Iran-Linked Hackers Breach FBI Director’s Personal Email and Carry Out Wiper Attack on Stryker
Operators tied to Iran successfully accessed the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation, and published a collection of photographs and other documents online.
The group calling itself “Handala Hack Team” posted on its site that Patel has been added to its roster of compromised targets. The FBI confirmed to Reuters that Patel’s personal emails were targeted and said it has taken steps to address and reduce any risks stemming from the incident. The bureau also indicated the posted material is historical and does not contain government records; the leaked messages reportedly include emails from 2010 and 2019.
Security analysts assess Handala Hack as a pro-Iranian, pro-Palestinian hacktivist front likely tied to Iran’s Ministry of Intelligence and Security (MOIS). The cybersecurity community has tracked this actor under several names, including Banished Kitten, Cobalt Mystique, Red Sandstorm, and Void Manticore. The same operator has also used a separate persona, Homeland Justice, to target Albanian organizations since mid-2022.
A third identity historically linked to the MOIS-aligned cluster - Karma - appears to have been largely supplanted by Handala since late 2023. Research from StealthMole shows Handala maintains a multi-layered presence across the internet, advertising its activity not only on messaging apps and cybercrime forums such as BreachForums but also via surface web domains, Tor services, and file-hosting platforms like MEGA.
Check Point’s recent analysis notes the group focuses on IT and service providers to harvest credentials, frequently gaining initial access through compromised VPN accounts. The vendor reported observing hundreds of login and brute-force attempts against corporate VPN infrastructure tied to Handala-associated infrastructure in recent months. Once inside, the operators commonly use RDP for lateral movement and deploy destructive wiper families - named Handala Wiper and Handala PowerShell Wiper - often delivered through Group Policy logon scripts. In some incidents attackers have also used legitimate disk-encryption tools such as VeraCrypt to hinder recovery efforts.
Flashpoint researchers emphasize that, unlike financially motivated threat actors, Handala’s activity is driven by disruption, psychological pressure, and geopolitical signaling. Their operations tend to coincide with spikes in regional tensions and are aimed at targets that carry symbolic or operational significance.
This activity has unfolded amid rising tensions involving the U.S., Israel, and Iran. Handala claimed responsibility for a destructive campaign against Stryker - a major medical-devices company - asserting it deleted vast amounts of corporate data and wiped thousands of employee machines. Security firms and Stryker confirmed the intrusion is the first publicly confirmed destructive wiper attack against a U.S. Fortune 500 firm.
In a statement posted this week, Stryker said the incident has been contained and that its teams moved quickly to regain control and evict the intruder by removing persistence mechanisms. The company clarified that the breach was limited to its internal Microsoft environment. Stryker also noted the attackers executed a malicious file that ran commands to hide their actions, but the file lacked any self-propagation capability.
In response to the incident, Microsoft and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have issued guidance aimed at hardening Windows domains and locking down Intune. Recommended mitigations include applying the principle of least privilege, requiring phishing-resistant multi-factor authentication (MFA), and enabling multi-admin approval workflows in Intune for high-risk changes.
Handala’s disclosure of Patel’s personal emails appears to be retaliation for a court-authorized U.S. operation that seized four domains allegedly used by MOIS since 2022 to support malign online activities. The U.S. government has also announced a $10 million reward for information about members of the group. The Justice Department named the seized domains as:
justicehomeland[.]orghandala-hack[.]tokarmabelow80[.]orghandala-redwanted[.]to
The Department of Justice said the confiscated domains were used by MOIS to carry out influence operations claiming credit for hacks, publishing stolen information, and even calling for violence against journalists, regime opponents, and Israeli citizens. Among the material reportedly seized were identifying and sensitive records for roughly 190 people connected to the Israeli Defense Forces or Israeli government, plus about 851 GB of personal data tied to members of the Sanzer Hasidic community. The DOJ also says an email account associated with the group - handala_team@outlook[.]com - was used to send death threats to Iranian dissidents and journalists abroad.
Separately, an FBI advisory described how Handala and other MOIS-linked cyber actors use social engineering on messaging platforms to deliver Windows malware. In these campaigns the first-stage payload is disguised as popular apps - such as Pictory, KeePass, Telegram, or WhatsApp - and the malware establishes persistent remote access by leveraging a Telegram bot as a command-and-control (C2) channel.
Using legitimate services like Telegram as C2 helps attackers blend malicious traffic with normal communications and reduces detection likelihood. Artifacts recovered from infected machines show additional capabilities, including audio capture and screen recording while victims attended Zoom calls. The FBI says these operations have targeted Iranian dissidents, opposition figures, and journalists, producing intelligence collection, data disclosures, and reputational harm to the victims.
After the domain seizures, Handala reappeared on a new clearnet site - handala-team[.]to - denouncing the takedowns as attempts by the U.S. and its partners to silence the group’s voice.
The wider conflict has driven a surge in cyberactivity: DDoS attacks, website defacements, and hack-and-leak operations against Israeli and Western organizations have increased, while hacktivist campaigns seek to intimidate and disorient target populations.