Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24839 published victims and 72 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Breach House as a ransomware group with 24839 published victims.
United States is currently the most targeted country in this dataset.
72 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 58 87.9%
- Pending 7 10.6%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (72)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 71 | Onion service | Up checked 2h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 68 | Onion service | Up checked 2h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 69 | Onion service | Up checked 2h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 66 | Onion service | Up checked 2h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 67 | Onion service | Up checked 2h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 63 | Onion service | Up checked 2h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 65 | Onion service | Up checked 2h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 64 | Onion service | Up checked 2h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 61 | Onion service | Up checked 2h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 58 | Onion service | Up checked 2h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 59 | Onion service | Up checked 2h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 60 | Onion service | Up checked 2h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 55 | Onion service | Up checked 2h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 57 | Onion service | Up checked 2h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 56 | Onion service | Up checked 2h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 54 | Onion service | Up checked 2h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 53 | Onion service | Up checked 2h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 51 | Onion service | Up checked 2h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 50 | Onion service | Up checked 2h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 45 | Onion service | Up checked 2h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 43 | Onion service | Up checked 2h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 72 | Onion service | Down checked 2h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Down checked 2h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 62 | Onion service | Down checked 2h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 48 | Onion service | Down checked 2h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 49 | Onion service | Down checked 2h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 2h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 46 | Onion service | Down checked 2h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 44 | Onion service | Down checked 2h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 42 | Onion service | Down checked 2h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 2h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 40 | Onion service | Down checked 2h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 36 | Onion service | Down checked 2h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 38 | Onion service | Down checked 2h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 39 | Onion service | Down checked 2h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 37 | Onion service | Down checked 2h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 35 | Onion service | Down checked 2h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 32 | Onion service | Down checked 2h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 33 | Onion service | Down checked 2h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 34 | Onion service | Down checked 2h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 29 | Onion service | Down checked 2h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 31 | Onion service | Down checked 2h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 30 | Onion service | Down checked 2h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 27 | Onion service | Down checked 2h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 26 | Onion service | Down checked 2h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 28 | Onion service | Down checked 2h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 24 | Onion service | Down checked 2h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 23 | Onion service | Down checked 2h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 25 | Onion service | Down checked 2h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 22 | Onion service | Down checked 2h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 21 | Onion service | Down checked 2h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 20 | Onion service | Down checked 2h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 2h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 2h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 2h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 16 | Onion service | Down checked 2h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 15 | Onion service | Down checked 2h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 13 | Onion service | Down checked 2h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 2h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 11 | Onion service | Down checked 2h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 12 | Onion service | Down checked 2h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 10 | Onion service | Down checked 2h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 7 | Onion service | Down checked 2h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 5 | Onion service | Down checked 2h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 4 | Onion service | Down checked 2h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 48
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Finance / Legal / Insurance 17
- Public Sector 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24839)
Search, filter and paginate the victim timeline for Interlock. Showing 14001–14100 of 24839.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | City of St Paul id32837 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and digital infrastructure, providing official resources and administrative offerings for its designated community and functions. As a public sector organization, it represents a critical infrastructure asset within the United States government ecosystem, where cyber threats and ransomware incidents carry significant operational and national security implications. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically associated with the interlock threat actor. The inclusion reflects its documented relationship within threat actor activity targeting public sector environments. This entry serves as a reference point for security professionals monitoring ransomware exposure across government-related domains. |
||||||
| Ransomware | City of St Paul id32837 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing government or public-service operations where digital infrastructure resilience is critical. The entity functions within public-sector offerings, supporting official services and administrative functions for its designated locality or jurisdiction. Within this threat-intelligence index, stpaul.gov is formally listed as a ransomware victim associated with the threat actor interlock. This classification reflects observed threat activity targeting public-sector environments and underscores the importance of continuous monitoring for entities in sensitive government sectors. The entry provides neutral context for security professionals assessing ransomware exposure across public infrastructure. |
||||||
| Ransomware | City of St Paul id32837 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity providing government-related services and digital infrastructure within the state of Pennsylvania. The domain operates under a public sector classification, reflecting its role in delivering official governmental functions and resources to citizens. Within the threat-intelligence index catalog, this entity is formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the cybersecurity assessment linking the domain to malicious activity attributed to interlock, contributing to broader awareness of Public Sector exposure. The entry documents the relationship without disclosing unverified incident details, maintaining factual neutrality per catalog standards. |
||||||
| Ransomware | City of St Paul id32837 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative offerings, commonly associated with municipal or regional public functions. As cataloged in this threat-intelligence index under the ransomware victim listing type, the entity is linked to the threat actor interlock, with the incident contextualized within the US public sector environment. This description maintains neutrality regarding confirmed breach details, avoiding speculation on data theft, ransom terms, or specific compromise metrics. The entry serves to document the relationship between the entity, its sector classification, and the associated threat actor for analytical and informational purposes. |
||||||
