


Handala hijacks cloud admin accounts to wipe devices at scale. See how this Iran-linked group operates and how to stop it.
Get Guide
Success here means containing the Intune or Entra ID admin compromise before a remote-wipe command goes out, not restoring devices after the fact.
This is state-linked destruction, not opportunistic crime. This guide covers the privileged access controls that stop a single compromised admin account taking out your fleet.
Handala uses legitimate MDM commands, not custom malware. This guide explains why standard endpoint detection misses this and what closes the gap.
Global Admin access is the whole attack. This guide sets out the segregation and monitoring that keeps that access from being hijacked.