Iran-Aligned Actors Escalate Cyber Attacks on US, Allies
Iran-linked state actors and criminal affiliates have ramped DDoS, data‑wiping, and intrusion campaigns against government, energy, and telecommunications targets. US intelligence and security vendors warn the threat environment is heightened after recent US‑Israeli strikes. Some MOIS‑associated groups are using criminal malware, ransomware branding, and affiliate ecosystems to expand reach and obscure attribution.
Iran-linked ransomware gang targeted US healthcare org amid military conflict
The incident responders noted that there was no evidence that data was exfiltrated during the intrusion — an unusual development considering U.S. intelligence agencies previously said Pay2Key attacks were largely conducted for information theft.