| Ransomware | City of St Paul id32837 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US Public Sector, representing a government or public service entity offering web-based administrative and informational functions. As a ransomware victim, this listing reflects an incident where the entity was targeted by malicious cyber activity linked to the interlock threat actor group. The catalog entry documents the entity's sector classification, geographic context, and the specific threat intelligence association without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. This entry serves threat-intelligence professionals seeking to understand public sector exposure patterns and actor-targeted environments. |
||||||
| Ransomware | City of St Paul id32837 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing government-related services and digital infrastructure within the public administration domain. As a victim listed under the ransomware incident classification, it is documented within the threat-intelligence index as associated with the interlock threat actor. This entry reflects the cybersecurity posture and incident correlation of an organization operating in the public sector across the United States. The catalog description maintains factual neutrality regarding the event while contextualizing its sector, geographic location, and threat actor linkage for analytical purposes. |
||||||
| Ransomware | City of St Paul id32840 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative functions. Its domain serves official organizational purposes tied to public infrastructure and sector-specific digital services. Within this threat-intelligence index, stpaul.gov is cataloged as a ransomware victim associated with the threat actor interlock. This listing reflects the entity's inclusion in incident-linked intelligence records without disclosing unverified breach details. The entry supports security teams monitoring public-sector exposure and interlock-related activity across government environments. |
||||||
| Ransomware | City of St Paul id32847 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing government or public service operations. Its primary role involves providing public-facing services, administrative functions, or information resources aligned with public sector infrastructure. Within threat-intelligence indexing frameworks, this entity is cataloged specifically as a ransomware victim. The association connects stpaul.gov to the threat actor interlock, indicating a cybersecurity event where ransomware activity was observed or attributed to this actor. This description maintains neutrality regarding unconfirmed technical details while documenting the official listing context for catalog and research purposes. |
||||||
| Ransomware | City of St Paul id32847 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official digital functions and public-facing resources for its community and stakeholders. The domain represents an institutional presence in the public sector, with offerings aligned to governmental services and information dissemination. Within the threat-intelligence index, this entity is cataloged as a ransomware victim linked to the interlock threat actor. This listing reflects the association between the affected public sector infrastructure and interlock in the ransomware incident dataset, without confirming specific breach details. The designation supports analytical tracking of public sector exposure to identified threat activity. |
||||||
| Ransomware | City of St Paul id32850 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity operating within government services and digital infrastructure, providing official web presence and public-facing offerings aligned with municipal or state administrative functions. As cataloged in the threat-intelligence index, it is listed as a ransomware victim associated with threat actor interlock. This designation reflects the entity's inclusion in intelligence records linking its compromised status to interlock's activity within the Public Sector environment. The entry serves catalog and analytical purposes for threat researchers tracking ransomware incidents across government and public infrastructure domains. No specific breach details, data loss metrics, or confirmed incident timelines are asserted beyond the listing classification. |
||||||
| Ransomware | City of St Paul id32852 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a government or public service entity whose infrastructure was identified within threat-intelligence indexing. As a ransomware victim, this listing type indicates its inclusion in records tied to malicious cyber activity, specifically associated with the threat actor interlock. The description focuses on the entity's classification, sector context, geographic origin, and its documented relationship to this threat actor without asserting unconfirmed breach specifics. This catalog entry provides neutral, authoritative context for researchers and defenders analyzing public-sector exposure to ransomware campaigns. |
||||||
| Ransomware | City of St Paul id32857 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative offerings. Its domain functions as an official online presence for public-sector functions, providing information and services aligned with government operations. This listing type identifies stpaul.gov as a ransomware victim within the threat-intelligence index. The association connects the entity to the interlock threat actor. This entry documents the relationship neutrally without confirming specific incident details, data scope, or breach evidence. |
||||||
| Ransomware | City of St Paul id32858 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a government or public service entity operating within official administrative functions. Its inclusion in this threat-intelligence index is categorized specifically as a ransomware victim, with interlock identified as the associated threat actor or source. This listing reflects intelligence gathered on the entity's exposure within cybersecurity threat landscapes, without disclosing unverified incident details such as data exfiltration scope, ransom demands, or internal forensic findings. The designation provides catalog users with context regarding the organization's sector, geographic origin, and documented threat association for risk assessment and monitoring purposes. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | City of St Paul id32859 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing government services or administrative functions. Within the threat-intelligence index, it is classified as a ransomware victim, with the associated threat actor identified as interlock. This listing reflects observed cybersecurity intelligence correlating the entity with malicious activity targeting public-sector infrastructure. The description remains neutral, focusing solely on the index classification without asserting unverified breach details, data exfiltration specifics, or financial impact. The catalog entry documents the relationship between stpaul.gov and interlock as a ransomware incident marker for analytical and defensive reference. |
||||||
| Ransomware | City of St Paul id32860 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing government services and digital infrastructure functions within its designated locality. As a public sector organization, it handles official operations and citizen-facing services, making it a potential target for cyber threats. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor interlock. The classification reflects its documented association with this adversary group within cybersecurity intelligence records. This entry provides neutral context for threat researchers and security professionals monitoring public sector ransomware activity. |
||||||
| Ransomware | City of St Paul id32860 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative offerings, commonly associated with municipal or public institution functions. As cataloged in this threat-intelligence index, it is classified as a ransomware victim linked to the interlock threat actor. The listing reflects intelligence context concerning the entity's exposure profile within public-sector cybersecurity monitoring. This description avoids inventing incident details such as data stolen, records compromised, ransom demands, or confirmed breach specifics. The entry provides neutral catalog information for threat-intelligence researchers, defenders, and sector-focused security analysts tracking ransomware activity across US public infrastructure. |
||||||
| Ransomware | City of St Paul id32861 View details | United States | Public Sector | — | ||
|
stpaul.gov operates as a public sector entity based in the United States, providing government-related services and digital infrastructure. The domain functions within the public administration sector, supporting official functions and citizen-facing resources. Within threat-intelligence indexing frameworks, this entity is documented specifically as a ransomware victim associated with the threat actor interlock. This classification reflects its inclusion in cybersecurity databases tracking adversary campaigns and impacted infrastructure. The description remains neutral, focusing solely on the indexed listing type and associated actor without extrapolating beyond verified intelligence sources. |
||||||
| Ransomware | City of St Paul id32861 View details | United States | Public Sector | — | ||
|
