Intel-owned AI chip developer Habana Labs was breached by the Pay2Key ransomware operation, which stole data and began leaking it publicly after giving the company a reported 72-hour deadline to halt the release. Material described as exposed included Windows domain account information, DNS zone data, a file listing from Habana Labs' Gerrit code review system, business documents, and images related to source code.
The intrusion was reported amid a broader run of attacks targeting Israeli organizations, and security researchers cited in reporting said Pay2Key appeared focused on disruption as much as financial extortion. Assessments referenced by incident responders and threat research linked the ransomware activity to actors potentially aligned with Iranian interests, underscoring concern that the operation blended data theft, public leaking, and ransomware pressure against Israeli-linked targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Pay2Key was linked to a series of attacks against Israeli businesses, according to reporting cited in the source. Check Point and Profero reported on this wave, and Profero assessed that Iranian threat actors were behind the operation.
Intel acquired Israeli AI processor developer Habana Labs for approximately $2 billion. This acquisition established Habana Labs as an Intel-owned company before the later ransomware incident.
After leaking Habana Labs data, Pay2Key posted a threat stating that the company had 72 hours to stop the leaking process. The source noted that any ransom demand made to Habana Labs was unknown.
Intel-owned Habana Labs suffered a cyberattack in which data was stolen and later leaked by the Pay2Key ransomware operation. The exposed material allegedly included Windows domain account information, DNS zone information, Gerrit file listings, business documents, and source code images.
A separate threat actor, BlackShadow, carried out a cyberattack against Israeli insurance company Shirbit. In that incident, data was stolen and leaked, though the source said it was unknown whether it was linked to Pay2Key.
Israeli media reported that threat actors breached shipping and cargo software company Amital. The breach reportedly enabled a supply-chain attack affecting forty of Amital's clients, and Profero and Security Joes linked related indicators to previous Pay2Key attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.