Monday, August 3, 2026

Policy & Regulation

U.S. links hacktivist group Handala to Iranian government

The U.S. Justice Department has formally linked the hacktivist group Handala to Iran’s Ministry of Intelligence and Security, following the group's recent cyberattack on Stryker.

U.S. links hacktivist group Handala to Iranian government

The U.S. Justice Department has formally accused Iran’s Ministry of Intelligence and Security (MOIS) of operating the hacktivist group Handala. The government characterized the group as a fake activist persona used to carry out psychological operations against its enemies, claim responsibility for cyberattacks, and publish stolen information. Handala recently claimed responsibility for a destructive cyberattack against Stryker, a U.S. medical technology company. According to the Justice Department, the group has also called for the killing of journalists, regime dissidents, and Israeli persons.

The announcement followed action by the FBI, which seized two websites linked to Handala. FBI Director Kash Patel stated that the agency took down four of the operation’s pillars and noted that their work was not finished. Handala had used these websites to claim responsibility for a March 11 cyberattack on Stryker, during which hackers wiped tens of thousands of employee devices. The hackers claimed the breach was in retaliation for a U.S. air strike on an Iranian school that Iranian officials said killed 168 children. In response, Handala released a statement on Telegram calling the U.S. actions the latest desperate attempts by the United States and its allies to silence the group.

The U.S. government’s crackdown extends beyond Handala. The Justice Department also seized two domains associated with another persona, Justice Homeland. According to an FBI affidavit, Handala, Justice Homeland, and a third persona, Karma Below, are part of the same conspiracy because they are operated by the same individuals. The Justice Department accused these Iranian government hackers of using the Justice Homeland domains to claim responsibility for a 2022 cyberattack against the Albanian government, which took government servers offline and resulted in the theft of sensitive data. Microsoft also previously linked that Albanian cyberattack to the MOIS.

While the U.S. government treats these personas as unified operations, cybersecurity experts point to a complex structure. Alex Orleans, the head of threat intelligence at Sublime Security, noted that the people managing the public-facing persona are not necessarily the ones executing the technical hacks. “Handala does not necessarily equate, one-to-one, with the actors conducting the activities it’s taking credit for,” said Orleans. He suggested that multiple teams could conduct actual intrusions while a distinct team is responsible for maintaining the persona, with all of these distinct elements coexisting within a larger unified MOIS element. Orleans added that there is a level of opacity in these operations that can be difficult to penetrate. Meanwhile, DomainTools cybersecurity researcher Keith O’Neill noted that Handala has already established new domains.

Why it matters

The U.S. Justice Department’s formal attribution of Handala to Iran’s Ministry of Intelligence and Security marks a significant escalation in the ongoing cyber conflict. By seizing domains and exposing the links between multiple front personas, U.S. authorities are actively trying to disrupt Iranian psychological operations rather than just defending against their intrusions.