stpaul.gov operates as a public sector entity based in the United States, providing government-related services and digital infrastructure. The domain is cataloged within a threat-intelligence index under the designation of ransomware victim, linked to the threat actor interlock. This listing reflects observed security event correlations without confirming specific breach details, data exfiltration, or operational impact. The entry serves to document the entity's sector classification, geographic context, and association with identified cyber threats for analytical purposes. It remains a reference point for monitoring public sector exposure to ransomware campaigns. |
||||||
| Ransomware | City of St Paul id32861 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing a government or public-facing entity providing administrative and civic services. The domain serves as a catalog entry within a threat-intelligence index documenting cybersecurity incidents, specifically categorized as a ransomware victim. This listing reflects observed threat activity linking the entity to the interlock threat actor group. The entry contributes to broader monitoring of public-sector exposures and associated adversary methodologies. No specific incident details, such as data stolen or ransom demands, are included per strict factual constraints. |
||||||
| Ransomware | City of St Paul id32861 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative functions. Its domain represents an official organizational presence focused on public-sector offerings and infrastructure. Within the threat-intelligence index catalog, stpaul.gov is formally listed as a ransomware victim linked to the interlock threat actor. This classification reflects the entity's documented association with interlock's activity in the cybersecurity landscape. The entry provides neutral context for researchers assessing public-sector exposure and threat actor targeting patterns. |
||||||
| Ransomware | City of St Paul id32861 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US Public Sector, representing government or public-service entities and their digital infrastructure, services, and administrative offerings. As cataloged in this threat-intelligence index under the ransomware victim listing type, the entity reflects an incident context where cyber activity targeted public-sector systems. The association with threat actor interlock identifies a specific adversary linkage within the ransomware incident classification. This entry documents the entity's sector, geographic context, listing classification, and attributed threat actor without disclosing unverified technical details or confirmed breach specifics. The neutral framing supports comprehensive threat indexing and analytical reference. |
||||||
| Ransomware | City of St Paul id32862 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with a United States public sector organization, providing governmental services and administrative functionalities typical of public sector entities. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the interlock threat actor. The classification reflects observed cybersecurity event correlations within the index rather than confirmed breach details. Public sector entities like stpaul.gov are frequently targeted by ransomware campaigns, underscoring the importance of continuous threat monitoring and defensive readiness. This entry serves to catalog the relationship between the entity, its sector context, and the associated threat actor for analytical purposes. |
||||||
| Ransomware | City of St Paul id32862 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative offerings, reflecting the broader domain of public-sector digital infrastructure. Its inclusion in this threat-intelligence index is categorized specifically as a ransomware victim, associated with the threat actor interlock. This listing serves to document the entity's exposure profile within cybersecurity intelligence records, providing context for monitoring public-sector security postures and adversary activity. The description remains factual and neutral, focusing on classification rather than speculative incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | City of St Paul id32862 View details | United States | Public Sector | — | ||
|
stpaul.gov operates as a United States public sector entity, providing governmental services and digital infrastructure functions within its designated jurisdiction. The domain represents an organization within the public administration sector, where cybersecurity resilience is critical for maintaining operational continuity and public trust. Within the threat-intelligence index, this entity is formally cataloged as a ransomware victim linked to the interlock threat actor group. This classification reflects the documented relationship between stpaul.gov and interlock in cybersecurity threat databases, highlighting the vulnerability exposure within public sector infrastructure. The entry serves to inform analysts and defenders about potential attack vectors and associated threat actor methodologies targeting similar government domains. |
||||||
| Ransomware | City of St Paul id32862 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing government or public service operations and digital infrastructure. The entity functions within public sector contexts, providing official services, administrative resources, or organizational presence relevant to government stakeholders. In the threat-intelligence index under consideration, stpaul.gov is cataloged as a ransomware victim linked to the interlock threat actor. This listing reflects its inclusion within cybersecurity intelligence records concerning ransomware activity and associated attribution. The description remains neutral and avoids speculative claims regarding breach details, data exposure, or operational impact. |
||||||
| Ransomware | City of St Paul id32862 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US Public Sector, representing government-related services or infrastructure. As cataloged in the threat-intelligence index, it is classified specifically as a ransomware victim tied to the interlock threat actor. This listing reflects observed security events or attributed activity within the entity's operational environment. The description maintains neutrality regarding incident details, focusing solely on the verified categorization within the intelligence framework. Public sector entities like stpaul.gov are closely monitored due to their critical role in national services and infrastructure resilience. |
||||||
| Ransomware | City of St Paul id32863 View details | United States | Public Sector | — | ||
|
stpaul.gov operates within the United States public sector, representing a government or public-facing web presence associated with municipal or civic services. The entity is documented within this threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as interlock. This classification contributes contextual intelligence regarding public-sector exposure and adversary targeting patterns. No specific incident details, such as stolen data categories, record counts, ransom amounts, or confirmed breach evidence, are included per strict factual boundaries. The listing neutrally records stpaul.gov as a ransomware victim associated with interlock. |
||||||
| Ransomware | City of St Paul id32863 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing a government or public service institution whose online presence and digital services fall within public administration functions. As cataloged in this threat-intelligence index under the listing type ransomware victim, the entity is linked to the threat actor interlock, indicating a cybersecurity incident context tied to this adversary group. The description maintains factual neutrality regarding the nature of any potential compromise, avoiding speculation on data stolen, financial impact, or specific technical details absent verified public disclosure. This entry serves to document the relationship between the entity, its sector classification, and the associated threat actor for analytical and cataloging purposes. |
||||||
| Ransomware | City of St Paul id32864 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States government domain operating within the Public Sector, providing official services and digital infrastructure functions for its associated public institution. The entity is cataloged in this threat-intelligence index as a ransomware victim, with the associated threat actor identified as interlock. This listing type indicates cybersecurity incident classification relevant to public sector defense and threat tracking. No specific breach details, data exfiltration claims, or financial impact are included per strict factual constraints. The entry serves to document the relationship between this government entity, its sector classification, and the interlock threat actor within the ransomware victim index. |
||||||
| Ransomware | City of St Paul id32864 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing government services and administrative functions within the domain stpaul.gov. As a Public Sector organization in the US, it operates within government frameworks and delivers services relevant to its jurisdiction. This entity has been cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The classification reflects its documented relationship to this specific cyber threat actor within the index records. The description remains neutral and factual regarding its categorization without alleging unconfirmed breach details. |
||||||
