logo

Iran-linked ransomware gang targeted US healthcare org amid military conflict

ID: 6cf7562a-95e0-553e-b244-1b5a7bdc1112

STIX ID: report--6cf7562a-95e0-553e-b244-1b5a7bdc1112

Feed Name: The Record from Recorded Future News

Threat Score
80/100

Date Published: 2026-03-24

Date Updated: 2026-05-01

...
...

A U.S. healthcare organization was struck in late February by the Pay2Key ransomware; responders observed prior administrative account compromise, encryption, and attempts to clear logs. Investigators found no evidence of data exfiltration in this incident, but Halcyon and Beazley highlight Pay2Key's expanded activity (about 170 victims and ~$8M in ransoms) and potential Iranian government ties that suggest some attacks may be strategically destructive rather than solely financially motivated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.