Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 60 88.2%
- Pending 7 10.3%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 74 | Onion service | Up checked 3h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 73 | Onion service | Up checked 3h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 71 | Onion service | Up checked 3h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 72 | Onion service | Up checked 3h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 69 | Onion service | Up checked 3h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 70 | Onion service | Up checked 3h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 66 | Onion service | Up checked 3h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 64 | Onion service | Up checked 3h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 65 | Onion service | Up checked 3h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 63 | Onion service | Up checked 3h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 3h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 3h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 59 | Onion service | Up checked 3h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 58 | Onion service | Up checked 3h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 57 | Onion service | Up checked 3h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 54 | Onion service | Up checked 3h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 55 | Onion service | Up checked 3h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 53 | Onion service | Up checked 3h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Up checked 3h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 43 | Onion service | Up checked 3h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 3h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 3h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 3h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 68 | Onion service | Down checked 3h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 67 | Onion service | Down checked 3h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 60 | Onion service | Down checked 3h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 56 | Onion service | Down checked 3h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 51 | Onion service | Down checked 3h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 48 | Onion service | Down checked 3h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 49 | Onion service | Down checked 3h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 46 | Onion service | Down checked 3h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 47 | Onion service | Down checked 3h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 44 | Onion service | Down checked 3h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 45 | Onion service | Down checked 3h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 41 | Onion service | Down checked 3h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 42 | Onion service | Down checked 3h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 39 | Onion service | Down checked 3h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 40 | Onion service | Down checked 3h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 38 | Onion service | Down checked 3h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 3h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 35 | Onion service | Down checked 3h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 36 | Onion service | Down checked 3h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 33 | Onion service | Down checked 3h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 34 | Onion service | Down checked 3h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 32 | Onion service | Down checked 3h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 3h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 30 | Onion service | Down checked 3h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 29 | Onion service | Down checked 3h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 28 | Onion service | Down checked 3h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 27 | Onion service | Down checked 3h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 26 | Onion service | Down checked 3h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 25 | Onion service | Down checked 3h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 24 | Onion service | Down checked 3h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 23 | Onion service | Down checked 3h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 22 | Onion service | Down checked 3h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 20 | Onion service | Down checked 3h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 21 | Onion service | Down checked 3h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 19 | Onion service | Down checked 3h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 3h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 3h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 16 | Onion service | Down checked 3h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 15 | Onion service | Down checked 3h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 14 | Onion service | Down checked 3h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 13 | Onion service | Down checked 3h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 12 | Onion service | Down checked 3h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 11 | Onion service | Down checked 3h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 10 | Onion service | Down checked 3h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 3h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 3h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 7 | Onion service | Down checked 3h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 6 | Onion service | Down checked 3h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 5 | Onion service | Down checked 3h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 3 | Onion service | Down checked 3h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
| Leak location 4 | Onion service | Down checked 3h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 15301–15400 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Wilsonville Toyota-Scion id32875 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is situated in the United States. The entity functions as a commercial online presence associated with the threat-intelligence index listing type ransomware victim. Its inclusion reflects threat-intelligence analysis connecting the domain to interlock, a threat actor identified in cyber incident tracking. This entry serves catalog and analytical purposes by documenting the relationship between the entity, its sector context, location, and the associated threat actor without asserting unverified incident details. The listing type ransomware victim indicates the entity is cataloged within ransomware-related threat intelligence records. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32876 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The entry records the organizational context and attacker linkage without disclosing unverified incident details such as data stolen, ransom demands, or specific breach timelines. It serves as a reference point for analysts tracking ransomware campaigns targeting retail and e-commerce infrastructure in the US. The classification reflects the confirmed association with interlock as the responsible threat actor for this victim profile. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32876 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is situated in the United States. The entity represents a business profile included in the threat-intelligence index under the ransomware victim listing type. Its association with the threat actor interlock indicates it was identified within intelligence records as a victim of this actor's activity. This description maintains neutrality regarding specific incident details, avoiding assumptions about data exposure, operational impact, or confirmed breach specifics. The listing serves to document the entity's categorization within cybersecurity threat intelligence for monitoring and risk assessment purposes. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32876 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, with operational context tied to the United States. The domain represents an entity cataloged in a threat-intelligence index under the designation ransomware victim. Its inclusion reflects observed threat-intelligence linkage to the interlock threat actor, relevant for security teams monitoring retail and e-commerce environments against ransomware campaigns. No specific incident details such as data exfiltration scope, ransom demands, or confirmed breach metrics are attributed here, preserving factual neutrality per catalog standards. This listing serves as a structured reference for analysts assessing exposure patterns and actor relationships within the affected sector. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32876 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services and customer-facing digital offerings. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. This listing reflects the cybersecurity context surrounding the organization's exposure to ransomware activity within its industry domain. The entry serves to document the relationship between the entity, its operational sector, and the identified threat actor for analytical and defensive reference purposes. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32876 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, with operational presence associated with the United States. As a ransomware victim entry in the threat-intelligence index, the entity is cataloged to reflect its exposure profile and the cybersecurity threat landscape affecting retail digital infrastructure. The listing type identifies the entity as impacted by ransomware activity, with interlock cited as the associated threat actor or source. This description maintains factual neutrality regarding the nature of the incident, avoiding invented details such as stolen data, ransom terms, or confirmed breach specifics. The entry serves catalog and intelligence purposes by documenting the relationship between the entity, its sector, location, and the attributed threat actor. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32878 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, reflecting commercial activities associated with online commerce and consumer-facing retail services. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim connected to the threat actor interlock. The listing type indicates observed or attributed exposure to ransomware-related activity within the retail and e-commerce environment. No specific incident details, such as data stolen, ransom demands, breach dates, or confirmed loss metrics, are provided here to maintain factual neutrality. This entry serves threat-intelligence professionals seeking context on ransomware incidents affecting retail and e-commerce organizations in the United States. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32878 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services under its domain name. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects observed cybersecurity intelligence linking the domain and organization to this specific ransomware activity within the retail and e-commerce context. No further incident specifics, such as stolen data categories, record counts, ransom amounts, or confirmed breach details, are provided in this catalog entry to maintain factual neutrality and avoid speculation. This record serves as a structured reference for threat analysts tracking ransomware exposure across retail and e-commerce environments. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is situated in the United States. The domain represents a business entity documented in this threat-intelligence index under the classification of ransomware victim. Its inclusion reflects the association with threat actor interlock, indicating a cybersecurity event categorized within the ransomware threat landscape. This entry provides neutral catalog information regarding the entity's sector, geographic context, and verified threat-actor linkage without disclosing unconfirmed incident details. The listing type underscores the entity's status as a victim of ransomware activity connected to interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is situated in the United States. The entity functions as a commercial online presence serving retail and e-commerce activities, with its domain reflecting its business identity and market focus. Within threat-intelligence indexing frameworks, this listing type identifies wilsonvilletoyota.com as a ransomware victim linked to the interlock threat actor group. This designation contributes contextual data to cybersecurity monitoring efforts, highlighting exposure within digital commerce environments. The record reflects association with interlock without disclosing unverified incident details, operational specifics, or confirmed breach parameters. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, with its primary location identified as the United States. The entity represents a business organization whose cybersecurity posture and incident history are cataloged within this threat-intelligence index. The listing type designated for this entity is ransomware victim, reflecting its association with the threat actor interlock as documented in the index records. This entry provides neutral, factual context for analysts monitoring retail and e-commerce sector exposure to cyber threats, without disclosing unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, with a presence associated with the United States. The entity represents a business context relevant to threat-intelligence cataloging where cybersecurity events are documented and analyzed. As cataloged in this threat-intelligence index, it is classified as a ransomware victim associated with the threat actor interlock. This listing type indicates its inclusion based on intelligence linkage rather than confirmed incident details, ensuring neutrality and factual accuracy in the record. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is situated in the United States. The entity represents a business organization whose infrastructure was impacted by malicious activity, specifically categorized within our catalog as a ransomware victim linked to the interlock threat actor group. This listing reflects the security event documented in our threat-intelligence index, highlighting the intersection of retail technology environments and cyber threats targeting commerce platforms. The record serves as a reference point for stakeholders monitoring ransomware campaigns and their impact across commercial sectors. It neutrally states that wilsonvilletoyota.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services and customer-facing digital offerings typical of modern retail platforms. As cataloged in this threat-intelligence index under the ransomware victim listing type, the entity is associated with the threat actor interlock, indicating a cybersecurity incident of this classification. The entry reflects the organization's documented exposure within the interlock threat actor's activity scope without disclosing unverified technical or operational details. This record serves to inform security professionals, compliance teams, and risk analysts monitoring ransomware incidents across retail and e-commerce environments in the United States. The neutral classification emphasizes the association with interlock as the verified linkage for this listing. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, serving as an entity cataloged as a ransomware victim in the threat-intelligence index. The domain represents a business context where cybersecurity threats, including ransomware incidents, may have been observed or reported against its infrastructure. This listing type indicates association with the interlock threat actor, a group tracked within cyber threat intelligence frameworks for malicious activity targeting commerce environments. The description maintains neutrality regarding specific incident details, avoiding speculation on data compromises, operational impacts, or unverified claims. It serves to document the entity's sector, geographic location, threat association, and classification for analytical and defensive reference purposes. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32879 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, presenting online commerce and customer-facing retail functionalities. As cataloged in this threat-intelligence index under the ransomware victim listing type, the entity is associated with the threat actor interlock. This classification reflects the entity's documented relationship to interlock within the ransomware incident landscape, contextualized by its business sector and geographic location. The description remains neutral and avoids speculative details regarding specific attack mechanisms, data exposure, or operational impact. It serves to inform analysts tracking ransomware victims and threat actor linkages across retail and e-commerce environments. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32880 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services and customer-facing retail functionality. As a ransomware victim, this entity is cataloged within the threat-intelligence index under association with the interlock threat actor. The listing type identifies the entity's status in relation to this specific cyber threat context, reflecting its role as an affected organization rather than a threat source. Catalog records for such entities serve to inform security professionals, compliance teams, and industry stakeholders about potential attack surfaces within targeted sectors. This entry remains neutral and factual, documenting the association without speculating on unverified incident details. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32885 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services and related commercial functionalities. The entity is cataloged in this threat-intelligence index under the classification of ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the observed cybersecurity relationship between the domain/entity and the specified threat actor within the retail technology landscape. No specific incident details, such as data stolen, ransom demands, or breach confirmation evidence, are included per strict factual constraints. The designation serves to inform analysts tracking ransomware activity across e-commerce environments and identify potential correlated threats. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32898 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services and customer-facing digital offerings. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. The listing type identifies the relationship between the organization and the cyber threat actor without disclosing unverified incident details. This entry serves threat analysts and security teams monitoring retail and e-commerce environments for ransomware-related activity. The description remains neutral and factual, focusing solely on the entity's sector, geographic context, listing classification, and the attributed threat actor. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32898 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, based in the United States. The entity represents a business whose infrastructure was impacted by a cyber incident categorized as ransomware activity within threat intelligence indexing frameworks. This listing type identifies the organization as a victim affected by the actions of the interlock threat actor group. The catalog entry provides context for monitoring retail and e-commerce security postures amid evolving ransomware threats targeting commercial sectors. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32899 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is associated with the threat actor interlock in the threat-intelligence index under the ransomware victim listing type. The entity reflects a retail or e-commerce business context in the United States, where cyber incidents may impact operational continuity, customer trust, and digital commerce functions. This entry documents the relationship between the entity and interlock without disclosing unverified incident details, such as stolen data, ransom terms, or confirmed breach specifics. The listing serves as a neutral catalog reference for threat-intelligence professionals monitoring ransomware activity across retail and e-commerce environments. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the US Retail and E-commerce sector, providing online commerce services and related retail functionality. As a ransomware victim entry in the threat-intelligence index, it is associated with the threat actor interlock, reflecting the entity's documented exposure within this intelligence context. The listing type identifies the organization's role in the ransomware threat landscape without disclosing specific incident details, such as data accessed, systems impacted, or remediation actions taken. This catalog entry serves to catalog the entity's relationship to the interlock threat actor for threat-intelligence researchers and defenders monitoring Retail and E-commerce environments. The description remains factual and neutral, aligning with standards for premium threat-intelligence indexing. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, based in the United States, and represents an entity cataloged as a ransomware victim within a threat-intelligence index. Its inclusion reflects threat-intelligence analysis linking the domain or associated organization to malicious activity associated with the interlock threat actor. The listing type identifies the entity's relationship to ransomware incidents without disclosing unverified technical details, breach specifics, or confirmed outcomes. This description provides an authoritative, neutral overview suitable for catalog indexing and cyber-threat-intelligence reference. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector and is identified within this threat-intelligence index as a ransomware victim. The entity is associated with the threat actor interlock, with country context established as the United States. Catalog records for this listing emphasize objective documentation of the incident classification without disclosing unverified technical or operational details. This description serves to contextualize the entity within cyber threat reporting frameworks, maintaining neutrality regarding confirmed breach specifics. The listing type ransomware victim reflects the assessed threat context under which the entity was documented. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector based in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. Catalog entries of this nature provide structured intelligence regarding entities impacted by cyber threats, contextualized by sector, geographic location, and known adversary attribution. No specific incident details such as data stolen, ransom demands, or breach confirmation are included to maintain factual neutrality. This listing serves as a reference point within the broader cyber-threat-intelligence landscape for monitoring and analysis. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector from the United States, providing online commerce services. This entity is cataloged in the threat-intelligence index under the designation ransomware victim, associated with the threat actor interlock. The listing reflects observed security-related activity tied to this actor within the retail digital infrastructure context. No specific incident details such as data stolen, records accessed, ransom demands, or confirmed breach metrics are provided here to maintain factual neutrality. The entry serves as a reference point for threat analysts monitoring retail sector exposure to interlock-linked ransomware activity. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, with its identified location in the United States. The domain represents an organization whose infrastructure or operational systems were affected under the classification of ransomware victim within the threat-intelligence index. This listing type indicates observed or attributed cybersecurity compromise activity associated with the threat actor interlock. The entry provides context for monitoring retail and e-commerce environments facing ransomware-related threats. It neutrally states that wilsonvilletoyota.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce services and customer-facing digital offerings. The domain is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock indicates a cybersecurity incident context relevant to retail and e-commerce threat monitoring. No specific incident details, such as data stolen, ransom demands, or confirmed breach metrics, are included per strict factual guidelines. This entry serves as a neutral reference point for threat analysts tracking ransomware activity in US-based retail and e-commerce environments. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32901 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, based in the United States, and represents a business entity cataloged in a threat-intelligence index under the ransomware victim listing type. The entity reflects incidents affecting commerce-focused organizations where cyber threats may compromise operational continuity, customer trust, and digital commerce infrastructure. Its association with the threat actor interlock contributes contextual intelligence for security teams monitoring retail and e-commerce environments against evolving ransomware activity. This listing type documents the observed relationship between the entity and the specified threat actor without asserting unverified breach details, data losses, or recovery specifics. wilsonvilletoyota.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32942 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the US Retail and E-commerce sector, providing online commerce and retail services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This classification reflects observed cybersecurity intelligence linking the domain and organization to malicious activity attributed to interlock. The entry documents the entity's status within the ransomware victim registry without disclosing unverified incident details. It serves as a reference point for security professionals monitoring retail and e-commerce environments for threats associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33109 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector, with its primary location identified as the United States. The entity represents a business context evaluated within our threat-intelligence index, where it is formally listed as a ransomware victim associated with the interlock threat actor. This classification supports cyber-threat analysis and cataloging efforts focused on identifying affected organizations and their connections to active threat campaigns. The description maintains neutrality regarding specific incident details, as confirmed specifics such as data scope or resolution are not attributed to this entity in available intelligence. Understanding such listings aids security teams in assessing exposure patterns across retail and e-commerce environments. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33110 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the US Retail and E-commerce sectors, providing online commerce services and related retail functionalities. The entity is cataloged in this threat-intelligence index specifically as a ransomware victim associated with the threat actor interlock. This listing type indicates that the organization was impacted by ransomware activity connected to interlock, highlighting potential security vulnerabilities within its digital infrastructure. The description maintains a neutral, encyclopedic tone regarding the entity's classification and its association with the identified threat actor, serving as a reference point for cybersecurity analysts monitoring retail sector threats. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33111 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the Retail and E-commerce sector based in the United States, providing online commerce and retail services. This entity is cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The record documents the entity's classification within cybersecurity threat reporting without detailing specific incident mechanics, data compromises, or operational impacts. Neutral assessment focuses on the verified association and sectoral context for analytical indexing purposes. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33111 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the US retail and e-commerce sector and represents a business entity documented in the threat-intelligence catalog under the ransomware victim listing type. Its inclusion reflects cybersecurity monitoring related to potential ransomware activity affecting retail and online commerce environments. The entity is contextualized by its geographic location in the United States and operational focus on consumer-facing retail and e-commerce services. This entry serves as a reference point within the index for threat actors and associated victim profiles. The listing neutrally states that wilsonvilletoyota.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33111 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, presenting a business context relevant to cyber-threat intelligence indexing. As cataloged under the ransomware victim listing type, this entity is associated with the threat actor interlock, reflecting observed or attributed ransomware activity within its operational environment. The description intentionally avoids inventing specific incident details such as stolen data categories, record counts, ransom amounts, or confirmed breach specifics, maintaining factual neutrality. This entry supports threat-intelligence professionals seeking structured, sector-aware context for ransomware victim identification and actor correlation in retail and e-commerce domains. Its inclusion underscores the importance of monitoring entity-level indicators for proactive security posture assessment. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33111 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce and related commercial services. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. The listing type identifies the entity's relationship to this cyber threat context without disclosing unverified incident details, such as data stolen, records affected, ransom demands, or confirmed breach specifics. This description maintains neutrality and encyclopedic objectivity while incorporating natural keywords including entity name, sector, listing type, threat actor, and country for precise indexing and search relevance. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33111 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce and customer-facing services typical of modern retail platforms. The entity is cataloged specifically as a ransomware victim within the threat-intelligence index, with its association attributed to the threat actor interlock. This listing type indicates that the organization was identified in relation to a cyber threat event involving ransomware activity. The description focuses on verified contextual attributes—sector, geographic location, listing classification, and threat actor linkage—without speculating on unconfirmed technical details, data exposure, or operational impact. Such entries support security teams in mapping victim profiles and correlating retail or e-commerce targets with active threat actor campaigns. |
||||||
| Ransomware | Wilsonville Toyota-Scion id33111 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the United States retail and e-commerce sector, providing online commerce and customer-facing services typical of modern retail platforms. The entity is cataloged specifically as a ransomware victim within the threat-intelligence index, with its association attributed to the threat actor interlock. This listing type indicates that the organization was identified in relation to a cyber threat event involving ransomware activity. The description focuses on verified contextual attributes—sector, geographic location, listing classification, and threat actor linkage—without speculating on unconfirmed technical details, data exposure, or operational impact. Such entries support security teams in mapping victim profiles and correlating retail or e-commerce targets with active threat actor campaigns. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32908 View details | United States | Retail / E-commerce | — | ||
|
wilsonvilletoyota.com operates within the US Retail and E-commerce sector, functioning as an online commerce entity. It has been cataloged in this threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. The entry documents the entity's classification within cybersecurity threat reporting without disclosing unverified incident details. This description maintains neutrality regarding operational specifics while reflecting the confirmed association with interlock as a ransomware victim in the retail digital landscape. |
||||||
| Ransomware | Wilsonville Toyota-Scion id32908 View details | United States | Retail / E-commerce | — | ||
|
Wilsonville Toyota-Scion is a new and used car dealership company. It provides a variety of vehicles, including coupes, convertibles, hatchbacks, sedans, and passenger vans. The company was formed in 2007 and is based in Wilsonville, Oregon |
||||||
| Ransomware | Positive Solutions id20829 View details | United Kingdom | Education | — | ||
|
Positive Solutions High School offers a flexible learning environment with a split session format and a College Credit Program, enabling students to earn college credits while completing high school. The school empowers students with resources for future employment and personal success, emphasizing academic excellence and student accountability. |
||||||
| Ransomware | Positive Solutions id32578 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a ransomware victim within the threat-intelligence index. The entity is associated with the threat actor interlock, with its geographic context identified as the United Kingdom. This listing type categorizes the organization as an affected entity in a ransomware incident context. The entry provides neutral catalog information for threat analysts tracking education sector vulnerabilities and associated actors. No specific incident details such as data stolen, records compromised, ransom amounts, or confirmed breach specifics are included per strict factual guidelines. |
||||||
| Ransomware | Positive Solutions id32578 View details | United Kingdom | Education | — | ||
|
Positive Solutions High School offers a flexible learning environment with a split session format and a College Credit Program, enabling students to earn college credits while completing high school. The school empowers students with resources for future employment and personal success, emphasizing academic excellence and student accountability. |
||||||
| Ransomware | Positive Solutions id32684 View details | United Kingdom | Education | — | ||
|
https:positivesolutions.school is an entity operating within the Education sector located in the United Kingdom. The organization provides school-focused solutions and services aligned with educational infrastructure and operational support needs. It has been cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the intelligence assessment linking the entity to this specific cyber threat actor within the ransomware incident landscape. The description remains factual and neutral, focusing solely on the indexed classification without elaborating on unverified incident details. |
||||||
| Ransomware | Positive Solutions id32685 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school operates within the education sector and serves as a threat-intelligence index entry. Its catalog profile identifies it as a ransomware victim associated with the threat actor interlock. The entity is geographically linked to the United Kingdom, reflecting the GB country designation within the index data. This listing type documents the cybersecurity event classification without disclosing specific technical incident details. The description remains neutral and factual, adhering to threat-intelligence catalog standards for ransomware victim indexing. |
||||||
| Ransomware | Positive Solutions id32685 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as an institution based in the United Kingdom. It is documented within this threat-intelligence index under the classification of ransomware victim, with the associated threat actor or source identified as interlock. The listing reflects the entity's inclusion in cybersecurity threat records concerning ransomware activity within its sector and geographic context. This catalog entry provides neutral, factual context for threat researchers and defenders monitoring education sector vulnerabilities and associated adversary activity. No specific incident details such as data stolen, ransom demands, or breach confirmation are included per strict factual constraints. |