| Ransomware | City of St Paul id32865 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a government or public-service entity. Its domain serves official functions within public administration, though specific operational details remain limited to its classification within threat-intelligence indexing. This listing identifies stpaul.gov as a ransomware victim linked to the interlock threat actor group. The entry reflects cybersecurity intelligence observations regarding entity exposure and threat associations without confirming breach specifics, data exfiltration details, or financial impact. Such catalog entries support threat-aware monitoring and sector-focused risk assessment for public infrastructure. |
||||||
| Ransomware | City of St Paul id32866 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing governmental services and administrative functions within its designated operational domain. The domain operates within the public sector framework, reflecting standard government infrastructure and service offerings typical of US state or municipal systems. Within threat intelligence indexing frameworks, this entity has been cataloged specifically as a ransomware victim linked to the interlock threat actor group. The classification reflects observed security event correlations and does not confirm specific breach details, data exfiltration, or operational impact. This entry serves to document the association for cybersecurity monitoring and sector-focused threat analysis. |
||||||
| Ransomware | City of St Paul id32869 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing an official government or public service entity whose online presence supports administrative functions and public-facing services. Within the threat-intelligence index under analysis, this entity is specifically listed as a ransomware victim. The association connects stpaul.gov to the threat actor interlock, indicating a cybersecurity incident classification tied to this actor's activity. This catalog entry provides neutral context for defenders monitoring ransomware campaigns targeting public-sector infrastructure in the US. The listing reflects the entity's status within the intelligence dataset without confirming specific breach details or operational specifics. |
||||||
| Ransomware | City of St Paul id32870 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain operating within the United States public sector, providing governmental services and digital infrastructure functions. As a ransomware victim entry in this threat-intelligence index, it is documented alongside the threat actor interlock for analytical reference. This listing type indicates the entity's association with a cyber threat campaign targeting public sector environments. The description remains factual and neutral, focusing on the entity's sector classification, geographic context, and its designation within the ransomware victim category linked to interlock. No specific incident details such as breach confirmation, data exfiltration scope, or financial impact are included per strict factual reporting guidelines. |
||||||
| Ransomware | City of St Paul id32870 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity operating within government-facing services and digital infrastructure contexts, reflecting the broader public administration and service delivery landscape. The domain serves organizational functions tied to public-sector operations, though specific internal services, geographic scope, or operational details are not specified in the provided context. Within the threat-intelligence index, stpaul.gov is cataloged as a ransomware victim associated with the threat actor interlock. This listing type indicates its inclusion based on threat-correlation evidence linking the entity to interlock activity within the ransomware incident profile. The description remains factual and neutral, avoiding invented technical findings or unconfirmed breach details. |
||||||
| Ransomware | City of St Paul id32870 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a government or public service entity whose online presence and digital services fall within the public administration domain. As cataloged in this threat-intelligence index under the listing type ransomware victim, the entity is associated with the threat actor interlock. This designation reflects the intelligence assessment linking stpaul.gov to ransomware activity attributable to interlock, without disclosing unverified specifics such as data exfiltration details, ransom demands, or breach confirmation. The entry provides context for security professionals monitoring public-sector exposure and threat actor targeting patterns across government infrastructure. It neutrally records that stpaul.gov was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | City of St Paul id32870 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a government or public-service entity whose online presence and digital infrastructure are relevant to public-sector threat assessment. As cataloged in this threat-intelligence index under the listing type ransomware victim, stpaul.gov is associated with the threat actor interlock. This designation contributes contextual intelligence regarding public-sector exposure patterns and adversary targeting behavior within governmental digital environments. The entry provides neutral catalog information for researchers, defenders, and analysts tracking ransomware incidents affecting public-sector entities across the United States. It states neutrally that stpaul.gov was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | City of St Paul id32870 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a governmental or public-service entity whose online presence provides official functions, services, and communications. As categorized within this threat-intelligence index, it is formally listed as a ransomware victim linked to the threat actor interlock. This designation reflects the entity's inclusion in cybersecurity threat databases where ransomware incidents involving public-sector organizations are documented and analyzed for defensive intelligence. The entry serves to contextualize the entity's operational scope alongside its security-related classification without disclosing unverified incident details. This neutral description adheres to factual reporting standards for cataloging threat-associated entities. |
||||||
| Ransomware | City of St Paul id32872 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US Public Sector, providing government-related services and administrative functions. As a ransomware victim listed within this threat-intelligence index, it is documented in connection with the threat actor interlock. The entry serves to catalog the entity's status and associated adversary context for security analysts and defenders monitoring public-sector infrastructure threats. No specific incident details, such as data stolen or ransom demands, are included per strict factual boundaries. This listing reflects the entity's classification and the attributed threat actor for comprehensive cyber threat intelligence. |
||||||
| Ransomware | City of St Paul id32872 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official digital resources and administrative functions for its designated locality or community. Its classification within the Public Sector underscores its role in civic infrastructure and service delivery. According to the threat-intelligence index, stpaul.gov is formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the entity's inclusion in cybersecurity monitoring for public sector exposure. The entry documents the relationship without disclosing unverified incident details, maintaining factual neutrality per catalog standards. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official online functions and public-facing resources for its designated community. As a public sector organization, it handles citizen-facing services, administrative operations, and digital infrastructure within the broader governmental framework. This entity is cataloged in the threat-intelligence index under the classification ransomware victim, with the associated threat actor or source identified as interlock. The listing reflects the observed relationship between stpaul.gov and the interlock threat actor within the ransomware incident context. This entry serves to inform security professionals, defenders, and analysts monitoring public sector exposure and threat actor activity. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with a public sector organization located in the United States, providing governmental services and digital infrastructure. As part of the threat-intelligence index, this entity is categorized specifically as a ransomware victim linked to the threat actor interlock. Public sector entities like stpaul.gov are frequently targeted by cybercriminals seeking to disrupt critical services and operations. The inclusion of this domain in the ransomware victim listing underscores ongoing vigilance against coordinated cyber threats targeting government infrastructure. This neutral record reflects the indexed association with interlock without confirming specific breach details. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and related civic offerings. Its domain represents an official or affiliated public institution, serving functions aligned with public administration and sector-specific digital services. Within the threat-intelligence index catalog, stpaul.gov is classified as a ransomware victim associated with the threat actor interlock. This listing reflects the entity's inclusion in intelligence records documenting cybersecurity incidents linked to interlock activity. The description remains factual and neutral, focusing on sector context, geographic scope, and the assigned ransomware victim classification without adding unverified incident details. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity whose domain represents government or public-service operations, providing official digital presence and online functions within the public administration context. Its inclusion in this threat-intelligence catalog identifies it as a ransomware victim associated with the threat actor interlock. The listing reflects intelligence-based correlation between the entity, its public-sector classification, the geographic location of the US, and the interlock threat actor profile. No specific incident details such as stolen data, record counts, ransom amounts, or confirmed breach evidence are provided here, in compliance with strict factual reporting requirements. This entry serves as neutral catalog documentation for threat-intelligence indexing and research. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing government services and administrative functions within the sector classification. The domain represents an official government presence operating within public services infrastructure. Within the threat-intelligence index, this entity is cataloged as a ransomware victim associated with the interlock threat actor. This listing reflects the cybersecurity context in which the organization was impacted and documented by intelligence sources. The description maintains neutrality regarding specific incident details while accurately representing its classification and associated threat actor. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov operates as a public sector entity based in the United States, providing government-related services and digital infrastructure. As part of the threat-intelligence index catalog, this domain is formally classified as a ransomware victim associated with the threat actor interlock. The listing reflects observed security events within the public sector context, contributing to broader awareness of cyber threats targeting governmental systems. This entry documents the entity's presence in intelligence records without disclosing specific incident details. The association with interlock underscores ongoing monitoring of ransomware activity within US public infrastructure. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing a government or public service entity whose online presence and digital infrastructure fall within the public sector domain. The entity's role and specific offerings are defined by its classification and operational context within national public systems. Within the threat-intelligence index, stpaul.gov is formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the entity's inclusion in cybersecurity records documenting attacks targeting public sector infrastructure. The catalog entry provides neutral context for researchers and defenders analyzing threat actor interlock's impact across US public sector environments. |
||||||
| Ransomware | City of St Paul id32873 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official online functions and public-facing resources for its designated community. As a public sector organization in the United States, it falls under critical infrastructure and government service domains monitored for cyber threats. According to the threat-intelligence index catalog, stpaul.gov is formally listed as a ransomware victim associated with the interlock threat actor. This designation reflects its inclusion within intelligence records documenting ransomware incidents affecting public sector entities. The entry provides context for threat actors, sectors, and victim profiles within cybersecurity intelligence frameworks without disclosing unverified incident details. |
||||||
| Ransomware | City of St Paul id32874 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official digital offerings and administrative functions for its community. As a public sector institution, it represents critical infrastructure within the US government landscape, making it a significant focus for cyber threat monitoring and defense efforts. This entity has been formally cataloged in the threat-intelligence index under the ransomware victim listing type, specifically associated with the threat actor interlock. The inclusion reflects the entity's role within the observed threat landscape and underscores the importance of continuous public sector cybersecurity vigilance against ransomware campaigns targeting governmental systems. |
||||||
| Ransomware | City of St Paul id32879 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing a government or public service entity whose infrastructure was identified within a threat-intelligence index as a ransomware victim. The entity operates within the public sector framework, providing governmental or civic-oriented digital services and administrative functions. This listing type categorizes stpaul.gov under ransomware incidents, specifically linked to the threat actor interlock, which has been documented in cyber threat intelligence databases for targeting public infrastructure. The description remains neutral regarding breach confirmation, data specifics, or operational impact, focusing solely on the verified categorization of the entity within the ransomware victim index associated with interlock. |
||||||
| Ransomware | City of St Paul id32892 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing a governmental or public-service entity whose online presence and services fall within public administration frameworks. The domain is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the threat actor interlock. This designation reflects the entity's inclusion in intelligence records documenting cybersecurity incidents involving this specific adversary group. The description remains factual and neutral, focusing on the entity's classification, sector context, geographic scope, and the verified association with interlock as a ransomware victim without elaborating on unconfirmed operational details. |
||||||
| Ransomware | City of St Paul id32892 View details | United States | Public Sector | — | ||
|
stpaul.gov operates as a United States public sector entity, providing governmental services and digital infrastructure functions within the broader public administration framework. As cataloged in threat-intelligence databases, this domain is officially listed as a ransomware victim associated with the interlock threat actor group. The classification reflects documented security incident correlations between the entity and interlock's activity within the public sector context. This entry serves to inform defenders and analysts monitoring ransomware campaigns targeting government infrastructure in the United States. The listing underscores ongoing vigilance required for public sector digital assets against evolving cyber threats. |
||||||
| Ransomware | City of St Paul id32893 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative functions. Its domain serves official organizational purposes aligned with public-sector digital infrastructure and service delivery. Within the threat-intelligence index, stpaul.gov is cataloged as a ransomware victim associated with the interlock threat actor. This listing reflects the entity's inclusion in cyber threat intelligence records documenting ransomware-related exposure. The description remains neutral regarding specific incident details, as confirmed specifics are not provided in the available data. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing government services and administrative functions within the domain stpaul.gov. Its classification within the threat-intelligence index identifies it as a ransomware victim associated with the threat actor interlock. Public sector entities like stpaul.gov often handle sensitive civic data, making them potential targets for cyber threats. This listing reflects the entity's presence in the ransomware incident catalog tied to interlock, without disclosing specific breach details. The entry supports threat-aware analysis for monitoring public infrastructure security posture and associated adversary activity. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official digital functions and resources for its designated community. As part of the public sector landscape, it represents infrastructure requiring robust cyber defense against evolving malicious activities. Within our threat-intelligence index, stpaul.gov is formally listed as a ransomware victim associated with threat actor interlock. This classification reflects documented threat intelligence linking the entity to this specific adversary group, highlighting vulnerabilities within public sector systems. The entry serves to inform security professionals and stakeholders about potential risks and historical incident correlations. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative offerings. As a public sector organization, it provides official functions typical of municipal or governmental infrastructure, with cyber resilience being a critical concern for entities in this sector. This listing type identifies stpaul.gov as a ransomware victim associated with the threat actor interlock, reflecting its inclusion within a threat-intelligence index for monitoring and risk assessment. The description remains factual and neutral, focusing on the entity's sector classification and its documented association with interlock without speculating on unconfirmed technical details or incident specifics. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the US public sector, representing a governmental or public-service entity whose online presence provides official services and information. Within the threat-intelligence index, this domain is categorized as a ransomware victim linked to the interlock threat actor. The listing type identifies the entity's relationship to a cyber incident involving ransomware activity, providing context for security researchers and defenders monitoring public-sector exposure. No specific incident details such as data stolen, ransom demands, or breach confirmation are included, maintaining factual neutrality. This entry serves to document the association for catalog purposes and threat-aware decision-making. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector domain operating within government services and related public-facing offerings. Its classification as a ransomware victim within the threat-intelligence index reflects an incident tied to the interlock threat actor. This listing type indicates cybersecurity exposure relevant to public-sector resilience monitoring and threat-correlation analysis. No specific breach details, stolen data categories, record counts, ransom terms, or confirmed breach evidence are included here. The entry provides neutral catalog context for researchers tracking ransomware impacts across US public sector entities and associated threat actor activity. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and digital infrastructure functions, providing official information and services for its designated locality or administrative scope. Within the threat-intelligence catalog, stpaul.gov is specifically categorized as a ransomware victim linked to the interlock threat actor. This listing reflects its association with interlock within the ransomware incident index and contributes contextual data for analysts tracking public-sector cyber incidents. The description remains factual and neutral, documenting the entity's sector, geographic context, listing classification, and attributed threat actor without asserting unverified breach details. The inclusion supports comprehensive monitoring of ransomware activity affecting US public-sector organizations. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services, providing official functions and digital offerings for its designated locality or program. The domain serves governmental purposes typical of public sector infrastructure, including administrative services and information dissemination. Within the threat-intelligence index, this entity is formally cataloged as a ransomware victim associated with the threat actor interlock. This listing reflects the cybersecurity intelligence assessment linking the domain to a specific malicious actor profile in the public sector context. The entry contributes to comprehensive tracking of ransomware incidents affecting U.S. government-related domains. |
||||||
| Ransomware | City of St Paul id32895 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity representing a government or public-service domain. Its operational scope aligns with public-sector offerings typically involving administrative services, digital infrastructure, and civic-facing functions. Within the threat-intelligence index, stpaul.gov is cataloged as a ransomware victim linked to the threat actor interlock. This listing reflects its association with the identified actor and its classification within cybersecurity incident tracking. The description remains neutral regarding unconfirmed technical details, incident specifics, or recovery outcomes. |
||||||
| Ransomware | City of St Paul id32920 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity providing governmental services and digital infrastructure functions. As a public sector organization, it handles official operations, citizen services, and administrative resources within the government domain. This listing type identifies stpaul.gov as a ransomware victim within the threat-intelligence index. The association links this entity to the threat actor interlock, reflecting observed cyber threat activity targeting public sector infrastructure. The description remains neutral regarding specific incident details, focusing solely on the verified classification and contextual sector information. |
||||||
| Ransomware | City of St Paul id33103 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity operating within government services and digital infrastructure offerings. Its domain functions as a representative public institution within the American governmental framework, providing access to public resources and services under the US jurisdiction. This entity has been cataloged within the threat-intelligence index as a ransomware victim, with the associated threat actor and source identified as interlock. The classification reflects its inclusion in cybersecurity intelligence records documenting adversary activity targeting public sector infrastructure. All descriptions remain factual and neutral, focusing on verified listing metadata without extrapolating unconfirmed incident details. |
||||||
| Ransomware | City of St Paul id33104 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity operating within government services and digital infrastructure functions. Its domain serves official public-sector purposes, reflecting the organizational role of a government institution in the US context. Within threat-intelligence indexing, stpaul.gov is cataloged as a ransomware victim associated with the interlock threat actor. This listing type records the entity's relationship to a specific cyber threat actor within the index's ransomware incident dataset. The description remains factual and neutral, focusing on sector classification, geographic context, and the verified association without extrapolating breach details or unconfirmed claims. |
||||||
| Ransomware | City of St Paul id33105 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing a government or public institution whose online presence and services fall under public administration. The entity operates within the public sector domain, providing services or functions relevant to civic or governmental operations in the US context. Within the threat-intelligence index, stpaul.gov is formally cataloged as a ransomware victim linked to the interlock threat actor group. This listing reflects the entity's inclusion in intelligence records documenting cybersecurity incidents and associated threat activity. The description remains neutral regarding specific incident details, focusing solely on the indexed classification and contextual attributes of the entity. |
||||||
| Ransomware | City of St Paul id33105 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity operating within government services, providing official digital offerings and administrative functions for its designated community or jurisdiction. As cataloged in this threat-intelligence index, the domain is classified as a ransomware victim linked to the interlock threat actor. This listing reflects observed cyber threat activity targeting entities within the public sector, highlighting the vulnerability landscape for government infrastructure. The record emphasizes neutral documentation of the association without disclosing unverified incident details, ensuring factual accuracy and adherence to threat intelligence standards. |
||||||
| Ransomware | City of St Paul id33105 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity operating within government services and administrative offerings. Its domain functions as an official government presence, serving public-sector functions and resources under the US jurisdiction. Within the threat-intelligence index catalog, stpaul.gov is listed as a ransomware victim associated with the threat actor interlock. This classification reflects the entity's inclusion in the ransomware victim category tied to interlock's activity profile. The description maintains neutrality regarding specific incident details, as confirmed specifics remain outside verified public disclosure boundaries. |
||||||
| Ransomware | City of St Paul id33105 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States Public Sector entity operating within government services and digital infrastructure offerings. Its domain functions as an official government presence, providing public-facing services, information dissemination, and administrative resources aligned with US public sector operations. This listing type identifies stpaul.gov as a ransomware victim within the threat-intelligence index. The association with threat actor interlock contextualizes the entity within active cyber threat intelligence records, reflecting observed security incident linkages. This description maintains factual neutrality regarding the incident specifics while documenting the indexed relationship. |
||||||
| Ransomware | City of St Paul id33105 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity representing municipal or governmental administrative services, providing online resources, public records access, and service portals for community stakeholders. Within the threat-intelligence catalog, this domain is classified as a ransomware victim linked to the interlock threat actor. The listing type identifies the entity's involvement in a cyber incident context under interlock's activity profile. This entry contributes structured intelligence for security professionals monitoring public-sector exposure and ransomware campaigns in the United States. The record reflects the indexed association without confirming specific breach details or operational specifics. |
