Overview
- The Justice Department says Iran’s Ministry of Intelligence and Security operated Justicehomeland.org, Handala-Hack.to, Karmabelow80.org, and Handala-Redwanted.to, which now display FBI seizure notices.
- Officials say the Handala Hack persona used the sites to claim a March 11 destructive malware attack on a U.S.-based multinational medical technologies firm.
- Court filings describe posts that exposed sensitive data for about 190 people tied to the Israeli military or government and urged violence, alongside a claim of stealing 851 gigabytes from the Sanzer Hasidic community.
- FBI investigators attribute death-threat emails to an account linked to the domains that offered $250,000 bounties and referenced alleged CJNG cartel partners.
- Prosecutors cite shared infrastructure and a common playbook connecting the sites, note prior 2022 leak claims targeting Albania, and say the case is being handled by FBI Baltimore with NSD and the Maryland U.S. Attorney’s Office, as State’s Rewards for Justice offers up to $10 million.