Listen to the article ☞
0:00
-17:01
The missiles and drones were visible. The cyber campaign was not. When the United States and Israel opened a new strike campaign against Iran on February 28, Reuters reported that Israel had launched what it called a pre-emptive attack and that U.S. strikes were underway. Another Reuters dispatch described fear, flight and disruption inside Iran as the attack spread. In the days that followed, Iran answered in the familiar language of asymmetric war: missiles, drones, proxy pressure and threats against U.S. positions around the region.
But the part of the story that has received far less unified attention is the parallel front that moved through Microsoft tenants, leak sites, personal inboxes, WhatsApp messages, industrial controllers, defense-contractor personnel files and commercially available location data. It was not one event. It was a chain. And although each link has appeared somewhere in public reporting, the full pattern has not been widely reported in this level of detail. The pieces are scattered across wire reports, official advisories and specialist cybersecurity outlets; together, they show a campaign designed not merely to steal information, but to intimidate, disrupt, publicize and keep operating even after takedowns.
The U.S. government expected something like this. A March 2 Reuters report on a DHS intelligence assessment said the Department of Homeland Security assessed that Iran-aligned hacktivists would likely conduct cyberattacks against U.S. networks after the opening strikes. That warning was framed around lower-level activity such as defacements and distributed denial-of-service attacks. What followed was broader and more revealing: a campaign that used ordinary administrative tools and commercially available data as weapons.
The central case is Stryker Corporation, one of the world’s major medical technology companies. On March 11, Stryker posted that it was experiencing a global network disruption to its Microsoft environment as a result of a cyberattack. The company repeatedly said it had no indication of ransomware or malware, that the incident was contained to its internal Microsoft environment, and that its connected and life-saving products remained safe to use. It also acknowledged that the disruption affected order processing, manufacturing and shipping.
This is where the case becomes more important than a conventional cyber incident. According to Reuters, the March 11 attack caused widespread disruption to Stryker’s business, including its ability to process orders, make products and ship them. Reuters also reported that the Iran-linked group Handala claimed responsibility. By March 26, Reuters reported that Stryker’s manufacturing was mostly restored, while staff had found that cellphones, laptops and other remote Windows devices able to connect to the company’s platforms had been impacted.
The most alarming allegation was not that the attackers smuggled in a brilliant new virus. It was that they may have used Stryker’s own management infrastructure. KrebsOnSecurity reported, citing a source familiar with the attack, that the perpetrators appeared to use Microsoft Intune to issue remote wipe commands. Censys and Sygnia reached the same practical lesson: cloud identity and endpoint-management systems like Microsoft Entra ID and Intune should be treated as high-value control planes because, in the wrong hands, they can deliver destructive impact through legitimate administrative functions.
That distinction matters. A ransomware attack announces itself as extortion. A malware outbreak spreads as code. The Stryker incident, as publicly described, points to something simpler and in some ways more frightening: a trusted tool used in an untrusted context. If an attacker gets high-level access to a platform designed to update, manage, lock or wipe devices, the platform itself becomes the weapon.
The biggest numerical claims should be handled carefully. Handala claimed, according to KrebsOnSecurity, that more than 200,000 systems, servers and mobile devices were erased and that offices in 79 countries were affected. Those figures have circulated widely in security reporting, but they remain Handala claims, not independently verified numbers from Stryker. Likewise, Reuters, citing Bloomberg, reported that surgeries were delayed for some patients, not that hundreds of surgeries across countries had been publicly confirmed. The defensible point is still stark enough: a cyberattack on a medical-device supply chain disrupted manufacturing, shipping, ordering and some patient-specific procedures.
Handala presents itself as a hacktivist brand. U.S. officials and security researchers describe something closer to an Iranian intelligence persona. On March 19, the Justice Department announced the seizure of four domains - Justicehomeland, Handala-Hack, Karmabelow80 and Handala-Redwanted - and said those domains were used by Iran’s Ministry of Intelligence and Security, or MOIS, for psychological operations, hacking claims, stolen-data leaks and threats. DOJ specifically said the Handala-hack domain was used to claim credit for a March 2026 destructive malware attack against a U.S.-based multinational medical technologies firm.