||||||
| Ransomware | City of St Paul id33105 View details | United States | Public Sector | — | ||
|
stpaul.gov is a United States public sector entity representing municipal or governmental administrative services, providing online resources, public records access, and service portals for community stakeholders. Within the threat-intelligence catalog, this domain is classified as a ransomware victim linked to the interlock threat actor. The listing type identifies the entity's involvement in a cyber incident context under interlock's activity profile. This entry contributes structured intelligence for security professionals monitoring public-sector exposure and ransomware campaigns in the United States. The record reflects the indexed association without confirming specific breach details or operational specifics. |
||||||
| Ransomware | City of St Paul id32902 View details | United States | Public Sector | — | ||
|
stpaul.gov is a domain associated with the United States public sector, representing government-facing infrastructure and services. The entity is documented within a threat-intelligence index under the classification of ransomware victim, specifically tied to the threat actor interlock. Public sector entities like stpaul.gov are critical infrastructure components requiring vigilant monitoring due to their role in civic functions and service delivery. This listing reflects observed threat intelligence linking the domain to malicious activity associated with interlock, without confirming specific breach details. The catalog entry serves to inform defenders and analysts about potential risks targeting this sector and associated actors. |
||||||
| Ransomware | City of St Paul id32902 View details | United States | Public Sector | — | ||
|
The government of the city of Saint Paul, Minnesota, including its representatives and employees, is extremely careless and irresponsible about the security of their city, because of this, a large part of the infrastructure was damaged, brought a lot of losses and damage! Including in the worst position were residents whose data was compromised in the internet! Saint Paul, Minnesota, population is about 310,992 people. The city is part of the Minneapolis - Saint Paul metropolitan area. |
||||||
| Ransomware | Weisman Children's id21519 View details | United States | Education | leaked | ||
|
Weisman Children's Rehabilitation Hospital is the leading provider of pediatric rehabilitation services in the Delaware Valley |
||||||
| Ransomware | Weisman Children's id32572 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with child-focused educational or institutional offerings. As cataloged in this threat-intelligence index, the entity is identified specifically as a ransomware victim linked to the threat actor interlock. This listing reflects the cybersecurity context in which the organization was affected, contributing to broader awareness of active threats targeting education-sector infrastructure. The description remains factual and neutral, focusing solely on the verified association without elaborating on unconfirmed technical details or incident specifics. Such entries support researchers and defenders in understanding threat patterns across critical sectors. |
||||||
| Ransomware | Weisman Children's id32572 View details | United States | Education | — | ||
|
Weisman Children's Rehabilitation Hospital is the leading provider of pediatric rehabilitation services in the Delaware Valley |
||||||
| Ransomware | Weisman Children's id32678 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused community or institutional offerings. The domain is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. This designation reflects the entity's inclusion in records documenting cybersecurity incidents linked to this actor. No specific incident details, such as data stolen, records impacted, ransom demands, or confirmed breach evidence, are provided here to maintain factual neutrality. The listing serves as a reference point for threat analysts tracking education sector exposure to ransomware activity. |
||||||
| Ransomware | Weisman Children's id32679 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with children's educational and institutional needs. As documented in the threat-intelligence index, this entity is classified as a ransomware victim linked to the interlock threat actor. The listing reflects observed threat intelligence data concerning this organization's exposure to ransomware activity. This description maintains neutrality regarding specific incident details, as confirmed specifics are not publicly available through official channels. The entry serves catalog and analytical purposes within the threat-intelligence ecosystem. |
||||||
| Ransomware | Weisman Children's id32679 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. This listing reflects verified intelligence concerning network compromise and associated malicious activity without disclosing unconfirmed incident details. The record supports cybersecurity monitoring, sector-specific threat analysis, and defensive awareness for education-sector organizations operating in the US. |
||||||
| Ransomware | Weisman Children's id32680 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused institutional or organizational needs. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the interlock threat actor. The listing reflects observed threat activity targeting this sector and geographic context without disclosing specific breach details, stolen data, or operational impact. This record serves catalog and analytical purposes for monitoring cyber threats within educational infrastructure. |
||||||
| Ransomware | Weisman Children's id32684 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational initiatives and related institutional offerings. As part of the threat-intelligence index, this entity is cataloged as a ransomware victim linked to the interlock threat actor. The listing reflects cybersecurity incident intelligence concerning the organization's exposure profile within the Education sector. This description adheres to neutral, authoritative reporting standards without speculating on unconfirmed breach details, stolen data, or financial impact. The inclusion underscores ongoing monitoring of ransomware activity targeting education-sector organizations in the US. |
||||||
| Ransomware | Weisman Children's id32684 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with child-focused organizational needs. As a ransomware victim entry in this threat-intelligence index, the entity is documented alongside threat actor interlock for analytical and cataloging purposes. This listing reflects observed cybersecurity event associations without disclosing specific incident details, breach confirmations, or proprietary intelligence. The record supports threat-aware monitoring for sector-relevant entities and helps contextualize risks within educational infrastructure. All information remains factual and neutral per index standards. |
||||||
| Ransomware | Weisman Children's id32692 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with its domain identity and institutional role. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the interlock threat actor. The listing reflects observed security incident associations without disclosing unverified technical details or confirmed breach specifics. This neutral description serves catalog purposes for threat-aware stakeholders monitoring Education sector vulnerabilities and associated threat actor activity. |
||||||
| Ransomware | Weisman Children's id32694 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with childcare and children's educational offerings. As cataloged in the threat-intelligence index, this entity is identified as a ransomware victim linked to the interlock threat actor. The listing reflects observed cybersecurity intelligence concerning this organization's exposure profile within the indexed threat landscape. This description maintains neutrality regarding specific incident details while documenting the association for analytical and cataloging purposes. |
||||||
| Ransomware | Weisman Children's id32694 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector in the United States, providing services aligned with childcare and children's educational offerings. As a ransomware victim, this entity appears in the threat-intelligence index linked to the threat actor interlock. The listing reflects an assessed cybersecurity incident classification without disclosing unverified details such as data exfiltration scope, ransom demands, or specific breach mechanics. This catalog entry serves to document the association for defenders monitoring Education sector threats and interlock-related activity. The designation remains neutral, focusing solely on the verified listing context within the intelligence index. |
||||||
| Ransomware | Weisman Children's id32695 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the interlock threat actor. This listing reflects observed security-related activity and does not confirm specific breach details, stolen data, financial impact, or operational disruption. The record serves to inform stakeholders about potential cyber exposure within this sector and geographic context. Neutral documentation supports threat-aware decision-making and context for monitoring related activity. |
||||||
