The Justice Department shut down four websites it says Iranian government operatives used to claim credit for cyberattacks, spread stolen data, and threaten regime critics living in the United States. FBI Director Kash Patel announced the action Thursday, calling the sites "pillars" of Tehran's online intimidation campaign.
The seized domains corresponded to three hacking groups, Handala, Homeland Justice, and Karma Below, that the FBI says are all run by Iran's Ministry of Intelligence and Security. In court papers, the bureau described a coordinated operation that deployed "custom-built malware" against targets ranging from a major American medical technology company to the Albanian government to individual Iranian-American journalists.
The takedown matters for two reasons. First, it shows Tehran running an aggressive, multi-front cyber war against the United States and its allies, one that reaches into American neighborhoods to menace dissidents. Second, it signals that the current DOJ and FBI leadership intend to treat foreign influence operations as a law-enforcement priority, a shift from years in which intelligence officials were accused of burying evidence of foreign meddling when it cut against preferred policy narratives.
CBS News reported that the Justice Department described the websites as tools for "hacking and transnational repression schemes" and "attempted psychological operations targeting adversaries of the regime." The groups behind them did not just brag about break-ins. They weaponized stolen information to terrorize people on American soil.
Handala's sites allegedly served the widest range of purposes. The DOJ said the group used them to take credit for "a destructive malware attack against a U.S.-based multinational medical technologies firm." In recent weeks, the same sites claimed responsibility for a hack against members of a Hasidic Jewish community and published names and personal information for Israeli Defense Forces and Israeli government employees, encouraging supporters of Iran to "respond" to IDF personnel.
Earlier this month, Handala was accused of emailing death threats to Iranian dissidents and journalists. At least one target lived in the United States. The Justice Department disclosed that one alleged message claimed Handala was "partners" with Mexico's Jalisco New Generation Cartel and offered a "$250,000 reward for the target's death."
That last detail deserves a pause. A state-sponsored Iranian hacking front allegedly invoked a Mexican drug cartel to make its death threat more credible. If accurate, it illustrates how hostile foreign actors study American vulnerabilities, including the border chaos and cartel violence that dominate domestic headlines, and fold them into their intimidation playbook.
The medical technology firm referenced by the DOJ appears to be Michigan-based Stryker, which reported a cyberattack last week that caused what the company called "global disruption." Stryker said the hack was limited to its internal Microsoft systems and did not affect its products, including medical implants. Cybersecurity expert Brian Krebs wrote in a blog post last week that Handala appeared to claim responsibility for the Stryker incident.
Stryker is no small outfit. It manufactures implants and surgical equipment used in hospitals around the world. A cyberattack that disrupts its internal systems, even without touching products, can ripple through supply chains and operating rooms. That Iran's intelligence apparatus would target a company like this shows the regime is not simply harassing dissidents on social media. It is going after critical American infrastructure.
One of the shuttered sites belonged to Homeland Justice, which the DOJ says used it to take credit for a highly publicized 2022 hack against the Albanian government. FBI court papers revealed that an undercover agent bought a trove of stolen data from a representative of Homeland Justice, including Albanian ID cards that appeared related to the 2022 incident.
The undercover purchase is a significant detail. It means the FBI did not merely observe these groups from a distance. Agents infiltrated the operation closely enough to conduct a transaction with someone representing one of the fronts. That kind of work takes time, tradecraft, and institutional commitment, the sort of focused counterintelligence effort that critics have long argued the bureau neglected while it chased domestic political targets. The question of how the FBI allocated its investigative resources in recent years remains a sore point for many Americans who want the bureau focused on genuine foreign threats.
Former Cybersecurity and Infrastructure Security Agency Director Chris Krebs, now a CBS News contributor, told the network that "the cyber front of this conflict has officially opened." On "CBS Mornings," Krebs said the line between Handala and the Iranian government is "really blurry."
"It's almost an all-hands-on-deck approach by Iran. So all of their groups, whether they're directly related to the military, the intelligence services or their proxies, contractors, hacktivists, sympathizers, whatever you want to call them, they're all going for targets."
That assessment tracks with the DOJ's own framing. The FBI's court papers assert that all three groups, Handala, Homeland Justice, and Karma Below, answer to Iran's Ministry of Intelligence and Security. They share tactics and tools. The separate branding is a mask, not a meaningful organizational distinction.
U.S. military officials have said that in the early hours of the broader conflict, cyber operations helped degrade Iran's communications. Tehran's response has been to unleash its own digital proxies against softer targets: hospitals, dissidents, religious communities, allied governments. The pattern is familiar. Regimes that cannot match American military power look for asymmetric pressure points. Cyberspace offers plenty.
Among the most disturbing elements of the DOJ's disclosure is the targeting of Iranian-American journalist and regime critic Masih Alinejad, who has been the subject of multiple thwarted plots to kidnap or murder her. The broader campaign of threats against dissidents and journalists living in the United States represents a direct challenge to American sovereignty. Foreign governments do not get to run hit squads, physical or digital, inside our borders.
The $250,000 bounty message, the invocation of a Mexican cartel, the publication of personal data meant to incite violence, these are not abstract cyber nuisances. They are acts of transnational repression carried out by a hostile state against people who live under the protection of the U.S. Constitution. Every one of those targets has the same right to speak freely and live safely that every American citizen enjoys.
FBI Director Patel was blunt about the operation's purpose and its trajectory:
"Iran thought they could hide behind fake websites and keyboard threats to terrorize Americans and silence dissidents. We took down four of their operation's pillars and we're not done."
The "we're not done" line carries weight. It signals that the current FBI leadership views this as the opening move, not the final one. For an agency that has spent years under bipartisan criticism, from the right for political bias, from the left for surveillance overreach, a clean, publicly announced takedown of hostile foreign cyber infrastructure is the kind of mission that can rebuild credibility.
The Trump administration has shown a willingness to use federal authority aggressively when it identifies threats to American interests. Separately, Fox News reported that the administration briefly paused most federal government websites to scrub content described as contrary to the president's agenda, a move that, whatever one thinks of its scope, reflects a White House comfortable wielding digital tools to enforce policy priorities. Applying that same energy against foreign adversaries running propaganda and intimidation campaigns on American soil is a natural and welcome extension.
The seizure also raises questions about what previous administrations knew and when. If the FBI had enough intelligence to conduct undercover purchases from Homeland Justice operatives, how long had these sites been active? Were earlier requests to shut them down delayed or deprioritized? The DOJ's announcement does not answer those questions, but they deserve answers, especially given the bureau's uneven track record in handling politically sensitive foreign-linked investigations.
Shuttering four websites is a start, not a solution. Iran's intelligence services will spin up new domains, new fronts, new names. The value of the DOJ's action lies partly in the public exposure, naming the Ministry of Intelligence and Security, laying out the groups' shared infrastructure, and putting the regime on notice that American law enforcement is watching and willing to act.
But exposure alone does not deter a regime that has tried to kidnap journalists on American streets. Sustained enforcement, criminal indictments of identifiable operatives, and diplomatic consequences are the tools that impose real costs. The FBI's court papers and the undercover operation suggest the bureau has the intelligence to pursue those next steps. Whether it will depends on whether the political will holds.
For Iranian-Americans who fled the regime and built lives here, and for every American whose hospital equipment or personal data sits in the crosshairs of Tehran's hackers, the message should be clear: the federal government's job is to protect them. Four websites are down. The test is what happens when Iran puts up four more.