCrunch.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cBut this does not mean that their activities may stop \u2014 no. It is possible that future leaks may be published by this group through media close to the IRGC,\u201d referring to the country\u2019s military.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/19\/fbi-seizes-pro-iranian-hacking-groups-websites-after-destructive-stryker-hack\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The FBI seized and took down t&hellip; <\/p>\n","protected":false},"author":1,"featured_media":28266,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[1662,4910,2542,12345,15718,6466,15407,11080],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/28265"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=28265"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/28265\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/28266"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=28265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=28265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=28265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}