||||||
| Ransomware | Positive Solutions id32686 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the education sector located in the United Kingdom. The organization provides solutions and services aligned with educational needs, though specific operational details remain limited within public threat intelligence records. This listing identifies positivesolutions.school as a ransomware victim associated with the threat actor interlock. Threat intelligence indexing captures such entity-level affiliations to support security awareness and defensive analysis across sectors. The designation reflects observed connections between the entity and the specified threat actor without disclosing unverified incident specifics. |
||||||
| Ransomware | Positive Solutions id32690 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the education sector located in the United Kingdom. It provides educational solutions and services, contributing to the broader digital infrastructure of schools and educational institutions. Within the threat-intelligence index, this entity is specifically listed as a ransomware victim associated with the threat actor interlock. This classification reflects its inclusion in cybersecurity monitoring records concerning ransomware incidents affecting education-focused organizations. The entry serves as a reference point for threat actors, defenders, and analysts tracking ransomware activity within the education sector across the UK. |
||||||
| Ransomware | Positive Solutions id32690 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and serves the GB region, providing solutions aligned to institutional digital safety and operational continuity. As documented in the threat-intelligence index, this entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects observed threat exposure within its sector and geographic context, contributing to broader awareness of risks targeting educational organizations. This entry supports cybersecurity professionals, defenders, and compliance stakeholders in understanding active threat patterns affecting education infrastructure across the UK. |
||||||
| Ransomware | Positive Solutions id32698 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector based in the United Kingdom. The entity provides school-related solutions and services focused on positive educational outcomes and operational support within the education landscape. This listing identifies positivesolutions.school as a ransomware victim linked to the threat actor interlock within the threat-intelligence index. The designation reflects cybersecurity incident status without disclosing confirmed breach details or specific attack mechanics. This catalog entry serves to document the association for threat monitoring and sector-specific risk awareness. |
||||||
| Ransomware | Positive Solutions id32700 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and serves the GB region, providing school-focused solutions aligned with institutional technology and operational needs. As cataloged in the threat-intelligence index, this entity is listed as a ransomware victim associated with threat actor interlock. The listing type reflects its documented relationship to this cyber incident within the intelligence dataset. Descriptions remain neutral and factual, focusing on sector, geographic context, offering classification, and the verified association without speculating on breach details, data scope, or recovery specifics. This entry supports threat-intelligence analysis for Education sector entities in the UK. |
||||||
| Ransomware | Positive Solutions id32700 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and serves the GB region, providing school-focused operational and digital solutions. The entity is formally listed within this threat-intelligence index under the designation ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the observed relationship between the organization and the specified cyber threat actor without disclosing unconfirmed incident details. The catalog entry supports threat-aware monitoring and contextual analysis for entities within critical educational infrastructure. |
||||||
| Ransomware | Positive Solutions id32701 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the United Kingdom market. The entity provides school-related solutions and services, though specific operational details are limited in public threat-intelligence records. This listing identifies positivesolutions.school as a ransomware victim associated with the threat actor interlock. The classification reflects cybersecurity incident indexing rather than confirmed breach details, record counts, or financial impact. Understanding such entries helps security teams assess sector-specific risks within educational infrastructure. |
||||||
| Ransomware | Positive Solutions id32704 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is situated in the United Kingdom. The entity provides educational solutions and services, contributing to the broader education technology landscape. Within the threat-intelligence index, this listing type identifies positivesolutions.school as a ransomware victim associated with the threat actor interlock. This classification reflects the cybersecurity context documented for the entity, highlighting its connection to this specific threat actor group. The description remains factual and neutral, focusing on the indexed attributes without speculating on unverified incident details or operational specifics. |
||||||
| Ransomware | Positive Solutions id32704 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the Education sector located in the United Kingdom. Its name suggests a focus on positive solutions, potentially offering educational technology services, institutional support platforms, or related digital infrastructure within the school and education landscape. Within the threat-intelligence index, this entity is cataloged as a ransomware victim associated with the threat actor interlock. This listing type indicates its inclusion in cybersecurity records due to its connection to this specific threat actor's activity within its sector and geographic region. The description remains neutral regarding incident specifics while accurately reflecting its indexed status. |
||||||
| Ransomware | Positive Solutions id32704 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is located in the United Kingdom. The entity provides school-related services and solutions aligned with educational infrastructure, though specific operational details remain limited within this threat-intelligence catalog context. It is formally cataloged as a ransomware victim associated with the threat actor interlock. This listing type indicates the entity's inclusion in a threat-intelligence index due to its connection to this cyber threat actor within the education sector. The description adheres to neutral, authoritative reporting standards for catalog purposes. |
||||||
| Ransomware | Positive Solutions id32704 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a ransomware victim entry within a threat-intelligence index. The entity is associated with the threat actor interlock, with operational context indicating its location in the United Kingdom. This listing type documents the organization's status as an affected entity in cybersecurity threat monitoring. The description remains neutral and factual, focusing on the entity's classification without elaborating on unverified incident details. Such catalog entries support threat analysts in tracking ransomware incidents across sectors and geographies. |
||||||
| Ransomware | Positive Solutions id32704 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a registered entity within the threat-intelligence index under the classification of ransomware victim. The organization is associated geographically with the United Kingdom and reflects sector-specific exposure patterns relevant to educational institutions. Its inclusion in this ransomware victim listing indicates documented threat intelligence linkage to the interlock threat actor group. This entry provides neutral context for catalog users assessing affected entities, associated actors, and sector-relevant security implications without disclosing unverified incident details. The description adheres to factual, encyclopedic standards for threat-intelligence catalog representation. |
||||||
| Ransomware | Positive Solutions id32704 View details | United Kingdom | Education | — | ||
|
https:positivesolutions.school is an education-sector organization based in the United Kingdom. Its name and sector context indicate its role within institutional education environments, where cyber threats pose significant risks to operational continuity and data integrity. This entity is cataloged within a threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The inclusion reflects its documented relationship to this specific threat actor within the intelligence dataset. This description adheres to neutral, factual reporting standards for catalog entries. |
||||||
