• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Iran’s Pay2Key Ran a Criminal Side Business on Russian Forums While Attacking U.S. Healthcare

  • SOFX Staff Writer
  • March 26, 2026
Lightspring / Shutterstock
Share on FacebookShare on TwitterLinkedIn

An Iranian government-linked ransomware group known as Pay2Key attacked an unnamed U.S. healthcare organization in late February, locking down the institution’s systems within three hours while stealing no data and issuing no ransom demand, according to a report published by Halcyon Ransomware Research Center.

🚨 #Breaking Newz Alert 🚨
“Iranian State-Backed Hackers Deploy Pay2Key Ransomware Against U.S. Healthcare Organization”
➡️ New reports from Tuesday, March 24, 2026, confirm that an unnamed U.S. healthcare group was hit in late February by the Iranian Pay2Key ransomware gang.
➡️… pic.twitter.com/1Sfqi36EQp

— BreakinNewz (@BreakinNewz01) March 24, 2026


Beazley Security handled the initial response before calling in Halcyon researchers to examine the malware. Investigators found the attackers had compromised an administrator’s account on the victim’s network several days before deploying the ransomware, then cleared event logs to erase all traces of their activity after encryption completed.

The absence of a data theft attempt and a ransom demand are significant departures from Pay2Key’s documented pattern. U.S. intelligence agencies previously assessed the group’s attacks as primarily conducted for information theft.

Halcyon said Pay2Key “does not always appear to prioritize extortion and financial gain over the destruction of victim environments for strategic impact.”

“This pattern suggests motivations that extend well beyond typical financially driven ransomware operations,” Halcyon researchers said.

Cynthia Kaiser, senior vice president at Halcyon’s Ransomware Research Center and a former deputy assistant director in the FBI’s Cyber Division, said the attack’s timing, concurrent with the start of military conflict between the U.S. and Iran, complicates any straightforward read of intent.

“Is the group just seeking to maximize money among chaos? This is a group that does work on behalf of the government, but not always,” Kaiser said.

The Halcyon report also documents Pay2Key’s parallel effort to build a commercial criminal operation. The group marketed itself on Russian cybercriminal forums beginning in the summer of 2025, raised affiliate cuts from 70% to 80%, and at one point offered the entire ransomware-as-a-service (RaaS) platform for sale at 0.15 BTC.

Cybersecurity firm Morphisec tracked 51 ransom payments to the group over a four-month stretch that summer, totaling roughly $4 million. The group has since logged 170 victims and $8 million in total ransom payments.

Halcyon noted the group’s ties to Russian criminal networks raise “unresolved questions about the current ownership, operational control, and future trajectory of the group’s RaaS platform.” Kaiser said the sale offer was likely a smokescreen, given Pay2Key’s continued role in Iranian kinetic operations.

The healthcare attack preceded a separate incident at Stryker, a U.S. medical device company, in which an Iranian group known as Handala wiped approximately 200,000 devices. The FBI attributed that operation to Iranian intelligence.

Iranian hackers say they wiped 200,000 devices at US medical company $SYK Stryker, forcing closure of offices

An Iran-linked hacking group (Handala) claimed it had extracted 50 terabytes of data in retaliation for military strikes (girl’s school)https://t.co/3rBs2odYqD pic.twitter.com/nBR5o3Wrca

— Special Situations 🌐 Research Newsletter (Jay) (@SpecialSitsNews) March 11, 2026


“Some attacks may have more limited impact, and so there isn’t going to be as much publicity around that, but you have to assume that Iran is looking for targets, seeking out what they can do,” Kaiser said. “And my assumption is that it’s a combination of wiper attacks, ransomware attacks, and attempting to target critical infrastructure through unpatched vulnerabilities.”

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

US Army Special Operations Soldier Arrested for $400K Polymarket Bet on Maduro Raid

US Army Special Operations Soldier Arrested for $400K Polymarket Bet on Maduro Raid

by SOFX Staff Writer
April 24, 2026
4

The Department of Justice arrested Army Master Sgt. Gannon Ken Van Dyke, 38, on charges that he used classified intelligence...

EU Declared Age App “Ready” While GitHub Flagged it Unfit, Then Hackers Bypassed It in 2 Minutes

EU Declared Age App “Ready” While GitHub Flagged it Unfit, Then Hackers Bypassed It in 2 Minutes

by SOFX Staff Writer
April 20, 2026
0

Security researchers bypassed the European Commission's new age verification app in under two minutes on April 16, days after Commission...

CIA Officers Die in Mexico Drug Raid Crash as Agency Veteran Ambassador Calls Them Embassy Staff

CIA Officers Die in Mexico Drug Raid Crash as Agency Veteran Ambassador Calls Them Embassy Staff

by SOFX Staff Writer
April 22, 2026
1

Two Central Intelligence Agency (CIA) officers were killed in a vehicle crash in Chihuahua, Mexico, on April 19 while returning...

Video Shows Iranian Commandos Storming Container Ships in Strait of Hormuz

Video Shows Iranian Commandos Storming Container Ships in Strait of Hormuz

by SOFX Staff Writer
April 24, 2026
3

Iran has released a new video purportedly showing the seizure of two commercial container ships, the MSC Francesca and the...

ADVERTISEMENT
ADVERTISEMENT
Next Post
B-2 Spirit Bombers Depart for Iran with Unidentified Wing Patches Days After Key Comms Upgrade

B-2 Spirit Bombers Depart for Iran with Unidentified Wing Patches Days After Key Comms Upgrade

Pentagon Targets THAAD Supply Chain Bottleneck With Trio of Munitions Production Agreements

Pentagon Targets THAAD Supply Chain Bottleneck With Trio of Munitions Production Agreements

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz