Skip to content

Interlock

Ransomware Group8 claimsLast activity:

Overview

Interlock is a financially motivated ransomware and data-extortion group first observed in September 2024. A joint FBI, CISA, HHS and MS-ISAC advisory describes opportunistic attacks against businesses and critical-infrastructure organizations in North America and Europe. AWS reported an active Interlock campaign in early 2026, but public reporting does not identify the operators or establish a state sponsor.

Activity and targeting

Interlock has affected organizations across multiple sectors rather than a single fixed victim set. The joint advisory documents activity against businesses and critical infrastructure in North America and Europe. Amazon threat intelligence assessed that education represented the largest share of observed activity, followed by engineering, architecture and construction, manufacturing and industrial organizations, healthcare, and government and public-sector entities. These observations support opportunistic targeting and do not establish that every claimed victim or sector pattern reflects a verified intrusion.

Methods and operational characteristics

Interlock uses double extortion: operators steal data, encrypt systems and threaten publication through leak and negotiation infrastructure. The joint advisory documents Windows and Linux encryptors, virtual-machine targeting, unique victim codes and Tor-based contact. It also reports drive-by downloads from compromised websites, fake browser or security-software updates, ClickFix social engineering, PowerShell-based remote access, credential theft, RDP and legitimate remote-administration tools for lateral movement, and Azure tools for data exfiltration. Cisco Talos additionally analyzed Windows and Linux variants, the Worldwide Secrets Blog leak site, a Tor negotiation workflow and an intrusion that used a fake browser update, AnyDesk, PuTTY and AzCopy before encryption.

Interlock’s access methods have continued to evolve. In March 2026, AWS reported that the group had exploited CVE-2026-20131 in Cisco Secure Firewall Management Center before public disclosure. AWS linked the campaign through convergent technical and operational indicators, including Interlock-branded ransom notes, a known Tor portal and per-victim organization identifiers, and documented custom JavaScript and Java remote-access tools, memory-resident access, disposable proxy infrastructure and legitimate-tool abuse.

What type of group is it?

Interlock is best characterized as a financially motivated ransomware group. The reviewed sources support criminal extortion as its operating model and do not establish political motivation, government direction or state alignment. Cisco Talos assessed with low confidence that Interlock may have emerged from Rhysida operators or developers based on code, tooling and behavioral overlap. That hypothesis does not establish a rebrand, shared identity or confirmed organizational relationship, so Interlock remains a distinct actor record.

Incident claims

Cyber incident disrupts Southeastern Oklahoma State University

View public claim
Incident date: Source: ransomware.liveDiscovered:

Claim details

Interlock’s branded leak page names Southeastern Oklahoma State University and se.edu and claims a 710 GB collection containing 171,499 files and 19,366 folders. The group alleges the collection includes student names, contact information, Social Security numbers, grades, enrollment and financial-aid data, disciplinary and medical information, Forms 1095-C, more than 490 documents, records tied to more than 90,000 students, and employee identity, injury, Medicare and child-custody or consent information. The page shows document thumbnails and a “GET” button. A separate screenshot shows a directory listing with 11 folders and their stated sizes. The images document what Interlock claimed to possess and presented as available through its site. They do not establish that the files are authentic, originated from the university or were downloadable in full. The university has not confirmed data theft, ransomware or Interlock’s involvement.

AnMed ransomware disrupts systems and patient care

Incident date: Source: otherDiscovered:

Claim details

A confidential source working inside AnMed provided a photograph of a ransom demand displayed on a hospital screen, including a victim-specific Tor address for a negotiation chat server and a unique access code used to establish a negotiation account. The Tor address resolved to infrastructure associated with Interlock. The ransom note claims encryption and data theft, imposes a 72-hour deadline and threatens publication, but the visible text does not identify either AnMed or Interlock by name. The victim-specific negotiation infrastructure provides substantive evidence supporting medium-confidence attribution to Interlock.

That assessment is complicated by later, materially conflicting evidence. The Gentlemen subsequently listed AnMed on its leak site, and Gentlemen-branded messages were posted through AnMed’s compromised social-media accounts. AnMed’s Aug. 27 notice says a virus locked access to network files and files on certain systems were copied without permission, but it does not identify a threat actor or establish the encryption implementation.

The Tor address and negotiation code are withheld to protect private victim communications.

D.C. Housing Authority cyberattack disrupts systems

Incident date: Source: otherPublished: Discovered:

Claim details

Interlock claimed the District of Columbia Housing Authority on its leak site. Daily Security Review reported the listing, and BreachSense reported a claimed 1,660 GB volume. DCHA confirmed only that a limited subset of data including sensitive information was compromised; it did not confirm Interlock, the claimed volume, data theft, ransomware encryption or a demand.

Winona County April 2026 Ransomware Attack

View public claim
Incident date: Source: otherPublished:

Claim details

Interlock publicly claimed the April 2026 attack and posted purported samples, but Winona County did not name the group and the reporting outlet could not independently verify attribution or the claimed file volume.

Community College of Beaver County ransomware incident

View public claim
Incident date: Source: ransomware.livePublished:

Claim details

Interlock listed Community College of Beaver County and claimed it stole 780 GB and published records. CCBC later confirmed unauthorized access and that an unauthorized party obtained information, but it did not attribute the incident to Interlock or corroborate the group’s claimed data volume or publication. The claim supports low-confidence attribution, not proof of actor responsibility or the provenance and completeness of material Interlock presented.

Wagon Mound Public Schools malware incident

View public claim
Incident date: Source: ransomware.livePublished:

Claim details

Interlock listed Wagon Mound Public Schools and claimed it obtained about 80 GB of staff and student information. The district confirmed malware and operational disruption but has not corroborated Interlock, ransomware or data theft.

Impacted organizations

Impacted locations

Sources