| Ransomware | Positive Solutions id32705 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an organization operating within the Education sector based in the United Kingdom. It provides solutions and services aligned with educational technology and institutional support frameworks, contributing to operational resilience within the sector. This entity has been documented within a threat-intelligence index under the classification of ransomware victim, with an associated threat actor or source identified as interlock. The listing reflects the entity's inclusion in cybersecurity threat records for monitoring and defense purposes. Neutral catalog treatment focuses on verified contextual attributes without extrapolating unconfirmed incident details. |
||||||
| Ransomware | Positive Solutions id32705 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and serves the United Kingdom market, providing solutions focused on educational technology and institutional support. The entity is formally listed within this threat-intelligence index under the designation of ransomware victim, with the associated threat actor and source identified as interlock. This classification reflects the cybersecurity context in which the organization has been documented, emphasizing the need for vigilance within education sector infrastructure. The catalog entry serves to inform stakeholders about potential exposure vectors and associated threat landscapes relevant to this specific entity and its sector. |
||||||
| Ransomware | Positive Solutions id32708 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the education sector located in the United Kingdom. It is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor and source identified as interlock. The listing type reflects its classification in relation to a ransomware incident linked to this actor group. This description provides neutral, factual context for catalog users seeking authoritative intelligence on the entity, its sector, geographic location, and its association with interlock as a ransomware victim. No incident specifics such as data theft details, ransom amounts, or confirmed breach statistics are included, maintaining factual neutrality per strict reporting guidelines. |
||||||
| Ransomware | Positive Solutions id32708 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a registered entity in the threat-intelligence index. Its profile is categorized as a ransomware victim, with association to the threat actor interlock. The listing reflects cybersecurity intelligence documentation concerning this entity's exposure within the indexed threat landscape. This description maintains neutrality regarding incident details, focusing solely on the catalog classification and associated attribution. The entity's location is identified as the United Kingdom, sector as education, and listing type as ransomware victim under the interlock attribution. |
||||||
| Ransomware | Positive Solutions id32709 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the United Kingdom market. The entity provides school-focused solutions and services aligned with educational infrastructure needs. Within threat-intelligence indexing frameworks, this organization is specifically listed as a ransomware victim associated with the interlock threat actor. This designation reflects its inclusion in threat-actor attribution datasets concerning ransomware incidents within the education sector. The catalog entry documents the relationship without disclosing unverified technical or operational details. |
||||||
| Ransomware | Positive Solutions id32709 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an education-focused organization based in the United Kingdom. Its offerings and operational scope align with the education sector, providing services relevant to institutional digital security and operational continuity. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This designation reflects its inclusion in intelligence records documenting cybersecurity incidents affecting education-sector entities in the UK. The listing provides context for threat actors, defenders, and security analysts monitoring ransomware activity within targeted sectors. |
||||||
| Ransomware | Positive Solutions id32710 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is situated in the United Kingdom. The entity provides educational solutions and services aligned with institutional needs in the education space. According to the threat-intelligence index, this organization was cataloged as a ransomware victim associated with the threat actor interlock. The listing type identifies the entity's status within the ransomware incident dataset, reflecting the threat actor's operational targeting profile. This entry contributes to broader awareness of education sector vulnerabilities and associated threat actor activity in the GB region. |
||||||
| Ransomware | Positive Solutions id32710 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the United Kingdom market. The entity provides school-focused solutions and services aligned with educational institution needs. It is cataloged in this threat-intelligence index under the ransomware victim listing type. The association with threat actor interlock is documented as part of the index metadata. This entry reflects the entity's classification without disclosing unconfirmed incident details or operational specifics. The listing type identifies the organization within the ransomware victim category associated with interlock. |
||||||
| Ransomware | Positive Solutions id32715 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and is located in the United Kingdom. The entity provides school-focused solutions and services aligned with educational institution needs. It has been formally cataloged as a ransomware victim within a threat-intelligence index, with the associated threat actor or source identified as interlock. This listing reflects the entity's documented relationship to this specific cyber threat actor in intelligence records. No further incident specifics, such as data breach details or financial impact, are included based on available verified information. |
||||||
| Ransomware | Positive Solutions id32715 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the Education sector located in the United Kingdom. Its name suggests a focus on positive solutions, potentially aligned with educational technology, student support services, or institutional management tools within the school environment. The entity is cataloged specifically as a ransomware victim within this threat-intelligence index, with the associated threat actor and source identified as interlock. This listing type indicates its inclusion based on verified threat-intelligence data linking the organization to this actor. The description remains neutral and factual, reflecting the index classification without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | Positive Solutions id32717 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the United Kingdom market, offering services aligned with institutional digital infrastructure and operational continuity needs. The entity is catalogued within this threat-intelligence index specifically as a ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the cybersecurity posture and incident classification observed in external threat monitoring frameworks. The description remains neutral regarding specific breach details, as confirmed incident specifics are not publicly attributed to this entity in official disclosures. Understanding its classification aids security professionals in contextualizing education sector vulnerabilities and evolving threat actor methodologies. |
||||||
| Ransomware | Positive Solutions id32717 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the Education sector based in the United Kingdom. The organization provides solutions and services aligned with positive educational initiatives and sector-specific support frameworks. It has been formally cataloged within this threat-intelligence index under the listing type ransomware victim. The association links the entity to threat actor interlock, reflecting cybersecurity intelligence classification for monitoring and defense purposes. This description maintains factual neutrality regarding the incident context while documenting the verified linkage. |
||||||
| Ransomware | Positive Solutions id32718 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an organization operating within the Education sector, located in the United Kingdom. It provides solutions and services aligned with positive educational initiatives and institutional support frameworks. The entity has been cataloged within the threat-intelligence index under the designation of ransomware victim, linked to the threat actor interlock. This listing reflects the cybersecurity event classification associated with the organization and its connection to the identified threat actor. The description remains factual and neutral regarding the incident classification. |
||||||
| Ransomware | Positive Solutions id32718 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an education sector organization based in the United Kingdom. The entity provides solutions and services within the education domain, serving institutional or educational needs. According to the threat-intelligence index, this organization was listed as a ransomware victim associated with the threat actor interlock. This listing reflects the cybersecurity event documented within the index without disclosing unverified technical details or incident specifics. The entry serves to catalog the entity's involvement within the ransomware threat landscape for analytical and defensive reference. |
||||||
| Ransomware | Positive Solutions id32719 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and serves the GB region, providing school-oriented solutions and services aligned with institutional needs. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects the entity's position within incident-related threat data without disclosing confirmed breach details, affected data volumes, or operational impact specifics. This description maintains neutrality and focuses on the entity's sector, geographic context, listing classification, and associated threat intelligence attribution. |
||||||
| Ransomware | Positive Solutions id32723 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a registered entity within the threat-intelligence index. Its profile is categorized as a ransomware victim, with the associated threat actor identified as interlock. The organization's location is noted as the United Kingdom, reflecting its geographic context within the education sector landscape. This listing type documents the entity's relationship to the specified threat actor without disclosing unverified incident details, ensuring catalog integrity. The entry serves to inform threat intelligence consumers about this specific educational institution's association with interlock in cybersecurity reporting. |
||||||
| Ransomware | Positive Solutions id32723 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a ransomware victim entry within this threat-intelligence index. The entity is associated with the threat actor interlock and is situated in the country GB. Its inclusion reflects a documented security event categorized under ransomware incidents affecting educational organizations. This listing provides context for threat actors, defenders, and analysts monitoring cyber threats within critical infrastructure sectors. The description adheres strictly to verified index metadata without extrapolating unconfirmed breach details. |
||||||
| Ransomware | Positive Solutions id32723 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the United Kingdom. The entity provides solutions focused on educational technology and institutional support, aligning with the sector context of its threat profile. According to the threat-intelligence index, this organization was formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the cybersecurity event documented within the index without disclosing unverified technical details. The listing underscores ongoing vigilance within education sector infrastructure against evolving cyber threats. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a catalog entry under the ransomware victim listing type within this threat-intelligence index. The entity is associated with the threat actor interlock and is noted for its geographic context in the United Kingdom. This listing type reflects the cybersecurity classification applied to organizations impacted by ransomware activity, providing context for threat monitoring and sector-specific analysis. No confirmed breach details, data exfiltration specifics, or financial impact claims are included, adhering to strict factual boundaries. The entry neutrally documents its association with interlock as a ransomware victim entity in the education sector. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the Education sector, located in the United Kingdom. Its name and sector context indicate its involvement within educational technology or services, though specific operational details remain limited in public threat-intelligence records. This listing identifies the entity as a ransomware victim linked to the threat actor interlock, situating it within a cybersecurity incident catalog focused on affected organizations and associated adversary activity. The description maintains neutrality regarding unconfirmed technical specifics, avoiding assertions about data exfiltration, ransom demands, or precise incident timelines. It serves as a factual reference point for threat-intelligence indexing and analyst review of ransomware-related entities in the Education sector across GB. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as a registered entity within the threat-intelligence index under the classification ransomware victim. Its location is associated with the United Kingdom, reflecting the GB country context noted for this listing. The entity represents an organization whose security posture and incident status are documented for analytical and defensive reference purposes within cybersecurity threat intelligence frameworks. This listing type indicates its association with interlock, a threat actor identified in the index metadata. The entry provides neutral catalog information for monitoring and threat-response contexts without disclosing unverified incident details or confirming specific breach elements. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the GB region, providing school-focused solutions and services. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor interlock. This listing reflects verified intelligence concerning the organization's involvement in a cyber incident attributed to interlock. The description remains factual and neutral, focusing on the entity's sector, geographic context, and the nature of its inclusion in the ransomware victim index. No additional incident details such as data stolen, ransom demands, or breach confirmation are provided per strict reporting guidelines. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the Education sector based in the United Kingdom. It provides educational technology and solutions services, contributing to institutional digital infrastructure within the education landscape. This entity has been documented within a threat-intelligence index under the classification of ransomware victim. The association links the entity to the threat actor interlock, reflecting cybersecurity incident intelligence context. This listing serves to catalog verified threat-related data for analytical and defensive reference purposes. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the Education sector and serves the GB region, offering services aligned with institutional digital solutions and student support frameworks. The entity is cataloged in the threat-intelligence index specifically as a ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the cybersecurity assessment of the organization's exposure within the indexed threat landscape. The description remains factual and neutral, focusing on the entity's classification and contextual associations without elaborating on unconfirmed incident details. Understanding such victim profiles aids analysts in mapping attack patterns and sector-specific vulnerabilities. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the education sector located in the United Kingdom. Its name suggests a focus on positive solutions, potentially within educational technology, student support systems, or institutional services. Within the threat-intelligence index, this entity is cataloged specifically as a ransomware victim associated with the threat actor interlock. This listing type indicates its inclusion in records documenting cybersecurity incidents where ransomware activity was observed or attributed to interlock. The description remains neutral, focusing on the entity's classification and contextual sector without speculating on unconfirmed breach details or specific attack mechanics. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the education sector, located in the United Kingdom. Its name and sector context indicate its relevance within educational service environments and institutional security frameworks. The entity is cataloged in this threat-intelligence index specifically as a ransomware victim associated with the threat actor interlock. This listing reflects its documented relationship within cyber threat intelligence records without disclosing unverified incident details. The classification underscores ongoing monitoring of education sector entities impacted by coordinated cyber threats. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is situated in the United Kingdom. The entity provides educational solutions and services aligned with institutional and student support needs. Within the threat-intelligence index, it is cataloged as a ransomware victim associated with the threat actor interlock. This listing reflects the entity's inclusion in cybersecurity threat monitoring data, highlighting its status as an affected organization connected to this specific threat actor profile. The description remains factual and neutral, focusing on the entity's sector, location, and the nature of its listing without speculating on unconfirmed incident details. |
||||||
| Ransomware | Positive Solutions id32725 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the education sector located in the United Kingdom. The organization provides solutions and services aligned with educational needs, though specific operational details are limited in available threat intelligence records. This listing categorizes the entity as a ransomware victim associated with the threat actor interlock. The entry reflects cybersecurity monitoring findings and contributes to broader threat-intelligence indexing for sector-focused risk assessment. Neutral documentation ensures factual representation without speculative claims regarding incident details. |
||||||
| Ransomware | Positive Solutions id32726 View details | United Kingdom | Education | — | ||
|
https:positivesolutions.school operates within the education sector based in the United Kingdom. The entity provides educational solutions and services focused on supporting institutional learning and operational continuity within the GB education landscape. It has been formally cataloged within this threat-intelligence index under the designation of ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the entity's inclusion in cyber threat monitoring records for this specific incident context. The description remains strictly factual regarding sector, location, and listing classification without elaborating on unverified technical or operational details of the event. |
||||||
| Ransomware | Positive Solutions id32726 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the Education sector located in the United Kingdom. The organization provides solutions and services aligned with positive education initiatives. According to the threat-intelligence index, this entity has been classified as a ransomware victim linked to the threat actor interlock. This designation reflects its inclusion in cybersecurity threat records concerning malicious activity targeting education sectors. The listing serves as a reference point for monitoring associated threats and understanding the context of the incident within the GB education landscape. |
||||||
| Ransomware | Positive Solutions id32727 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is located in the United Kingdom. The entity provides school-focused solutions and services aligned with educational infrastructure needs. In the threat-intelligence index, this listing categorizes positivesolutions.school as a ransomware victim associated with the threat actor interlock. This designation reflects its inclusion within cybersecurity monitoring records documenting adversary-targeted environments. The entry serves as a reference point for analysts tracking ransomware activity across education sector organizations in the UK. |
||||||
| Ransomware | Positive Solutions id32728 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves the United Kingdom market. The entity provides educational solutions and services aligned with institutional needs in the education space. It is formally listed within this threat-intelligence index under the designation of ransomware victim, with the associated threat actor or source identified as interlock. This listing reflects the entity's documented relationship to this specific cyber threat actor within the index's catalog. The description adheres strictly to verified index data without extrapolating beyond confirmed details. |
||||||
| Ransomware | Positive Solutions id32729 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the education sector based in the United Kingdom. The organization provides solutions and services aligned with educational needs, though specific operational details remain limited in available threat-intelligence records. This listing identifies the entity as a ransomware victim associated with the threat actor interlock. The classification reflects cybersecurity incident categorization within the threat-intelligence index, highlighting exposure within the education sector context. This description maintains neutrality regarding unconfirmed incident specifics while documenting the verified association. |
||||||
| Ransomware | Positive Solutions id32730 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is situated in the United Kingdom. The entity provides school-related solutions or services, contributing to the educational infrastructure landscape. Within the threat-intelligence index, this organization is specifically listed as a ransomware victim associated with the threat actor interlock. This classification reflects its documented status in cybersecurity threat databases, highlighting exposure within the education sector to coordinated cyber threats. The entry serves as a reference point for monitoring ransomware incidents and associated threat actor activity in educational contexts. |
||||||
| Ransomware | Positive Solutions id32730 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and is situated in the United Kingdom. The entity provides school-focused solutions and services aligned with educational institution needs. It has been documented within a threat-intelligence index under the classification of ransomware victim, specifically associated with the threat actor interlock. This listing reflects cybersecurity incident data compiled by intelligence sources for catalog and analytical purposes. The description remains neutral regarding confirmed breach details, focusing solely on the entity's sector, location, and verified association with the identified threat actor. |
||||||
| Ransomware | Positive Solutions id32732 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the Education sector based in the United Kingdom. It provides educational technology solutions and services focused on supporting learning environments and institutional operations. This listing identifies positivesolutions.school as a ransomware victim associated with the threat actor interlock. The entry serves as a reference point within the threat-intelligence index for tracking incidents involving education-sector entities and specific threat actor activity. The description maintains neutrality regarding the nature of the incident while documenting the association for analytical purposes. |
||||||
| Ransomware | Positive Solutions id32733 View details | United Kingdom | Education | — | ||
|
https://positivesolutions.school is an entity operating within the Education sector, associated with the United Kingdom. Its name and domain context suggest services or infrastructure relevant to educational institutions, though specific offerings cannot be confirmed without verified source documentation. As cataloged in the threat-intelligence index, this listing identifies the entity as a ransomware victim linked to threat actor interlock. This classification contributes to situational awareness regarding cyber incidents affecting education-sector organizations in GB. The description remains neutral and avoids speculation regarding breach details, data exposure, or recovery outcomes. |
||||||
| Ransomware | Positive Solutions id32734 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the education sector located in the United Kingdom. The organization provides school-focused solutions and services aligned with educational technology and operational support needs. It has been formally cataloged as a ransomware victim within a threat-intelligence index, specifically associated with the threat actor interlock. This listing type documents the entity's relationship to a cyber threat event, contributing to a structured repository of affected organizations for security analysis and awareness. The description remains neutral regarding incident specifics, focusing solely on the verified classification and contextual metadata. |
||||||
| Ransomware | Positive Solutions id32737 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity operating within the education sector located in the United Kingdom. The organization provides digital learning and educational solutions, serving students and educators through its platform offerings. According to the threat-intelligence index, this entity has been listed as a ransomware victim associated with the threat actor interlock. This listing reflects the cybersecurity context in which the organization was impacted, highlighting vulnerabilities within education sector infrastructure. The entry serves as a reference point for threat analysts monitoring ransomware activity across educational institutions in the UK. |
||||||
| Ransomware | Positive Solutions id32737 View details | United Kingdom | Education | — | ||
|
positivesolutions.school operates within the education sector and serves as an institution located in Great Britain. Its inclusion in the threat-intelligence index reflects its classification as a ransomware victim associated with the threat actor interlock. This listing type indicates documented threat activity targeting entities within this sector, providing context for security professionals monitoring education-focused organizations. The catalog entry contributes to broader awareness of ransomware campaigns and their impact across critical infrastructure sectors in the United Kingdom. Neutral documentation supports researchers and defenders in understanding patterns of cyber incidents affecting educational entities. |
||||||
| Ransomware | Positive Solutions id32737 View details | United Kingdom | Education | — | ||
|
positivesolutions.school is an entity within the Education sector located in the United Kingdom. It operates within a school or educational services context, providing solutions or services aligned with institutional education needs. Within the threat-intelligence index, this entity is cataloged as a ransomware victim associated with the threat actor interlock. The listing reflects its classification by incident type, sector, geographic origin, and linked adversary, contributing to structured cyber-threat intelligence analysis for education-sector organizations seeking risk awareness and context. |
||||||