Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 59 88.1%
- Pending 7 10.4%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 74 | Onion service | Up checked 4h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 73 | Onion service | Up checked 4h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 72 | Onion service | Up checked 4h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 4h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 71 | Onion service | Up checked 4h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 68 | Onion service | Up checked 4h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 69 | Onion service | Up checked 4h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 67 | Onion service | Up checked 4h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 66 | Onion service | Up checked 4h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 65 | Onion service | Up checked 4h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 63 | Onion service | Up checked 4h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 4h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 4h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 60 | Onion service | Up checked 4h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 58 | Onion service | Up checked 4h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 56 | Onion service | Up checked 4h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 57 | Onion service | Up checked 4h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 55 | Onion service | Up checked 5h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 54 | Onion service | Up checked 5h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 51 | Onion service | Up checked 5h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 43 | Onion service | Up checked 5h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 5h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 5h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 5h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 64 | Onion service | Down checked 4h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 59 | Onion service | Down checked 4h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 53 | Onion service | Down checked 5h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Down checked 5h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 48 | Onion service | Down checked 5h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 49 | Onion service | Down checked 5h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 5h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 46 | Onion service | Down checked 5h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 45 | Onion service | Down checked 5h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 44 | Onion service | Down checked 5h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 42 | Onion service | Down checked 5h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 5h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 39 | Onion service | Down checked 5h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 40 | Onion service | Down checked 5h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 38 | Onion service | Down checked 5h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 5h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 35 | Onion service | Down checked 5h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 36 | Onion service | Down checked 5h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 33 | Onion service | Down checked 5h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 34 | Onion service | Down checked 5h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 32 | Onion service | Down checked 5h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 5h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 29 | Onion service | Down checked 5h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 30 | Onion service | Down checked 5h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 28 | Onion service | Down checked 5h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 27 | Onion service | Down checked 5h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 26 | Onion service | Down checked 5h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 25 | Onion service | Down checked 5h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 24 | Onion service | Down checked 5h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 23 | Onion service | Down checked 5h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 22 | Onion service | Down checked 5h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 21 | Onion service | Down checked 5h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 20 | Onion service | Down checked 5h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 5h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 5h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 5h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 15 | Onion service | Down checked 5h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 16 | Onion service | Down checked 5h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 13 | Onion service | Down checked 5h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 5h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 11 | Onion service | Down checked 5h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 12 | Onion service | Down checked 5h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 10 | Onion service | Down checked 5h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 5h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 5h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 6 | Onion service | Down checked 5h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 7 | Onion service | Down checked 5h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 5h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 4 | Onion service | Down checked 5h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 5h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 19701–19800 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | DaVita id32864 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves clients requiring technology solutions and services, with operations and presence linked to the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the intelligence assessment linking davita.com to an incident attributed to interlock within the ransomware threat landscape. No additional incident specifics, such as data stolen, records affected, ransom demands, or confirmed breach details, are included to maintain factual neutrality and avoid speculation. The entry provides a structured overview for researchers and security professionals monitoring entity exposure and threat actor activity. |
||||||
| Ransomware | DaVita id32864 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves entities requiring technology solutions, infrastructure services, or managed technology support, with operational presence rooted in the United States. The entity is formally listed within the threat-intelligence index under the designation ransomware victim, associated with threat actor interlock. This classification reflects the observed relationship between davita.com and interlock within cybersecurity incident databases, without disclosing unverified details regarding attack methodology or impact. The catalog entry provides neutral context for researchers, defenders, and security professionals monitoring adversary activity across IT environments. Official incident specifics, including notification dates or confirmed breach details, remain outside this descriptive scope. |
||||||
| Ransomware | DaVita id32864 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and professional services to clients. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, specifically associated with threat actor interlock. This designation reflects the inclusion of davita.com within threat-actor activity records linking interlock to a ransomware incident involving this organization. The description remains factual and neutral, focusing on the entity's sector, geographic context, and its classification within the intelligence dataset. No additional incident specifics, such as data stolen, ransom details, or confirmed breach evidence, are included per analytical constraints. |
||||||
| Ransomware | DaVita id32864 View details | United States | IT | — | ||
|
davita.com is a United States-based services sector entity operating within professional and commercial service offerings. The company functions within the broader services industry, providing solutions or services relevant to client needs in its geographic and sectoral context. This listing identifies davita.com as a ransomware victim associated with the threat actor interlock within the threat-intelligence index framework. The entry reflects the entity's classification based on verified intelligence sources without disclosing unconfirmed incident details. It serves as a reference point for monitoring threat actor activity and associated victim profiles. |
||||||
| Ransomware | DaVita id32864 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused organization located in the United States. Its inclusion in this threat-intelligence index reflects its classification as a ransomware victim linked to the interlock threat actor. The listing type identifies davita.com within the ransomware incident catalog, providing context for security researchers and defenders analyzing adversary activity across the technology sector. This entry contributes to broader situational awareness regarding cyber incidents involving entities in the IT domain. The association with interlock underscores ongoing monitoring of ransomware campaigns targeting infrastructure and personnel in this sector. |
||||||
| Ransomware | DaVita id32867 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business customers in the United States, providing technology solutions and services aligned with enterprise information technology needs. As cataloged in this threat-intelligence index, it is designated as a ransomware victim associated with the threat actor interlock. This listing reflects the entity's documented relationship to this specific threat actor within the index's ransomware victim classification. The description remains neutral regarding incident details, focusing solely on the entity's sector, geographic context, listing type, and associated threat actor. |
||||||
| Ransomware | DaVita id32874 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing professional and business-oriented services to clients. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the interlock threat actor group. The listing reflects the cybersecurity context in which davita.com was identified within the index's ransomware incident catalog. No further details regarding specific attack vectors, data handling, or resolution outcomes are included in this entry to maintain factual neutrality and avoid speculation about confirmed breach specifics. |
||||||
| Ransomware | DaVita id32874 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity documented within a threat-intelligence index as a ransomware victim. The company, located in the United States, represents a case where cybersecurity monitoring systems have associated its profile with the threat actor interlock. This listing type indicates that davita.com was identified in relation to a ransomware-associated activity within the broader cyber threat landscape. The description maintains neutrality regarding specific incident details, as confirmed specifics remain outside the scope of this catalog entry. The association with interlock underscores the importance of tracking ransomware victims and their linked actors for threat intelligence purposes. |
||||||
| Ransomware | DaVita id32877 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity documented in the threat-intelligence index under the classification of ransomware victim. The listing associates the entity with threat actor interlock, reflecting the cybersecurity context in which it was identified. This entry provides neutral catalog information regarding the organization's sector, geographic location within the United States, and its designation within threat-intelligence records. No specific incident details, breach confirmations, data losses, or financial impacts are included, adhering to factual and non-inventive reporting standards. The description serves to catalog the entity's relationship with the identified threat actor for analytical and informational purposes. |
||||||
| Ransomware | DaVita id32879 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and service-oriented offerings to clients. In the context of threat intelligence, this entity is listed as a ransomware victim associated with the threat actor interlock. This designation reflects its inclusion within a curated ransomware incident index, intended to inform security teams and analysts about potential attack pathways and affected organizations. The listing emphasizes the relationship between davita.com and interlock without disclosing unverified incident details. Users of this catalog should consult supplementary forensic reports for deeper analysis of the event. |
||||||
| Ransomware | DaVita id32884 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity documented in this threat-intelligence catalog under the ransomware victim listing type. The company is associated with the threat actor interlock, indicating its inclusion in intelligence records concerning cyber incidents affecting IT organizations in the United States. This description maintains factual neutrality regarding the entity's role within the index without disclosing unverified incident details. The listing reflects the cybersecurity community's assessment of davita.com as part of monitored ransomware activity linked to interlock. Authorities and sector observers continue tracking such entities to enhance threat awareness and defensive strategies. |
||||||
| Ransomware | DaVita id32885 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused entity headquartered in the United States. The company provides digital solutions and services aligned with its sector, though specific operational details remain outside verified public disclosures. This entry reflects its classification within a threat-intelligence index as a ransomware victim linked to the threat actor interlock. The description adheres to neutral, encyclopedic standards without attributing unconfirmed incident details. This listing type contextualizes davita.com within cybersecurity intelligence frameworks for monitoring potential risks. |
||||||
| Ransomware | DaVita id32886 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business customers in the United States, providing technology-focused services and solutions. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. This listing reflects the observed relationship between the organization and the identified adversary activity without disclosing unconfirmed technical details or incident specifics. The entry supports threat-aware cataloging for security teams monitoring ransomware exposure across IT environments in the US. |
||||||
| Ransomware | DaVita id32887 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and service-oriented offerings relevant to enterprise environments. The entity has been cataloged in the threat-intelligence index with the listing type ransomware victim, explicitly associated with the threat actor interlock. This classification reflects the intelligence assessment linking davita.com to interlock within the ransomware incident context. The description avoids speculative details regarding data exfiltration, ransom demands, or confirmed breach specifics, adhering to neutral analytical reporting standards. This entry serves as part of the premium catalog for threat-intelligence analysis and monitoring. |
||||||
| Ransomware | DaVita id32887 View details | United States | IT | — | ||
|
davita.com operates within the Services sector based in the United States, providing business and service-oriented offerings to clients and partners. As a ransomware victim listed in the threat-intelligence index, the entity is documented in connection with the threat actor interlock, reflecting a cybersecurity incident within its operational environment. This listing serves as a reference point for analysts monitoring adversary activity, sector-specific vulnerabilities, and potential impact on service-oriented organizations. The entry maintains a neutral, factual perspective without disclosing unverified details regarding attack mechanisms, data exposure, or resolution specifics. Understanding such associations supports proactive defense strategies and threat awareness among security stakeholders. |
||||||
| Ransomware | DaVita id32888 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity identified within a threat-intelligence index under the classification of ransomware victim. The company is situated in the United States and represents a target profile relevant to cybersecurity monitoring and incident analysis. This listing type indicates documented association with the threat actor interlock, contributing contextual intelligence for defenders assessing potential risks and historical attack patterns. The entry provides neutral, factual representation of the entity's categorization without elaborating on unverified breach specifics, operational details, or confirmed incident outcomes. Such catalog data supports comprehensive threat-intelligence research and catalog maintenance. |
||||||
| Ransomware | DaVita id32888 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves entities requiring technology solutions, infrastructure services, or managed technology support. Publicly available information identifies the organization by its domain and sector context, with operational presence linked to the United States. As part of the threat-intelligence catalog, davita.com is categorized as a ransomware victim connected to the interlock threat actor profile. This listing reflects the entity's association within the index without disclosing unverified incident details, such as data exfiltration specifics, ransom demands, or confirmed breach evidence. The record serves to document the relationship between the entity, the threat actor, and the sector context for cybersecurity monitoring and intelligence aggregation. |
||||||
| Ransomware | DaVita id32888 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and professional services to clients across relevant service industries. The entity is formally listed within this threat-intelligence index as a ransomware victim associated with threat actor interlock. This classification reflects the observed relationship between davita.com and interlock in threat-intelligence datasets, without confirming specific breach details, data handling practices, or operational impact. The entry serves to document the entity's sector, geographic context, and its association with interlock for analysts monitoring ransomware activity and victim profiles. |
||||||
| Ransomware | DaVita id32888 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and professional services to clients. The entity is documented within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This classification reflects the intelligence assessment connecting davita.com to interlock's activity without disclosing unverified incident details. The catalog entry serves to inform security professionals and stakeholders about the entity's placement in the ransomware victim index and its attributed threat source. All information remains factual and neutral per strict disclosure protocols. |
||||||
| Ransomware | DaVita id32888 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves clients requiring technology solutions and services from the United States. As documented in the threat-intelligence index, this entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects observed security event correlations without disclosing unverified details regarding intrusion methods, data exposure, or operational impact. This entry supports threat analysts in tracking adversary activity across enterprise technology environments. The inclusion underscores ongoing vigilance for IT sector organizations against coordinated cyber threats. |
||||||
| Ransomware | DaVita id32889 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves entities requiring technology solutions and services, with its operational base located in the United States. The entity is cataloged within this threat-intelligence index under the designation ransomware victim, specifically linked to the threat actor interlock. This listing reflects the association between davita.com and interlock within cybersecurity threat reporting frameworks. The description remains factual and neutral, focusing on the entity's sector, geographic context, and the nature of its inclusion without elaborating on unverified incident details. This entry supports threat-aware decision-making for stakeholders monitoring ransomware activity across IT environments. |
||||||
| Ransomware | DaVita id32889 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves customers requiring technology solutions and services. The entity is located in the United States and represents a business within a sector frequently targeted by cyber threats. In the threat-intelligence index, davita.com is cataloged as a ransomware victim linked to the interlock threat actor. This listing reflects the entity's association with interlock within the ransomware incident context. The description remains factual and neutral, avoiding speculation regarding breach details, data exposure, or operational impact. |
||||||
| Ransomware | DaVita id32889 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused organization based in the United States. The entity is documented in this threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This classification reflects the entity's inclusion in cybersecurity records related to this specific threat actor's activity. The description remains neutral and factual, focusing on the entity's categorization without elaborating on unverified incident details. Davita.com's presence in this index serves to inform defenders and analysts about potential exposure vectors within the IT sector. |
||||||
| Ransomware | DaVita id32889 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused entity headquartered in the United States. The entity is documented within the threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This classification reflects cybersecurity intelligence observations concerning the entity's exposure within the interlock threat landscape. The description remains neutral and avoids speculation regarding specific attack vectors, data handling practices, or incident details. Davita.com is presented as part of a structured catalog designed to support threat-aware analysis across sectors and geographies. |
||||||
| Ransomware | DaVita id32889 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves clients requiring technology solutions and services. As an entity identified in the threat-intelligence index under the ransomware victim listing type, it is associated with the threat actor interlock. This entry documents the relationship between the entity, its sector classification, geographic location in the United States, and the attributed threat actor without disclosing unverified incident details. The catalog description remains neutral and factual, focusing on the entity's categorization within the ransomware victim index and its linkage to interlock for analytical and security reference purposes. |
||||||
| Ransomware | DaVita id32890 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and professional services to clients across relevant service industries. The entity appears in threat-intelligence catalog records under the classification ransomware victim, associated with the threat actor interlock. This listing reflects cybersecurity intelligence indexing of the entity's relationship to this specific threat actor without disclosing confirmed breach details, operational impacts, or unverified claims. The description maintains neutrality and focuses on the documented association for catalog and analytical reference. |
||||||
| Ransomware | DaVita id32890 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business clients with technology-focused solutions and services. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the threat actor interlock. The listing reflects observed cybersecurity intelligence concerning entity involvement and associated adversary activity. This entry provides context for researchers, security professionals, and catalog consumers monitoring ransomware incidents across sectors and geographies. All details remain neutral and factual, avoiding speculative claims regarding attack details, data handling, or financial impact. |
||||||
| Ransomware | DaVita id32891 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and professional services to clients. The entity is formally listed within this threat-intelligence index under the designation ransomware victim. Its association with threat actor interlock indicates a documented cybersecurity incident context tied to this specific adversary group. This catalog entry preserves factual metadata regarding the entity's sector, geographic origin, listing classification, and linked threat actor without speculating on unconfirmed breach details. The record serves threat analysts seeking structured intelligence on ransomware-related entities and their connected actors. |
||||||
| Ransomware | DaVita id32891 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business clients requiring technology solutions and services, with operations and presence linked to the United States. As cataloged in the threat-intelligence index, the entity is classified as a ransomware victim connected to the interlock threat actor. This listing reflects the cybersecurity context in which davita.com was identified within the broader ransomware incident landscape. The description remains factual and neutral, focusing on the entity's sector, geographic context, listing classification, and associated threat actor without attributing unverified incident details. It serves as reference material for threat researchers and defenders monitoring ransomware activity across IT environments. |
||||||
| Ransomware | DaVita id32892 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business clients with technology-focused services and solutions. As a ransomware victim entry in this threat-intelligence index, it is associated with threat actor interlock, indicating a cybersecurity event linked to this adversary group. The listing reflects the entity's presence within the ransomware incident catalog without disclosing specific technical details, data scope, or operational impact. This record supports threat-intelligence analysis for monitoring IT sector exposure and adversary activity in the United States. The description remains neutral and factual, adhering to catalog standards for cybersecurity intelligence documentation. |
||||||
| Ransomware | DaVita id32893 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and professional services to clients within its domain. As documented in the threat-intelligence index, the entity has been categorized as a ransomware victim linked to the threat actor interlock. This listing reflects the cybersecurity context in which davita.com was identified, without disclosing specific incident details such as data stolen, ransom demands, or operational impact. The record serves catalog and analytical purposes for threat monitoring, sector risk assessment, and cross-referencing attacker activity with affected organizations. |
||||||
| Ransomware | DaVita id32896 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and service-oriented offerings relevant to enterprise environments. As cataloged in the threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. This listing reflects the observed relationship between davita.com and interlock within cybersecurity intelligence records, without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. The entry serves to document the entity's sectoral context, geographic origin, and its association with a designated threat actor for analytical and defensive reference. |
||||||
| Ransomware | DaVita id32897 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and client-focused service offerings. This entity is documented within the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The entry reflects the classification of this organization in relation to the identified cyber threat activity. No specific incident details, such as data stolen, ransom demands, or confirmed breach metrics, are included per strict factual constraints. This neutral catalog description serves to inform stakeholders of the entity's presence in the ransomware victim index tied to interlock. |
||||||
| Ransomware | DaVita id32897 View details | United States | IT | — | ||
|
davita.com is an IT-sector company based in the United States, operating within technology services and related offerings. In the threat-intelligence index, it is cataloged as a ransomware victim associated with the threat actor interlock. This listing type indicates a cybersecurity incident context where the entity was impacted by ransomware activity linked to interlock. The description remains factual and neutral, focusing on the entity's sector, geographic location, and its classification within the ransomware victim index tied to interlock. No specific incident details such as data stolen, ransom amounts, or confirmed breach specifics are included per strict reporting rules. |
||||||
| Ransomware | DaVita id32897 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity identified in threat-intelligence indexing. The company is situated in the United States and represents a business context relevant to cybersecurity analysis. Within this threat-intelligence catalog, davita.com is formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the entity's inclusion in records documenting cyber incidents and adversary activity. The description maintains neutrality regarding specific incident details while providing authoritative context for researchers and defenders. |
||||||
| Ransomware | DaVita id32897 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves entities requiring technology solutions and services based in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, explicitly associated with the threat actor interlock. This designation reflects the inclusion of davita.com within the intelligence dataset regarding cybersecurity incidents and adversary activity. The description remains neutral and factual, focusing on the entity's sector, geographic location, and its classification within the ransomware victim index linked to interlock. |
||||||
| Ransomware | DaVita id32897 View details | United States | IT | — | ||
|
davita.com is an IT sector organization headquartered in the United States, providing technology-focused services and solutions for enterprise clients. Within this threat-intelligence index, the entity is formally listed as a ransomware victim associated with threat actor interlock. This classification reflects the cybersecurity context in which davita.com was identified, without disclosing unverified incident details such as data stolen, ransom demands, or specific breach mechanics. The entry serves to document the relationship between the organization and the specified threat actor for monitoring, risk assessment, and defensive intelligence purposes. |
||||||
| Ransomware | DaVita id32899 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves clients requiring technology solutions and services, with its operational presence linked to the United States. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim connected to the interlock threat actor. The listing reflects the entity's association with this specific threat actor within cybersecurity intelligence records. No further incident details, such as data stolen, ransom demands, or confirmed breach specifics, are provided in this catalog entry to maintain factual neutrality and avoid speculation. This description focuses on the entity's sector, geographic context, listing classification, and verified threat association. |
||||||
| Ransomware | DaVita id32899 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused entity based in the United States. The company provides digital solutions and services aligned with enterprise technology requirements. According to the threat-intelligence index catalog, davita.com is formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the entity's inclusion in the index under the ransomware victim classification with the specified threat actor and source attribution. The description maintains factual neutrality regarding the incident association without elaborating on unverified technical or operational details. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves customers requiring technology solutions and services, with operations and presence tied to the United States. The entity is cataloged within a threat-intelligence index under the designation of ransomware victim. This listing reflects an association between davita.com and the threat actor interlock. No specific incident details, such as stolen data, ransom demands, or breach confirmation, are included per strict analytical guidelines. The entry provides neutral context for security professionals monitoring cyber threats and ransomware activity in the technology sector. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and professional services to clients. The entity has been identified within a threat-intelligence index as a ransomware victim associated with the threat actor interlock. This listing reflects the cybersecurity context in which the organization was documented, emphasizing its classification alongside the specific threat actor without disclosing unconfirmed incident details. The description maintains neutrality regarding the nature or scope of the threat event, focusing solely on the verified association and sectoral profile. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity documented in the threat-intelligence index under the designation of ransomware victim. The listing identifies interlock as the associated threat actor or source linked to this entity. As an IT-focused organization based in the United States, davita.com is cataloged for threat-intelligence analysis and monitoring purposes. This entry reflects its classification within the ransomware victim category associated with interlock. The description remains neutral and factual, focusing solely on the entity's sector, geographic location, listing type, and associated threat actor without speculating on incident details. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business clients requiring technology solutions and services. The entity is documented in this threat-intelligence index as a ransomware victim associated with the threat actor interlock. This listing reflects the cybersecurity context in which the organization was identified, without disclosing specific incident details such as data stolen, ransom demands, or breach confirmation. The record supports threat-mapping efforts for monitoring adversary activity and sector-specific risks in the technology industry. Authorities and sector analysts may reference this entry when assessing ransomware trends affecting IT-focused entities in the United States. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business and technology-focused clients, with operations and presence associated with the United States. Within this threat-intelligence index, the entity is classified as a ransomware victim, specifically associated with threat actor interlock. This listing reflects the cybersecurity context in which davita.com was identified, without disclosing unverified incident details such as data stolen, records affected, ransom amounts, or confirmed breach specifics. The entry supports threat-aware cataloging for analysts monitoring ransomware activity across IT-sector organizations in the US. It neutrally records that davita.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity identified within our threat-intelligence catalog under the designation of ransomware victim. The listing associates this organization with threat actor interlock, contextualizing its inclusion within cybersecurity incident records. This description maintains a neutral, encyclopedic tone regarding the entity's classification and associated threat profile without elaborating on unverified incident details. The catalog entry reflects verified intelligence linking davita.com to interlock's activity within the ransomware threat landscape for US-based IT organizations. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and service-oriented offerings relevant to enterprise environments. The entity is formally listed within this threat-intelligence index under the classification ransomware victim. Its association with the threat actor interlock indicates a documented security incident context tied to this actor's activity. This catalog entry provides neutral, factual context for analysts monitoring service-sector exposure and threat actor repercussions without disclosing unverified incident details. The listing type and linked actor serve as core identifiers for threat tracking and intelligence correlation. |
||||||
| Ransomware | DaVita id32900 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and commercial services. The entity is documented in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This classification reflects the index's aggregation of verified incident relationships between organizations and identified threat actors. The entry serves as a reference point for security professionals monitoring service-sector exposure and interlock-related activity. No specific incident details, such as data stolen or ransom demands, are included per strict factual boundaries. |
||||||
| Ransomware | DaVita id32901 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing professional and business-oriented services to clients. Within the threat-intelligence index, this entity is formally listed as a ransomware victim associated with the threat actor interlock. The classification reflects the observed security incident linkage without disclosing unverified details regarding data handling, attack vectors, or operational impact. This entry serves to inform defenders and security practitioners of the entity's documented exposure context within the interlock threat landscape. The description maintains neutrality while accurately representing the indexed relationship between davita.com and interlock. |
||||||
| Ransomware | DaVita id32906 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business clients requiring technology solutions and services, located in the United States. This entity has been cataloged in the threat-intelligence index under the designation ransomware victim, linked to the threat actor interlock. The listing reflects the association between davita.com and interlock within cybersecurity intelligence records. No specific incident details, such as data stolen or ransom demands, are provided here, adhering to strict factual boundaries. This entry supports threat-aware analysis for sector and geographic context. |
||||||
| Ransomware | DaVita id32919 View details | United States | IT | — | ||
|
davita.com is an entity operating within the United States IT sector, providing technology-focused services and solutions relevant to enterprise infrastructure and digital operations. Within this threat-intelligence index, the entity is formally listed as a ransomware victim associated with the threat actor interlock. This classification reflects the cybersecurity context in which the organization was identified, contributing to broader monitoring of ransomware activity across IT environments. The description remains factual and neutral, focusing on the entity's sector, geographic context, listing classification, and the specific threat actor association without adding unverified incident details. |
||||||
| Ransomware | DaVita id32919 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and professional services to clients. This entity is cataloged within the threat-intelligence index as a ransomware victim linked to the interlock threat actor. The listing reflects the association between davita.com and interlock without disclosing specific incident details, such as data stolen, ransom demands, or operational impact. For threat analysts and security professionals, this entry serves as a reference point for monitoring ransomware activity in the Services sector across the US. The classification supports contextual awareness of cyber incidents involving entities in this sector and geographic region. |
||||||
| Ransomware | DaVita id32920 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and service-oriented offerings relevant to enterprise threat analysis. In the context of this threat-intelligence index, the entity is listed as a ransomware victim associated with the threat actor interlock. This listing reflects its inclusion within cybersecurity monitoring records where adversary activity and victim profiles are documented for defensive intelligence purposes. The description remains neutral and avoids speculation regarding breach details, data impacts, or operational consequences. Understanding such catalog entries supports threat-resilience planning and contextual awareness for security professionals tracking ransomware incidents across sectors and geographies. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com is an IT sector entity based in the United States, providing technology-focused services and solutions within its operational domain. As documented in the threat intelligence index, this entity is listed as a ransomware victim associated with the threat actor interlock. The classification reflects the cybersecurity context in which the entity was identified within the index, highlighting its connection to this specific threat actor profile without disclosing unverified incident details. This entry serves to inform security analysts and stakeholders about the relationship between davita.com and interlock within the broader ransomware threat landscape. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused entity headquartered in the United States, providing digital solutions and services relevant to enterprise infrastructure. The entity has been cataloged in the threat-intelligence index under the designation ransomware victim, with interlock identified as the associated threat actor or source. This listing reflects the observed relationship between davita.com and interlock within cybersecurity threat datasets, without disclosing specific incident details such as data exfiltration scope, ransom demands, or confirmed breach elements. The entry serves to inform defenders and analysts about potential exposure vectors and contextual threat intelligence linked to this organization. Neutral documentation ensures transparency while maintaining factual boundaries regarding unverified incident specifics. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and professional services to clients. This entity is cataloged in the threat-intelligence index under the designation ransomware victim, associated with the threat actor interlock. The listing reflects observed threat activity context tied to this organization without disclosing confirmed breach specifics such as data stolen, records accessed, ransom demands, or operational impact. The profile is maintained to support security teams monitoring adversary tactics, victim exposure, and sector-specific risk indicators. It neutrally states that davita.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves clients requiring technology solutions and services. As an entity documented in our threat-intelligence index under the ransomware victim classification, it is associated with the threat actor interlock. This listing reflects the entity's inclusion in the dataset linked to this specific adversary group. The description remains factual and neutral, focusing on the company's sector, geographic origin, and its recognized association with interlock within the ransomware victim context. No additional incident details such as breach specifics, data impacts, or financial losses are included per strict reporting guidelines. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity documented in this threat-intelligence index under the ransomware victim listing type. The company, situated in the United States, is cataloged as having been associated with the threat actor interlock. This entry reflects the entity's inclusion in the ransomware victim classification linked to interlock, without disclosing specific incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. The description adheres to a neutral, encyclopedic tone consistent with threat-intelligence catalog standards, providing contextual context regarding sector, geographic location, listing classification, and associated actor. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and is situated in the United States. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This classification reflects the entity's inclusion in intelligence records documenting cyber incidents involving ransomware activity. The description remains neutral and factual, focusing on the entity's sector, geographic context, listing classification, and linked threat actor without asserting unverified details about the incident itself. All information presented aligns with the provided catalog parameters and avoids speculation regarding breach specifics. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity documented in the threat-intelligence index under the classification of ransomware victim. The company, situated in the United States, is cataloged alongside threat actor interlock, reflecting its association with this cybersecurity incident profile. This listing provides context for security researchers, defenders, and stakeholders monitoring ransomware activity across IT environments. The entry neutrally records the relationship without disclosing unconfirmed incident details such as data stolen, ransom demands, or specific compromise timelines. It serves to inform cyber-threat-intelligence consumers of the entity's status and linked adversary context within the index. |
||||||
| Ransomware | DaVita id32922 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and professional services to clients. The entity has been identified within the threat-intelligence index as a ransomware victim associated with the threat actor interlock. This listing reflects the security community's documented correlation between the organization and the identified malicious activity. The entry serves as a reference point for analysts monitoring service-sector exposure and related threat actor campaigns. No specific incident details, such as data stolen or ransom demands, are included per strict factual disclosure protocols. |
||||||
| Ransomware | DaVita id32963 View details | United States | IT | — | ||
|
davita.com operates within the US IT sector, providing technology-focused services and solutions for enterprise and organizational needs. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim associated with the threat actor interlock. The classification reflects security event attribution within the cybersecurity landscape, highlighting exposure to ransomware-related activity. This entry serves to catalog entity exposure alongside actor context for defensive analysis and intelligence tracking. All descriptions remain factual and neutral regarding incident specifics, adhering to strict non-inventive reporting standards for threat-intelligence documentation. |
||||||
| Ransomware | DaVita id33130 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves entities requiring technology services and solutions, with operations and presence linked to the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This classification reflects the intelligence assessment linking davita.com to interlock within the ransomware incident landscape. The description avoids inventing specific breach details such as data stolen, records accessed, ransom demands, or confirmed loss metrics. It neutrally documents the entity's sector profile, geographic context, and attributed ransomware victim status for catalog and analytical use. |
||||||
| Ransomware | DaVita id33131 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing professional and business-oriented services to clients. Within threat-intelligence indexing frameworks, this entity is formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects its inclusion in cybersecurity monitoring databases where ransomware incidents and correlated adversary activity are documented for risk assessment and defense planning. The entry serves as a factual reference point for security analysts tracking service-sector exposures and adversary-linked victim profiles. No specific breach details, data loss metrics, or ransom terms are included here, maintaining strict neutrality and adherence to verified intelligence sources. |
||||||
| Ransomware | DaVita id33132 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is headquartered in the United States, providing business and professional services to clients. This entity has been identified within a threat-intelligence index as a ransomware victim associated with the threat actor interlock. The listing type reflects the nature of the cybersecurity event documented for this organization, contributing to broader awareness of ransomware activity targeting service-oriented businesses. The entry provides neutral context for threat analysts tracking adversary campaigns and victim disclosures. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | DaVita id33132 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing business and service-oriented offerings to clients and partners. Within the threat-intelligence index, this entity is formally listed as a ransomware victim associated with the threat actor interlock. The classification reflects the observed relationship between the entity and the specified adversary group, contributing to broader analysis of ransomware targeting service-sector organizations in the US. This entry provides neutral context for catalog users tracking incident correlations and threat actor footprints. |
||||||
| Ransomware | DaVita id33132 View details | United States | IT | — | ||
|
davita.com operates within the Services sector and is based in the United States, providing professional and business-oriented offerings to clients and partners. The entity is formally listed within this threat-intelligence index under the designation ransomware victim. Its association with threat actor interlock indicates a documented cybersecurity incident classification relevant to security monitoring and risk assessment. This description adheres to neutral, encyclopedic standards without disclosing unverified incident details such as data stolen, ransom terms, or confirmed breach specifics. The listing serves to contextualize davita.com within the broader landscape of threat actor activity and victim categorization. |
||||||
| Ransomware | DaVita id33132 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as an entity within the threat-intelligence index under the classification of ransomware victim. The company is situated in the United States and represents a target profile relevant to cybersecurity monitoring and threat actor tracking. This listing reflects the association between davita.com and the threat actor interlock within the ransomware victim index. The description maintains neutrality regarding specific incident details, avoiding assumptions about data exfiltration, ransom demands, or confirmed breach specifics. The catalog entry supports analytical workflows for identifying patterns in ransomware targeting IT-sector organizations across the US. |
||||||
| Ransomware | DaVita id33132 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business customers requiring technology solutions and services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the threat actor interlock. This designation reflects the intelligence assessment connecting davita.com to an incident attributed to interlock within the monitored threat landscape. No specific technical details, breach confirmations, data losses, or financial impacts are included in this description to maintain factual neutrality. The entry provides contextual positioning for security professionals evaluating ransomware exposure across IT organizations in the United States. |
||||||
| Ransomware | DaVita id33132 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves business customers requiring technology solutions and services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, linked to the threat actor interlock. This designation reflects the intelligence assessment connecting davita.com to an incident attributed to interlock within the monitored threat landscape. No specific technical details, breach confirmations, data losses, or financial impacts are included in this description to maintain factual neutrality. The entry provides contextual positioning for security professionals evaluating ransomware exposure across IT organizations in the United States. |
||||||
| Ransomware | DaVita id32929 View details | United States | IT | — | ||
|
davita.com operates within the IT sector and serves as a technology-focused entity headquartered in the United States. The company provides digital solutions and services relevant to information technology infrastructure and client support. Within the threat-intelligence index under review, davita.com is categorized as a ransomware victim linked to the threat actor interlock. This listing reflects its association with interlock in the ransomware-victim classification, without confirming specific incident details such as data stolen, records affected, ransom demands, or breach timelines. The entry supports threat-mapping and catalog analysis for entities impacted by cyber incidents in the IT sector. |
||||||
| Ransomware | DaVita id32929 View details | United States | IT | — | ||
|
DaVita Inc. provides kidney dialysis services for patients suffering from chronic kidney failure in the United States. The company operates kidney dialysis centers and provides related lab services in outpatient dialysis centers. It also offers outpatient, hospital inpatient, and home-based hemodialysis services; operates clinical laboratories that provide routine laboratory tests for dialysis and other physician-prescribed laboratory tests for ESRD patients; and management and administrative services to outpatient dialysis centers. In addition, the company offers integrated care and disease management services to patients in risk-based and other integrated care arrangements; clinical research programs; physician services; and comprehensive kidney care services. Further, it engages in the provision of acute inpatient dialysis services and related laboratory services; and transplant software business. |
||||||
| Ransomware | Madison School District Schools id19343 View details | United States | Other | leaked | ||
|
Madison School District is dedicated to providing caring, innovative, and academically strong experiences for our students. Madison School District Schools is a company that employs 250to499 people and has 10Mto25M of revenue. The company is headquartered in Phoenix, Arizona |
||||||
| Ransomware | Madison School District Schools id32599 View details | United States | Other | — | ||
|
madisonaz.org is a domain entity operating within the Other sector based in the United States. As cataloged in the threat-intelligence index, it is classified as a ransomware victim associated with the threat actor interlock. The entity represents an organization or service exposed to the operational impact of this threat actor's activity within its sector and geographic context. This listing provides neutral intelligence context for security professionals monitoring ransomware incidents and associated threat actor relationships. No specific incident details such as data stolen, records affected, ransom demands, or confirmed breach evidence are included, preserving factual integrity. |
||||||
| Ransomware | Madison School District Schools id32599 View details | United States | Other | — | ||
|
Madison School District is dedicated to providing caring, innovative, and academically strong experiences for our students. Madison School District Schools is a company that employs 250to499 people and has 10Mto25M of revenue. The company is headquartered in Phoenix, Arizona |
||||||
| Ransomware | Madison School District Schools id32705 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within the threat-intelligence index. The entity operates in the Other sector and is associated with the US country context. Its listing type identifies it as directly affected by the threat actor interlock, without disclosing confirmed breach details such as stolen data, record counts, ransom terms, or specific incident mechanics. This entry serves as a neutral reference point for threat analysts tracking ransomware-related entities and their associated actors. The description adheres to strict factual boundaries, relying solely on the provided entity attributes and listing classification. |
||||||
| Ransomware | Madison School District Schools id32706 View details | United States | Other | — | ||
|
madisonaz.org is a domain associated with the ransomware victim listing type within this threat-intelligence index. Operating within the Other sector and located in the United States, the entity represents an organization referenced in relation to a cyber incident. The listing type identifies it specifically as a ransomware victim linked to the threat actor interlock, providing context for threat researchers and defenders assessing associated risks and indicators. This description adheres strictly to the provided entity classification, sector, geographic location, and threat actor association without extrapolating unconfirmed incident details. |
||||||
| Ransomware | Madison School District Schools id32706 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within the threat-intelligence index. Operating in the Other sector and located in the United States, the entity represents an organization assessed under threat-intelligence protocols. Its inclusion reflects an association with threat actor interlock, which is documented as the linked ransomware-related source in the index. The description maintains a neutral, authoritative stance, focusing on the entity's classification, geographic context, sector placement, and verified threat-actor linkage without asserting unconfirmed incident details. This entry supports cybersecurity professionals monitoring ransomware exposure patterns and attacker-source correlations across affected organizations. |
||||||
| Ransomware | Madison School District Schools id32707 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within the threat-intelligence index. Operating in the Other sector and located in the United States, the entity is documented as an affected organization associated with the threat actor interlock. The listing type identifies it specifically as a ransomware victim, reflecting its inclusion in intelligence records tied to this actor's activity. This description provides neutral, encyclopedic context for catalog users seeking structured threat-intelligence metadata. The final classification states that madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32711 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within a threat-intelligence index. The entity operates within the Other sector and is associated with the United States. Its inclusion reflects threat-intelligence analysis linking the organization to the threat actor interlock. This listing type identifies the entity's relationship to a ransomware incident without disclosing unverified technical details, data specifics, or financial impact. The description remains neutral and factual, adhering to catalog standards for cybersecurity intelligence documentation. |
||||||
| Ransomware | Madison School District Schools id32711 View details | United States | Other | — | ||
|
madisonaz.org is a domain associated with the Other sector and based in the United States. As cataloged in this threat-intelligence index under the ransomware victim listing type, it represents an entity impacted by the threat actor interlock. The description reflects the indexed classification without asserting unverified details regarding breach scope, stolen information, financial impact, or confirmed attack mechanisms. This entry supports security teams, defenders, and analysts monitoring ransomware activity linked to interlock within relevant sectors and geographic contexts. |
||||||
| Ransomware | Madison School District Schools id32719 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged within a threat-intelligence index under the designation ransomware victim. Operating within the Other sector and associated with the United States, the domain represents an organization referenced in relation to a cybersecurity incident involving the threat actor interlock. The listing type identifies madisonaz.org specifically as a ransomware victim connected to this adversary group. This description reflects the index's classification without attributing confirmed technical findings or operational details beyond the association. madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32721 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged under the ransomware victim listing type within a threat-intelligence index. Operating within the Other sector and situated in the United States, the organization's specific operational scope and offerings remain general within public threat-intelligence records. The entity is formally associated with threat actor interlock, indicating its inclusion in intelligence datasets tracking ransomware-related incidents and affected entities. This description maintains neutrality regarding unconfirmed incident details, focusing solely on the indexed classification and contextual metadata provided by the intelligence source. The listing reflects interlock's attribution of madisonaz.org as a ransomware victim. |
||||||
| Ransomware | Madison School District Schools id32721 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged within the threat-intelligence index under the ransomware victim listing type. Operating within the Other sector and based in the United States, the domain represents an organization subject to cyber threat analysis and monitoring. The entity is specifically linked to the threat actor interlock, indicating its inclusion in intelligence records reflecting potential ransomware exposure or activity. This description maintains neutrality regarding incident specifics, as confirmed details such as stolen data, ransom demands, or precise breach timelines are not provided in available intelligence sources. madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32722 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged under the ransomware victim listing type within a threat-intelligence index. Operating within the Other sector and based in the United States, the domain represents an organization referenced in threat intelligence records concerning malicious activity. The entity is associated with the threat actor interlock, indicating its inclusion in intelligence datasets tracking ransomware incidents and attacker networks. This description maintains neutrality regarding specific incident details, as confirmed only through the index association. madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32725 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within the threat-intelligence index. Operating in the Other sector and located in the United States, the entity represents an organization subject to cyber threat analysis and indexing efforts. Its association with threat actor interlock identifies a specific adversary context tied to this listing. This description maintains a neutral, encyclopedic tone focused on the entity's classification, sector, geographic context, and threat actor linkage without asserting unconfirmed incident details. The listing reflects its designation as a ransomware victim connected to interlock. |
||||||
| Ransomware | Madison School District Schools id32725 View details | United States | Other | — | ||
|
madisonaz.org is a US-based entity operating within the Other sector, cataloged in the threat-intelligence index under the listing type ransomware victim. The domain name suggests a business or service organization, though specific operational details, services, or infrastructure specifics remain limited within available threat-intelligence records. Its inclusion reflects observed threat-actor linkage to interlock, a cyber threat actor identified in intelligence datasets. This entry provides neutral context for security professionals monitoring ransomware incidents and associated adversary activity across sectors and geographies. The listing neutrally states that madisonaz.org was cataloged as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32725 View details | United States | Other | — | ||
|
madisonaz.org is a domain entity operating within the US Other sector, cataloged in the threat-intelligence index as a ransomware victim. The listing identifies interlock as the associated threat actor or source, reflecting the entity's classification within cybersecurity threat datasets. Sector and geographic context provide foundational context for threat analysts monitoring organizational exposure patterns. This entry documents the relationship between the entity and the identified threat actor without disclosing unverified incident details. The record neutrally states that madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32725 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged within the threat-intelligence index under the classification ransomware victim. Operating within the Other sector and associated with the United States, the entity represents a reported incident subject linked to the threat actor interlock. The listing type identifies madisonaz.org specifically as a ransomware victim, reflecting its inclusion in intelligence records tied to this adversary group. No further operational, technical, or disclosure details are asserted here beyond the verified association and categorization provided by the index. This entry serves threat analysts and security professionals seeking structured context on affected entities and their adversary connections. |
||||||
| Ransomware | Madison School District Schools id32725 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged under the ransomware victim listing type within a threat-intelligence index. Operating in the Other sector and located in the United States, the entity represents an organization identified in threat-intelligence records. Its classification reflects its association with the threat actor interlock, contributing contextual data for cybersecurity analysts monitoring ransomware activity. This description adheres to neutral, encyclopedic standards without inventing incident details such as data stolen, records compromised, ransom demands, or confirmed breach specifics. The listing neutrally states that madisonaz.org was identified as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32725 View details | United States | Other | — | ||
|
madisonaz.org is a domain entity categorized within the Other sector and associated with the US location. As a ransomware victim entry in the threat-intelligence index, it represents an organization or entity impacted by malicious cyber activity. The listing type identifies the relationship between madisonaz.org and the threat actor interlock within the catalog framework. The description remains neutral and factual, focusing on the entity's classification, sector, geographic context, and its documented association with interlock as a ransomware victim. No incident specifics such as stolen data, ransom demands, or confirmed breach details are included to maintain accuracy and avoid speculation. |
||||||
| Ransomware | Madison School District Schools id32726 View details | United States | Other | — | ||
|
madisonaz.org is a domain associated with the ransomware victim listing type within this threat-intelligence index. Operating within the Other sector and based in the United States, the entity represents an organization or digital presence evaluated for cyber-threat relevance. The listing identifies its connection to the threat actor interlock, reflecting observed or attributed activity in the cybersecurity landscape. This description maintains factual neutrality regarding the nature of any potential incident without confirming specifics such as data exposure, operational impact, or recovery status. madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32726 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged within a threat-intelligence index under the ransomware victim listing type. Operating within the Other sector and located in the United States, the domain reflects organizational activity relevant to cybersecurity monitoring and incident tracking. As part of the index, it is associated with threat actor interlock, indicating a connection to ransomware activity within the analyzed dataset. The description remains neutral regarding specific incident details, avoiding assumptions about data exposure, operational impact, or confirmed breach specifics. This entry serves to document the entity's classification and threat association for catalog and intelligence purposes. |
||||||
| Ransomware | Madison School District Schools id32729 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged under the ransomware victim listing type within the threat-intelligence index. Operating in the Other sector and associated with the United States, the organization's specific operational profile and offerings are documented at a high level to support threat-context analysis. This entry reflects its classification as a ransomware victim linked to the threat actor interlock, providing neutral reference points for security professionals monitoring cyber incidents and associated actors. No incident specifics, breach confirmations, or unverified claims are included per strict factual guidelines. |
||||||
| Ransomware | Madison School District Schools id32729 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within the threat-intelligence index. Operating in the Other sector and located in the United States, the entity represents an organization subject to cyber threat exposure documented in relation to the threat actor interlock. The listing type identifies madisonaz.org specifically as a ransomware victim associated with interlock, providing context for threat researchers and defenders tracking adversary activity and impacted infrastructure. This entry contributes to broader situational awareness regarding ransomware incidents tied to interlock, without disclosing unverified technical or operational details. The description remains neutral and factual, reflecting the indexed classification only. |
||||||
| Ransomware | Madison School District Schools id32730 View details | United States | Other | — | ||
|
madisonaz.org is a United States-based entity cataloged under the ransomware victim listing type within this threat-intelligence index. The organization operates within a sector context relevant to threat tracking and serves as an indexed reference point for cybersecurity professionals monitoring adversary activity. Its association with the threat actor interlock provides contextual intelligence for analysts assessing ransomware campaigns, source attribution, and potential impact pathways across affected digital environments. This entry maintains a neutral, factual perspective consistent with premium catalog standards for threat-intelligence documentation. |
||||||
| Ransomware | Madison School District Schools id32730 View details | United States | Other | — | ||
|
madisonaz.org is a domain entity categorized under the Other sector based in the United States. As a ransomware victim, it appears within a threat-intelligence index listing tied to the interlock threat actor. The entity's specific operational profile, services provided, and technical context are summarized within this catalog entry to support threat-intelligence analysis and monitoring workflows. This description maintains a neutral, encyclopedic tone consistent with premium threat-intelligence documentation standards. The listing reflects the association between madisonaz.org and interlock as a ransomware victim entity. |
||||||
| Ransomware | Madison School District Schools id32731 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim entity operating within the Other sector and based in the United States. The domain represents an organization subject to threat-intelligence indexing due to its association with the ransomware incident linked to the interlock threat actor. Catalog descriptions for such entities focus on verified affiliations and sector classification rather than speculative incident details. This listing type identifies the entity within a threat-intelligence index to support cybersecurity monitoring, risk assessment, and defensive intelligence workflows. The entry neutrally records that madisonaz.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Madison School District Schools id32731 View details | United States | Other | — | ||
|
madisonaz.org is an entity cataloged within the threat-intelligence index under the listing type ransomware victim. Operating within the Other sector and located in the United States, the domain represents an organization referenced in relation to a cybersecurity incident. The entity is associated with threat actor interlock, indicating a connection to this specific adversary group in threat-intelligence records. No further operational details, such as breach specifics or confirmed data exposure, are provided to maintain factual neutrality and avoid speculation beyond verified index associations. This entry documents the relationship between madisonaz.org and interlock within the ransomware victim classification. |
||||||
| Ransomware | Madison School District Schools id32736 View details | United States | Other | — | ||
|
madisonaz.org is cataloged as a ransomware victim within the threat-intelligence index. Operating in the Other sector and located in the United States, the entity represents an organization subject to cyber threat assessment and indexing. The listing explicitly associates madisonaz.org with threat actor interlock, reflecting its classification as a ransomware victim in this intelligence dataset. This description maintains a neutral, encyclopedic tone without inventing incident details, operational specifics, or unverified claims regarding breach scope, data handling, or response actions. The entry serves to document the entity's status and its linkage to the identified threat actor within the catalog framework. |
||||||
| Ransomware | Madison School District Schools id32736 View details | United States | Other | — | ||
|
madisonaz.org is a domain associated with the Other sector and located within the United States. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. The listing reflects observed intelligence context regarding the entity's involvement and the associated cyber threat profile without disclosing unverified incident details. This entry supports security teams in tracking ransomware-related entities, threat actor attribution, and sector-specific risk indicators for defensive monitoring and investigation workflows. |
||||||