惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
雷峰网
雷峰网
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
M
MIT News - Artificial intelligence
WordPress大学
WordPress大学
MongoDB | Blog
MongoDB | Blog
V
V2EX
博客园 - 【当耐特】
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
Martin Fowler
Martin Fowler
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
B
Blog
V
Visual Studio Blog
D
DataBreaches.Net
C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
Iran-linked cyber crew claims hit on US med-tech firm
Jessica Lyons Jessica Lyons · 2026-03-12 · via The Register - Security: Cyber-crime

Cyber-crime

Meanwhile, Verifone says 'no evidence' to support the digital intruders' claims

A hacking crew with ties to Iran's intelligence agency claimed to be behind a global network outage at med-tech firm Stryker on Wednesday, and said the cyberattack was in response to the US-Israel airstrikes.

If true, the incident would mark a major escalation in the war's cyber component, and could be the first destructive cyberattack linked directly to the current war to hit a major US company.

In a Wednesday statement, Stryker said it was "experiencing a global network disruption to our Microsoft environment as a result of a cyber attack," adding that there is no indication of a ransomware infection or any other type of malware deployment. 

Initial reports from Irish news outlets indicated that Stryker employees' devices, including their personal phones, were wiped in the attack.

The medical equipment maker said that it believes the security incident has been contained, and continues investigating the impact on its systems. 

"We are working shoulder-to-shoulder with our public- and private‑sector partners as we continue to uncover relevant information and provide technical assistance for the targeted attack on Stryker, while steadfastly standing at the ready to defend our nation’s critical infrastructure," CISA Acting Director Nick Andersen told The Register. "As with all cyber incidents, we have launched an investigation into this matter."

Stryker did not immediately respond to The Register's questions about the cyberattack, including whether Handala, an Iranian hacktivist group believed to be a front for the Ministry of Intelligence and Security (MOIS), was responsible for the incident.

"If accurate, Handala's alleged disruptive attack on Stryker marks a significant escalation - this is the first time this Iranian-backed threat actor has disruptively targeted a major US enterprise," Check Point Research threat intelligence group manager Sergey Shykevich told The Register

"The fact that they've set their sights on a major medical device company is particularly alarming," Shykevich added. "Critical healthcare infrastructure represents a high-value, high-impact target: disruption doesn't just mean data loss, it can mean patient safety. This should serve as a wake-up call for the entire medtech sector to urgently reassess their threat landscape -  nation-state actors are no longer someone else's problem."

Handala, in a lengthy post on its now-deleted Telegram channel and also shared on X, claimed it wiped more than 200,000 systems and servers, and stole 50 TB of "critical data." The group said the hack was "in retaliation for the brutal attack on the Minab school and in response to ongoing cyber assaults against the infrastructure of the Axis of Resistance." 

At least 175 people, most of them children, were reportedly killed in what appears to have been a Tomahawk missile strike on an Iranian elementary school in Minab when the US military may have mistakenly targeted the area. The school was adjacent to, and may once have been part of, an Iranian military compound.

The crew also claimed to have breached payment device maker Verifone, and released screenshots (seen by The Register) that appeared to show the company's internal systems with a Handala Hack logo overlay.

Verifone, in a statement to The Register, refuted the hacktivists' claims. 

"We have observed recent allegations on March 11, 2026 from threat actors claiming an intrusion into our systems in Israel," a Verifone spokesperson said. "Verifone has found no evidence of any incident related to this claim and has no service disruption to our clients." ®