Your Business Is Not Too Small to Be an Iranian Hacker's Next Target
Groups linked to Iran's intelligence services are not hand-picking victims. They're scanning the internet for any door left unlocked, and a GPS company and a medical-device maker have already paid the price.

Key points
- Handala, a hacker group attributed by the US Justice Department to Iran's Ministry of Intelligence and Security, remotely wiped data from more than 200,000 computer systems at medical-device maker Stryker in March 2025.
- A separate group, Ababil of Minab, broke into Vyncs, a GPS tracking platform used by logistics companies, taking its systems offline and defacing its website.
- The Stryker breach likely began with stolen login credentials bought from criminal marketplaces, not a sophisticated custom attack.
- CVE-2021-22681, a five-year-old flaw in industrial control systems that lets an attacker take remote control without a password, is among the weaknesses these groups have recently used.
- Both attacks show that opportunistic scanning, not targeted intelligence work, is how these groups find their victims.
Forget the image of a government war room selecting enemies of state. The Iranian-linked hacker groups making headlines right now are closer to opportunistic burglars testing every door handle on the street.
They use tools like Shodan, a search engine that maps internet-connected devices, to find systems with weak passwords or unpatched flaws. A law firm with a forgotten remote-access point and a logistics company with outdated software both look equally appealing.
The evidence is in the targets. Stryker, the medical-device manufacturer, isn't a power grid. Vyncs, the GPS platform hit by Ababil of Minab, isn't a water utility. Yet both were breached, and Stryker's manufacturing was disrupted badly enough to affect its first-quarter earnings. When Handala threatened California's water supply in June, forensics found no evidence the group had ever touched operational technology. Commercial targets appear to be easier pickings.
How do these groups actually get in?
Mostly through doors companies forgot they'd left open. Default credentials, the factory-set username and password that ships with a device and never gets changed, are a favourite entry point. So are known software flaws that haven't been patched in years.
Joe Slowik, Director of Cybersecurity Alerting Strategy at Dataminr, writing for Dark Reading, calls these groups "largely opportunistic." Stryker's credentials were almost certainly purchased from a criminal marketplace where stolen logins sell cheaply. No elaborate espionage required.
The attacks often look unimpressive: a screenshot of an industrial device posted to Telegram, a defaced website, a brief outage. Easy to dismiss. That's the mistake.
An open door doesn't care who walks through it. The weakness that let a low-skill group post a screenshot is the same one a more patient, more capable attacker could use to cause serious harm.
Should you worry?
Yes, but channel that worry into four concrete steps.
Find out what your organisation actually exposes to the internet. Internal asset lists are frequently wrong, and forgotten remote-access points are the most common entry route. Turn on multi-factor authentication (MFA, a second login check beyond just a password) for every externally reachable system, and confirm no device still runs on its factory-default password. Patch old flaws before new ones arrive: the vulnerabilities these groups exploit aren't novel, they're just unaddressed. Finally, watch the channels they actually use. A Telegram post claiming credit can appear within hours of a breach, well before any official advisory lands.
Most of this activity sits in the "moderately disruptive" range today. The real lesson isn't the damage done so far. It's the map of unlocked doors these incidents leave behind for whoever comes next.



