Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 22715 published victims and 72 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Breach House as a ransomware group with 22715 published victims.
United States is currently the most targeted country in this dataset.
72 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 58 87.9%
- Pending 7 10.6%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (72)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 72 | Onion service | Up checked 2h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 2h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 68 | Onion service | Up checked 2h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 69 | Onion service | Up checked 2h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 66 | Onion service | Up checked 2h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 67 | Onion service | Up checked 2h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 64 | Onion service | Up checked 2h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 65 | Onion service | Up checked 2h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 63 | Onion service | Up checked 2h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 2h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 60 | Onion service | Up checked 2h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 58 | Onion service | Up checked 2h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 57 | Onion service | Up checked 2h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 56 | Onion service | Up checked 2h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 55 | Onion service | Up checked 2h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 54 | Onion service | Up checked 2h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 53 | Onion service | Up checked 2h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Up checked 2h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 51 | Onion service | Up checked 2h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 45 | Onion service | Up checked 2h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 43 | Onion service | Up checked 2h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 71 | Onion service | Down checked 2h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 61 | Onion service | Down checked 2h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 59 | Onion service | Down checked 2h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 48 | Onion service | Down checked 2h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 49 | Onion service | Down checked 2h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 46 | Onion service | Down checked 2h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 47 | Onion service | Down checked 2h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 44 | Onion service | Down checked 2h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 42 | Onion service | Down checked 2h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 2h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 40 | Onion service | Down checked 2h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 38 | Onion service | Down checked 2h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 39 | Onion service | Down checked 2h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 37 | Onion service | Down checked 2h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 36 | Onion service | Down checked 2h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 34 | Onion service | Down checked 2h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 35 | Onion service | Down checked 2h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 33 | Onion service | Down checked 2h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 31 | Onion service | Down checked 2h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 32 | Onion service | Down checked 2h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 30 | Onion service | Down checked 2h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 29 | Onion service | Down checked 2h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 28 | Onion service | Down checked 2h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 26 | Onion service | Down checked 2h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 27 | Onion service | Down checked 2h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 25 | Onion service | Down checked 2h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 24 | Onion service | Down checked 2h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 23 | Onion service | Down checked 2h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 21 | Onion service | Down checked 2h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 22 | Onion service | Down checked 2h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 19 | Onion service | Down checked 2h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 20 | Onion service | Down checked 2h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 18 | Onion service | Down checked 2h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 2h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 15 | Onion service | Down checked 2h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 16 | Onion service | Down checked 2h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 13 | Onion service | Down checked 2h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 2h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 12 | Onion service | Down checked 2h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 11 | Onion service | Down checked 2h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 10 | Onion service | Down checked 2h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 7 | Onion service | Down checked 2h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 2h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 4 | Onion service | Down checked 2h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Down checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Down checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
Top Activity Sectors (15)
- Education 48
- Services 22
- Communication / Marketing 21
- Manufacturing / Engineering 20
- IT 19
- Finance / Legal / Insurance 17
- Public Sector 17
- Healthcare / Pharma 16
- Retail / E-commerce 13
- Construction / Real Estate 11
- NGOs / Associations 6
- Not identified 5
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (22715)
Search, filter and paginate the victim timeline for Interlock. Showing 22701–22715 of 22715.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Winnebago Public School Foundation id32924 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the United States education sector, serving public school community needs and institutional services. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects observed security event linkages and sector exposure without disclosing unverified incident details, data exfiltration specifics, or financial impact. This entry supports threat-aware monitoring for education infrastructure and related cybersecurity intelligence workflows. |
||||||
| Ransomware | Winnebago Public School Foundation id32924 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the United States education sector, associated with public school services and institutional offerings. As a ransomware victim entry in this threat-intelligence index, it is cataloged for its relationship with the interlock threat actor. The listing type identifies the entity as having been affected by ransomware activity linked to interlock, reflecting the cybersecurity risk profile within education infrastructure. This description remains neutral and factual, focusing on sector context, geographic location, and the verified association without attributing confirmed breach details or inventing specifics. The entry supports threat-intelligence analysis for monitoring education-sector exposure to identified threat actors. |
||||||
| Ransomware | Winnebago Public School Foundation id32924 View details | United States | Education | — | ||
