Iran-Linked Hackers Pause US Attacks but Keep Targeting Israel

The ceasefire between Iran and the US is a temporary pause in attacks against American targets, not a full stop. Handala, an Iran-linked hacking group, announced it will suspend operations against the US while continuing to target Israel. This means US organizations remain at risk despite diplomatic headlines suggesting reduced cyber threats. Handala has publicly tied its targeting decisions to the ceasefire, confirming ongoing operations against Israeli entities and a temporary halt on US attacks. The group has claimed disruptive actions against the US medical manufacturer Stryker and compromised the personal email of FBI Director Kash Patel. US authorities warn that Iran-aligned hackers have established footholds in industrial control systems critical to infrastructure, increasing the risk to US sectors like healthcare, manufacturing, and government. This campaign update shows that proxy actors can shift their focus geographically without ceasing operations. The ceasefire does not eliminate exposure for US organizations or public officials. The risk to operational technology assets in critical infrastructure persists, underscoring the need for continued vigilance and threat monitoring rather than assuming a reduction in threat activity.

Part of the PlainSec briefing for 2026-04-09

Sources