WASHINGTON: An Iran-linked hacking group claimed responsibility on Wednesday for a sweeping cyberattack on US medical technology giant Stryker, saying it had wiped more than 200,000 systems and extracted 50 terabytes of data in retaliation for military strikes on Iran.
“Our major cyber operation has been executed with complete success,” Handala said in a statement, describing the attack as retaliation for what it called “the brutal attack on the Minab school” and for “ongoing cyber assaults against the infrastructure of the Axis of Resistance.”
The group said it had shut down Stryker offices in 79 countries and that all extracted data was “now in the hands of the free people of the world.”
It issued an open warning to what it described as “Zionist leaders and their lobbies,” adding: “This is only the beginning of a new chapter in cyber warfare.”
Founded in Kalamazoo, Michigan, Stryker is a global medical device giant with some 56,000 employees and $25.12 billion in 2025 revenues, making everything from orthopedic implants and surgical instruments to hospital beds and robotic surgery systems.
The Handala group later posted that it had also carried out an attack on Verifone, which specializes in electronic and point-of-sale payments.
“This attack is a decisive and direct response to the Zionist regime’s airstrikes targeting banking infrastructure,” it wrote about Verifone Wednesday.
“Every blow will be met with an even greater response.”
The outages began shortly after 0400 GMT on Wednesday, the Wall Street Journal reported, citing people familiar with the matter. Windows devices — including laptops and mobile phones connected to Stryker’s networks — were remotely wiped.
- “Hacktivist” group -
Claiming several cyberattacks on American and Israeli infrastructure and businesses, the Handala group has been particularly active since the beginning of the war against Iran, openly supporting Tehran in the conflict.
A recently-created website lists the actions for which Handala asserts responsibility.
While Handala’s claims are making waves now, its first publicly-known activities date back to late 2023, according to several observers of the cybercrime world.
Named for a cartoon character representing the Palestinian people, Handala was at first classified as a “hacktivist” group supporting their cause.
Like many cybercrime groups, other outfits with which it is frequently associated may simply be aliases.
But many experts are now convinced it is tied to the Iranian state.
Handala is “the most prominent Iranian persona” in the hacktivist world, according to a note published in late February by the research arm of American cybersecurity firm Palo Alto Networks.
“They are the most notorious group affiliated with the Iranian regime,” Gil Messing of Israeli cybersecurity company Check Point said Wednesday.
“We have been tracking them for years and believe they operate on behalf of (Iran’s) ministry of intelligence and security.”
The Handala group appears to use a variety of methods.
It has claimed attacks on infrastructure as well as posting personal information belonging to Israeli air force personnel online.
“Threat actors such as Handala... have prioritized the Israeli defense industrial base,” Google’s Threat Intelligence arm said in February.
“The objective of these campaigns is not merely disruption but the degradation of Israel’s national security apparatus through the exposure of military capabilities, the intimidation of defense sector employees... and the erosion of public trust in the security establishment,” the company added.