| Ransomware | Weisman Children's id32698 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As a ransomware victim, it appears in this threat-intelligence index linked to the Interlock threat actor. The listing reflects an incident where the entity was impacted by ransomware activity attributed to Interlock, without disclosing specific technical details, stolen data categories, or operational consequences. This catalog entry supports cybersecurity professionals in tracking targeted sectors and associated threat campaigns. The record remains a factual reference to the entity's status and the attributed threat actor. |
||||||
| Ransomware | Weisman Children's id32698 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with children's educational or institutional offerings. As cataloged in the threat-intelligence index, this entity is designated as a ransomware victim linked to the interlock threat actor group. The listing reflects observed security-related activity tied to this actor within the sector context. No specific incident details, such as data stolen or ransom demands, are included here, adhering to strict factual boundaries. This entry documents the association neutrally for analytical and cataloging purposes. |
||||||
| Ransomware | Weisman Children's id32698 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As documented in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. The listing reflects the cybersecurity event involving this organization without disclosing unverified details such as data exfiltration scope, ransom demands, or specific breach mechanics. This entry serves catalog and analytical purposes for threat researchers monitoring ransomware activity across educational sectors in the US. The designation underscores the importance of vigilance for institutions within this sector facing advanced persistent threats. |
||||||
| Ransomware | Weisman Children's id32698 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with childcare and children's organizational needs. As a ransomware victim, this entity is documented within the threat-intelligence index due to its association with the threat actor interlock. The listing reflects the cybersecurity context in which the organization was impacted, emphasizing sector-specific risk awareness for educational institutions. This entry serves to inform defenders and analysts about real-world incidents affecting critical education infrastructure under confirmed threat actor attribution. |
||||||
| Ransomware | Weisman Children's id32698 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with childcare and children's educational offerings. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. The listing reflects observed cybersecurity intelligence concerning this organization and its association with this specific threat actor profile. This entry serves to inform security professionals and stakeholders about potential risks within this sector and geographic context. No additional incident details such as data stolen, ransom demands, or confirmed breach specifics are included, adhering to factual neutrality. |
||||||
| Ransomware | Weisman Children's id32698 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the interlock threat actor. The listing reflects observed cyber threat activity targeting this sector and geographic region without disclosing unverified technical or operational details. This record supports security teams monitoring Education infrastructure for ransomware-related indicators and attacker associations. The entity remains cataloged neutrally per index protocols. |
||||||
| Ransomware | Weisman Children's id32699 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As documented in the threat-intelligence index, the entity is classified as a ransomware victim linked to the interlock threat actor. This listing reflects cybersecurity intelligence observations regarding the organization's exposure profile and the associated threat context. The description remains neutral, focusing solely on the verified classification without speculating on breach details, data impacts, or operational consequences. The inclusion underscores ongoing vigilance for Education sector entities facing evolving cyber threats. |
||||||
| Ransomware | Weisman Children's id32699 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with children's educational and institutional needs. As documented in our threat-intelligence index, this entity is categorized as a ransomware victim linked to the threat actor interlock. The listing reflects observed cyber threat intelligence data concerning this organization without disclosing unverified incident details. This catalog entry serves to inform stakeholders about associated security risks within the Education sector context. Neutral reporting ensures transparency while respecting evidentiary boundaries in threat analysis. |
||||||
| Ransomware | Weisman Children's id32702 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with children's educational or institutional offerings. As cataloged in our threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. This listing reflects observed cybersecurity intelligence correlating the domain and organization with malicious activity targeting Education sector infrastructure. The description adheres strictly to verified index data without extrapolating unconfirmed breach details, stolen data, or financial impact. Neutral reporting ensures transparency for stakeholders monitoring threat exposure across critical sectors. |
||||||
| Ransomware | Weisman Children's id32702 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector based in the United States, providing services aligned with child-focused educational or institutional offerings. As documented in this threat-intelligence index, the entity is classified as a ransomware victim linked to the interlock threat actor. This listing reflects observed security event correlations within the index without confirming specific incident details such as data exfiltration, ransom demands, or breach scope. The record serves to catalog entities affected by identified threat activity for analytical and defensive reference. Neutral categorization supports threat-aware monitoring and sector-specific risk assessment. |
||||||
| Ransomware | Weisman Children's id32703 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational initiatives and institutional support. As a ransomware victim indexed in the threat-intelligence catalog, the entity is documented in connection with the threat actor interlock. This listing reflects the cybersecurity context in which the organization was identified, emphasizing sector vulnerability and threat attribution without disclosing unverified incident details. The catalog entry serves threat analysts and defenders seeking structured intelligence on compromised entities within critical infrastructure sectors. Neutral documentation ensures factual accuracy while maintaining focus on verified attribution and sector classification. |
||||||
| Ransomware | Weisman Children's id32703 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. This entity is cataloged within the threat-intelligence index under the listing type ransomware victim. The association links the organization to interlock, a threat actor identified in cybersecurity intelligence records. This designation reflects inclusion in threat-event documentation without confirming specific incident details. The listing serves to inform stakeholders of the entity's exposure profile within the indexed ransomware victim dataset. |
||||||
| Ransomware | Weisman Children's id32704 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim linked to the interlock threat actor. The listing reflects observed threat-intelligence data concerning this organization's security posture and its association with this specific adversary group. This description remains factual and neutral, focusing on the entity's sector, geographic context, listing classification, and source attribution without speculating on unverified incident details. The record serves to inform stakeholders about potential cybersecurity risks within this sector and associated threat actor activity. |
||||||
| Ransomware | Weisman Children's id32704 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with child-focused educational or institutional offerings. As documented in the threat-intelligence index, this entity is classified as a ransomware victim linked to the interlock threat actor. The listing reflects cybersecurity incident data relevant to monitoring educational sector vulnerabilities and associated adversary activity. This description adheres to neutral, factual reporting standards without speculating on unconfirmed breach details, data impacts, or resolution specifics. The entity remains cataloged for threat-intelligence analysis and sector-specific risk assessment. |
||||||
| Ransomware | Weisman Children's id32709 View details | United States | Education | — | ||
|
weismanchildrens.com operates within the Education sector and serves the United States market, providing services aligned with children's educational and institutional needs. As a ransomware victim, this entity is documented within the threat-intelligence index under association with threat actor interlock. The listing reflects cybersecurity incident classification and contextual threat intelligence rather than confirmed breach details. This catalog entry supports security professionals, defenders, and researchers monitoring education sector vulnerabilities and active threat actor campaigns. The record remains neutral, focusing solely on the verified association between weismanchildrens.com and interlock as a ransomware victim. |
||||||