Researchers had been following the same ecosystem under other names. Check Point Research identifies Handala Hack as an online persona operated by Void Manticore, also known as Red Sandstorm and Banished Kitten, and says the actor is affiliated with MOIS. CrowdStrike describes Banished Kitten as an Iran-nexus adversary linked to MOIS and says it has used personas including Homeland Justice and Handala Hack Team. MITRE ATT&CK now lists Void Manticore as a group assessed to operate on behalf of MOIS, with associated names including Handala Hack, Homeland Justice, Banished Kitten and Red Sandstorm.
There is also a reported human chain behind the brand. Check Point cited public reporting that linked Void Manticore to MOIS internal-security structures under Seyed Yahya Hosseini Panjaki. Iran International reported that Israel’s military said it killed Yahya Hamidi - identified by Iran International as Yahya Hosseini Panjaki - a deputy minister-level intelligence official for Israel affairs, in the opening phase of the strikes. That does not prove, in the public record, that Panjaki personally commanded every Handala operation. It does support a more careful formulation: Handala belongs to, or operates inside, a broader MOIS-linked ecosystem whose public personas persisted after senior intelligence figures were reportedly killed.
The resilience was visible almost immediately. A day after the DOJ and FBI domain seizures, Reuters reported that the Iranian government-linked hacking unit’s website was back online. That same Reuters story said DOJ described Handala as one of several public personas used by a hacking unit operating under MOIS as part of psychological operations. In other words: the takedown interrupted infrastructure, not the operating model.
Then came the breach of FBI Director Kash Patel’s personal email. On March 27, Reuters reported that Iran-linked hackers had broken into Patel’s personal inbox and published photographs and documents online; the bureau said the information was historical and did not involve government data. WIRED framed the same incident as a breach of Patel’s personal email, not the FBI’s systems.
The symbolism was obvious. The same ecosystem whose domains had just been seized by DOJ was able to reappear and claim an intrusion into the personal communications of the FBI director. The public evidence does not prove every technical detail of the compromise. But the timing and target fit the pattern: embarrassment, intimidation and psychological effect layered on top of cyber access.
Handala’s campaign then moved from corporate disruption and official embarrassment into direct threats against identifiable people. On March 26, Cybernews reported that Handala had leaked names, identification numbers, passport details, residences and service bases for 28 Lockheed Martin engineers allegedly working in Israel. Cybersecurity Dive separately reported that Iran-linked actors’ claims about Lockheed data were raising questions about veracity and tactics, and noted that Handala had allegedly doxxed Lockheed Martin engineers and threatened them to leave Israel within 48 hours. The caution is important: the leak was reported as a claim and not all underlying data has been publicly authenticated. The tactic, however, was consistent with Handala’s documented pattern of publishing personal data to frighten targets.
By late April, the target set had widened to U.S. service members. Stars and Stripes reported that U.S. service members assigned to units in the Middle East received WhatsApp messages signed by Handala warning that they were under surveillance and would be targeted by drones and missiles. The outlet reviewed messages sent to two service members stationed in Bahrain, which hosts U.S. Naval Forces Central Command. The same report said Handala claimed on Telegram to have published the personal details of 2,379 U.S. Marines stationed in the Persian Gulf. SecurityWeek summarized the episode as an influence campaign against U.S. troops in Bahrain and repeated that the claim about 2,379 Marines came from the group’s Telegram channel.
That is not simply a cyber story. It is a cyber-enabled targeting and intimidation story. The data leak, the direct message, the missile threat and the public boast work together. The goal is not only access. It is to make the target feel seen, located and personally vulnerable.
At the same time, U.S. agencies were warning that Iranian-affiliated actors were probing and disrupting operational technology inside civilian infrastructure. An April 7 joint advisory from the FBI, CISA, NSA, EPA, the Department of Energy and U.S. Cyber Command warned that Iran-affiliated actors were exploiting internet-facing operational technology devices, including Rockwell Automation/Allen-Bradley programmable logic controllers, across multiple critical-infrastructure sectors. The advisory said the activity had led to PLC disruptions through malicious interactions with project files and manipulation of data on HMI and SCADA displays, causing operational disruption and financial loss in some cases.
The EPA press release announcing the advisory emphasized water systems, saying U.S. organizations were experiencing exploitation and, in some cases, disruption of operational technology at drinking-water and wastewater systems. This is where the public script should be tightened: the advisory does not say attackers were merely “lying in wait” inside every water plant. It says they were exploiting exposed operational technology and, in some cases, causing disruption. That is alarming without embellishment.
