Skip to content

Interlock

Ransomware Group3 claimsLast activity:

Overview

Interlock is a financially motivated ransomware and data-extortion group first observed in September 2024. A joint FBI, CISA, HHS and MS-ISAC advisory describes opportunistic attacks against businesses and critical-infrastructure organizations in North America and Europe. AWS reported an active Interlock campaign in early 2026, but public reporting does not identify the operators or establish a state sponsor.

Activity and targeting

Interlock has affected organizations across multiple sectors rather than a single fixed victim set. The joint advisory documents activity against businesses and critical infrastructure in North America and Europe. Amazon threat intelligence assessed that education represented the largest share of observed activity, followed by engineering, architecture and construction, manufacturing and industrial organizations, healthcare, and government and public-sector entities. These observations support opportunistic targeting and do not establish that every claimed victim or sector pattern reflects a verified intrusion.

Methods and operational characteristics

Interlock uses double extortion: operators steal data, encrypt systems and threaten publication through leak and negotiation infrastructure. The joint advisory documents Windows and Linux encryptors, virtual-machine targeting, unique victim codes and Tor-based contact. It also reports drive-by downloads from compromised websites, fake browser or security-software updates, ClickFix social engineering, PowerShell-based remote access, credential theft, RDP and legitimate remote-administration tools for lateral movement, and Azure tools for data exfiltration. Cisco Talos additionally analyzed Windows and Linux variants, the Worldwide Secrets Blog leak site, a Tor negotiation workflow and an intrusion that used a fake browser update, AnyDesk, PuTTY and AzCopy before encryption.

Interlock’s access methods have continued to evolve. In March 2026, AWS reported that the group had exploited CVE-2026-20131 in Cisco Secure Firewall Management Center before public disclosure. AWS linked the campaign through convergent technical and operational indicators, including Interlock-branded ransom notes, a known Tor portal and per-victim organization identifiers, and documented custom JavaScript and Java remote-access tools, memory-resident access, disposable proxy infrastructure and legitimate-tool abuse.

What type of group is it?

Interlock is best characterized as a financially motivated ransomware group. The reviewed sources support criminal extortion as its operating model and do not establish political motivation, government direction or state alignment. Cisco Talos assessed with low confidence that Interlock may have emerged from Rhysida operators or developers based on code, tooling and behavioral overlap. That hypothesis does not establish a rebrand, shared identity or confirmed organizational relationship, so Interlock remains a distinct actor record.

Incident claims

AnMed evidence favors Interlock despite Gentlemen claim

Incident date: Source: InsiderDiscovered:

Claim details

A confidential source working inside AnMed supplied a photograph of a hospital-screen ransom demand, a victim-specific Tor link to a chat server and a unique code used to establish a negotiation account. The source identified the server as Interlock. The note claims encryption and data extraction, sets a 72-hour deadline and threatens publication but does not visibly identify AnMed or Interlock. The victim-specific negotiation access is operational infrastructure evidence and supports medium-confidence Interlock attribution. A later public message allegedly posted through AnMed’s hijacked Facebook page carried The Gentlemen branding and domain, providing material contrary evidence. AnMed and authorities have confirmed neither actor, encryption nor data theft. The Tor link and code are withheld to protect private victim communications.

D.C. Housing Authority cyberattack disrupts systems

Incident date: Source: otherPublished: Discovered:

Claim details

Interlock claimed the District of Columbia Housing Authority on its leak site. Daily Security Review reported the listing, and BreachSense reported a claimed 1,660 GB volume. DCHA confirmed only that a limited subset of data including sensitive information was compromised; it did not confirm Interlock, the claimed volume, data theft, ransomware encryption or a demand.

Impacted organizations

Impacted locations

Sources