Latest Internet & Cybersecurity News

đź“…March 12, 2026 at 1:00 PM
Ransomware attacks surged 43% in February; Europol takedown of LeakBase; Iran-linked Handala hackers launched major wiper attack on Stryker amid escalating US-Iran cyber tensions.
1

Ransomware Victims Surge 43% in February 2026

Bitdefender reported 1,194 claimed ransomware victims from February 1-28, a 43% increase from January, driven by inflated claims from 0APT group with 458 victims.Source 1 The Gentlemen ransomware group claimed half of Thailand's victims using BYOVD tactics like ThrottleStop.sys to evade detection and purge logs.Source 1 MDR insights highlight identity-first compromises, VPN credential theft, and fileless attacks as key trends.Source 1

2

Europol Leads Takedown of Stronghold LeakBase Forum

Europol, FBI, and agencies seized LeakBase, a dark web forum with 140,000 users sharing infostealers and leaked data, following RAMP seizure.Source 1 This marks a major blow to cybercrime data sharing platforms.Source 1 The operation underscores international efforts against underground marketplaces.Source 1

3

Iran-Linked Handala Claims Cyberattack on Stryker Corporation

Hacktivist group Handala, tied to Iran's Ministry of Intelligence, claimed a major attack on US medtech firm Stryker, disrupting global networks.Source 2Source 5 The assault used remote wipes on Microsoft Windows devices via Intune, defacing login pages and forcing device disconnections.Source 5Source 7 No ransomware detected, but it escalates tensions post-US strikes on Iran.Source 2

4

Stryker Confirms Global Network Outage from Cyber Incident

Stryker disclosed disruptions to Microsoft systems in an SEC filing, affecting 56,000 employees across 60+ countries.Source 2Source 5 Staff instructed to disconnect devices; recovery timeline unclear, with Cork HQ systems shut down.Source 7Source 8 Attack wiped laptops and phones, prompting building emergency messages.Source 2

5

Handala's Attack Marks First Major US Business Target

Check Point Research notes Handala's Stryker hit as its first against a major US firm, alarming due to healthcare risks to patient safety.Source 5 Group masquerades as pro-Iran hacktivists but linked to state intelligence.Source 5 Follows US-Israel war on Iran since late February, with other groups like Seedworm targeting US networks.Source 5

6

FBI Warns of Potential Iranian Drone Strikes on US West Coast

FBI bulletin to California law enforcement alerts of possible Iranian drone retaliation against US strikes.Source 6 Concerns rise amid Middle East security alerts and reports of Russian drone tech aid to Iran.Source 6 Counter-drone systems and AI monitoring urged to prevent attacks.Source 6

7

Bill Clinton Warns of Escalating US-Iran Cyber War

Clinton discusses Operation Epic Fury's fallout, including Stryker attack and decentralized Iranian proxy ops on Western firms in energy, finance, healthcare.Source 4 Predicts surging oil prices, supply chain disruptions, and cyber conflict spread without rules.Source 4 Notes CISA staffing cuts amid escalation.Source 4

8

CrowdStrike CEO on Iran's Shift to US Company Attacks

Mandiant CEO Kevin Mandia highlights Iran's escalation from ship threats to targeting Stryker and US tech firms.Source 10 Attack on medical giant underscores growing cyber risks to critical sectors.Source 10 Discussions on Fox Business emphasize need for heightened defenses.Source 10

9

Stryker Data Breach Investigation Launched

Reports of March 11 cyberattack disabled thousands of employee devices, prompting class action probes.Source 11 Incident aligns with Handala's claimed wiper operation.Source 11Source 7 Global impact includes international offices halting work.Source 8

10

Cyber Extortion Victims Triple Since 2020

Orange's Security Navigator 2026 reveals cyberextortion victims tripled since 2020, up 44.5% worldwide in 2025.Source 9 Report frames attacks as 'robbery,' highlighting rising threats.Source 9 Ties into broader ransomware and wiper trends seen in recent incidents.Source 9

11

MDR Insights: Identity-First Attacks Dominate February

Bitdefender MDR observed VPN credential theft, remote registry access, RMM tool persistence, and firewall/RDP changes in real incidents.Source 1 Fileless and in-memory execution prevalent among threat actors.Source 1 Shifts reflect evolving tactics in cyber operations.Source 1

Latest Internet & Cybersecurity News | DeckBook AI