The most revealing confirmation may be the least dramatic-sounding one. On May 28, Reuters reported that U.S. military personnel deployed to war zones had been targeted using commercially available location data. Reuters cited a letter in which U.S. Central Command said it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater. CENTCOM did not publicly name Iran or Handala. But the disclosure landed in the middle of a Gulf confrontation with Iran, and the lawmakers who pressed the Pentagon described it as the first official confirmation that U.S. forces had been targeted in an active war zone using this type of data.
This matters because the “weapon” was not a classified implant. It was the data economy. Reuters described location data as information typically collected from smartphones or devices by apps or service providers, then sold through data brokers and intermediaries. That means the same ecosystem that powers targeted advertising can also reveal troop movement, congregation points and patterns of life. In the logic of modern asymmetric conflict, ad-tech exhaust becomes targeting intelligence.
By May, outside researchers were explicitly warning that Handala was no longer just a hack-and-leak persona. Recorded Future’s Insikt Group assessed that MOIS had likely broadened the Handala brand to encompass external physical and influence operations targeting U.S. and Israeli interests. The report said this consolidation could amplify cyber and physical threats, particularly against law-enforcement, military and intelligence personnel. That analysis helps explain why the Stryker wipe, the Lockheed doxxing, the Marine WhatsApp messages, the Patel breach and the location-data warning should not be read as isolated episodes.
They are not identical operations. Some are officially confirmed; some are adversary claims; some are security-research assessments. But they share a strategic logic: use data, identity, access and ordinary platforms to impose psychological cost. The operation does not need to destroy a power grid to matter. It only needs to show that hospital supply chains, personal inboxes, defense engineers, deployed Marines and critical infrastructure operators are all reachable.
The cyber front also appears designed to absorb punishment. Commanders can be killed. Domains can be seized. Accounts can be frozen. Leak sites can move. The operational persona survives because its infrastructure is cheap, replaceable and performative. The public-facing brand is itself part of the weapon.
Even Israeli officials now describe the cyber conflict as persistent beyond kinetic pauses. On June 29, Reuters reported that Israel’s cyber chief said Iranian cyberattacks against Israel had surged in 2026, with June hostile cyber incidents rising to about 4,800 compared with roughly 1,600 in June 2025. He added that in cyberspace there is no ceasefire. That line captures the larger issue: the digital front does not end when missiles stop flying.
The clean version is this: since the February 28 U.S.-Israel strikes, Iran-linked cyber and influence actors have run a parallel campaign against U.S., Israeli, military, medical and critical-infrastructure targets. The most clearly documented private-sector case is Stryker, where the company confirmed a global Microsoft-environment disruption and Handala claimed responsibility. Official U.S. documents tie Handala-linked domains to MOIS. Security researchers connect Handala to Void Manticore/Banished Kitten. U.S. agencies warned of Iranian-affiliated exploitation of operational technology in water, energy and municipal systems. U.S. service members in Bahrain received direct threatening messages signed by Handala. CENTCOM confirmed reports that adversaries used commercially available location data to target or surveil U.S. personnel in theater.
The careful version is just as important: not every number is verified. Handala’s claim of 200,000 wiped devices and 79 countries should be attributed to Handala. The Lockheed data leak should be described as alleged unless independently authenticated. The critical-infrastructure advisory describes exploitation and some disruption, not a proven sleeper campaign inside every facility. CENTCOM confirmed adversary exploitation of commercial location data, but did not publicly name Iran or Handala in that disclosure.
But the bottom line survives those caveats. The overlooked story is not a single spectacular hack. It is the accumulation of smaller, cheaper, deniable and repeatable operations that turn normal commercial systems into instruments of state pressure. Microsoft device management. Data brokers. WhatsApp. Telegram. Leak sites. Exposed PLCs. Personal email accounts. None of them is exotic. That is precisely why the campaign matters.
Iran’s response was not only fired through the sky. Part of it moved through the infrastructure of ordinary digital life - the systems companies buy to manage devices, the apps people use to communicate, the brokers that sell location trails, and the public platforms that turn stolen data into fear. This story has been visible in fragments. Put together, it shows a cyber campaign built not just to hit, but to haunt.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.