|
winnebagopublicschools.org is a domain associated with public schools in the United States education sector, representing an institution operating within the broader public education infrastructure. The domain name indicates its role as a public school organization, serving educational services and administrative functions within the US education landscape. This entity has been formally cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as interlock. The classification reflects the cybersecurity incident classification applied to this organization in relation to the interlock threat actor's activity. This listing provides structured threat-intelligence context for monitoring education sector security events. |
||||||
| Ransomware | Winnebago Public School Foundation id32925 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the United States education sector, representing a public school institution. As cataloged in the threat-intelligence index under the ransomware victim listing type, this entity is associated with threat actor interlock. The description reflects the organization's identity and sector context without disclosing unverified incident details. This entry serves threat analysts tracking cyber incidents across educational infrastructure. The listing neutrally confirms winnebagopublicschools.org was identified as a ransomware victim associated with interlock. |
||||||
| Ransomware | Winnebago Public School Foundation id32930 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the United States education sector, providing public school-related services and infrastructure. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. This listing reflects the organization's status within incident tracking records, highlighting exposure to cyber threats targeting educational institutions. The description remains neutral, focusing solely on the indexed classification and contextual sector information without speculating on unverified incident details. Such entries support security teams in monitoring adversary activity across critical public education environments. |
||||||
| Ransomware | Winnebago Public School Foundation id32943 View details | United States | Education | — | ||
|
winnebagopublicschools.org is an entity associated with the Education sector and the United States, operating within the context of public school services and institutional digital infrastructure. As cataloged for this threat-intelligence index under the ransomware victim listing type, the entity represents an organization identified in relation to the threat actor interlock. The description remains factual and neutral, focusing on the entity's classification, sector relevance, geographic context, and the specific association with the interlock actor without speculating on unverified incident details such as data exfiltration scope, ransom demands, or internal breach specifics. This entry supports comprehensive threat-intelligence analysis by documenting the victim profile alongside its operational context and adversary linkage. |
||||||
| Ransomware | Winnebago Public School Foundation id32943 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the United States education sector, providing public school-related services and infrastructure. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. This listing reflects observed security event associations and contextual intelligence regarding the organization's exposure profile within cybersecurity monitoring frameworks. The description adheres to neutral, encyclopedic standards and avoids speculation regarding specific attack vectors, data handling, or operational impacts. Understanding such entries supports threat-aware defense strategies for education sector institutions facing evolving ransomware threats. |
||||||
| Ransomware | Winnebago Public School Foundation id32944 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the United States education sector, functioning as a public school institution or education-related organization. The domain name indicates a public school context, and the entity is cataloged specifically as a ransomware victim within the threat-intelligence index. Its association with the threat actor interlock identifies the cybersecurity threat profile linked to this listing. This description reflects the entity's classification and sector affiliation without asserting unverified incident details such as breach confirmation, data exfiltration specifics, or financial impact. The entry serves to document the relationship between the organization, its sector, location, listing type, and associated threat actor for analytical and catalog purposes. |
||||||
| Ransomware | Winnebago Public School Foundation id32946 View details | United States | Education | — | ||
|
winnebagopublicschools.org operates within the US Education sector, representing a public school institution whose domain is cataloged in the threat-intelligence index. The listing identifies this entity as a ransomware victim linked to the threat actor interlock. This designation reflects observed cybersecurity event data associated with the domain and its organizational context. The catalog entry provides neutral, factual context for threat researchers and defenders monitoring Education sector incidents in the United States. No specific breach details, data exfiltration claims, or financial impact are included in this description. |
||||||
| Ransomware | Texas Tech University Health Sciences Center id15007 View details | United States | Education | — | ||
|
Beginning in 1969 as the Texas Tech University School of Medicine, Texas Tech University Health Sciences Center (TTUHSC) is now a five-school, comprehensive health-related university with campuses in Abilene, Amarillo, Dallas/Fort Worth, Lubbock and Midland/Odessa. We present to you a large collection of confidential documents, including - patient data, medical research, a large set of SQL databases. |
||||||
| Ransomware | Legacy Treatment Services id14994 View details | United States | Services | pending | ||
|
Legacy Treatment Services has locations in Burlington, Atlantic, Camden, and Middlesex counties. They offer mental and behavioral health services, addiction services, counseling, medication management and more. And we offer you internal documents, patient records, and a large SQL database. |
||||||
| Ransomware | Drug and Alcohol Treatment Service id14951 View details | Australia | Healthcare / Pharma | — | ||
|
Drug and Alcohol Treatment Service is Lackawanna County's leading outpatient drug and alcohol treatment center. The focus of treatment at DATS is centered on changing destructive behaviors and developing a lifestyle free of mood altering drugs. At your disposal is the SAGE accounting database, personal data of employees, SQL database, personal data of patients |
||||||
| Ransomware | Smeg id14943 View details | Italy | Manufacturing / Engineering | — | ||
|
Smeg, an acronym of Smalterie Metallurgiche Emiliane Guastalla, is an Italian home appliance manufacturer We present to you a large collection of corporate documents, including a dump of mailboxes of all employees. Company developments and personal data of employees. |
||||||
| Ransomware | Wayne County id14910 View details | United States | Public Sector | — | ||
|
Wayne County is located in the state of Michigan, United States. We offer you more than 130 SQL databases . A large collection of confidential criminal investigation files, personal data of residents. |
||||||
| Ransomware | Cathexis Holdings LP id14746 View details | United States | Finance / Legal / Insurance | — | ||
|
Today, we unveil nearly 3 million files from the "Cathexis Holdings LP" corporate network. Dive into a wealth of SQL databases, email backups, and an expansive collection of corporate documents that offer unparalleled insights into one of the most diverse investment firms out there. Now, the information that drives billion-dollar decisions is at your fingertips, absolutely free! Transform your business with data that others pay a fortune for your path to insider knowledge starts today |
||||||