U.S. seizes four domains linked to Iran-associated Handala hacking group
The Facts
- U.S. authorities seized four internet domains associated with the Handala hacking group.
- The Justice Department said Handala is linked to Iran’s Ministry of Intelligence and Security.
- Handala claimed responsibility for a cyberattack on U.S. medical technology company Stryker.
- The seized domains were described by U.S. authorities as being used to post stolen information and carry out psychological operations or intimidation campaigns.
- At least one of the seized websites had been used to publicize Handala’s hacking activity, and another had been used to dox people linked to Israeli defense contractors and officials.
- After the seizure, Handala said its website was restored and framed the action as an attempt to silence the group.
Context
What did U.S. authorities say the domains were used for?
The Justice Department and FBI said the domains were used to support malicious cyber activity, including posting stolen information, publicizing hacks, and carrying out psychological or intimidation operations Axios,CBS News,TechCrunch,therecord.media.
What happened to Handala’s website after the seizure?
Reports said the site was back online within a day, and Handala posted that the seizure was a “desperate attempt” by the United States and its allies to silence the group Reuters,CNA,National.
Did U.S. officials say the seizure was connected to only one attack?
No. While the action followed Handala’s claim of responsibility for the Stryker incident, court filings and DOJ statements described broader activity involving multiple campaigns and multiple targets CBS News,therecord.media.
The receipts — all 24 sources
Wire services (1)
Independent coverage (23)
Facts first. Then every angle.
The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.