An Iran-linked Pay2Key ransomware operation targeted a U.S. healthcare organization after compromising an administrative account and remaining in the environment for several days before encrypting systems. Investigators from Beazley Security and Halcyon said the attackers also cleared activity and event logs in an apparent effort to erase evidence, and found no signs of data exfiltration despite earlier U.S. intelligence linking Pay2Key primarily to information theft.
Researchers said the intrusion reflects a more destructive and covert use of Pay2Key amid heightened U.S.-Iran military tensions, with the group increasingly assessed as pursuing strategic disruption rather than purely financial gain. Halcyon warned that additional U.S. organizations may already have been affected by Iranian cyber activity, including ransomware, wiper-style attacks, and efforts to exploit unpatched vulnerabilities, while Pay2Key has also expanded as a ransomware-as-a-service operation with recruitment on Russian cybercrime forums, roughly 170 attributed victims, and about $8 million in ransom payments since summer 2025.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Beazley Security and the Halcyon Ransomware Research Center disclosed their investigation linking the late-February attack on a U.S. healthcare organization to an Iranian ransomware gang tied to Pay2Key, and highlighted the group's more covert and destructive tradecraft.
Days after the initial compromise, the attackers encrypted the healthcare organization's environment with Pay2Key ransomware and attempted to erase evidence by deleting activity and event logs. Investigators found no evidence of data exfiltration in this incident.
In late February 2026, attackers linked to the Iran-associated Pay2Key operation gained access to a U.S. healthcare organization by compromising an administrative account and remained in the environment for several days.
Researchers assessed that Pay2Key activity increased following the U.S.-Iran military conflict, suggesting a shift toward more strategic and destructive operations beyond typical profit-driven ransomware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcelabs.beazley.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.