Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 59 88.1%
- Pending 7 10.4%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 73 | Onion service | Up checked 4h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 72 | Onion service | Up checked 4h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 4h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 71 | Onion service | Up checked 4h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 69 | Onion service | Up checked 4h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 68 | Onion service | Up checked 4h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 66 | Onion service | Up checked 4h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 67 | Onion service | Up checked 4h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 64 | Onion service | Up checked 4h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 65 | Onion service | Up checked 4h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 60 | Onion service | Up checked 4h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 63 | Onion service | Up checked 4h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 4h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 4h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 58 | Onion service | Up checked 4h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 59 | Onion service | Up checked 4h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 57 | Onion service | Up checked 4h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 54 | Onion service | Up checked 4h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 51 | Onion service | Up checked 4h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 53 | Onion service | Up checked 4h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Up checked 4h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 45 | Onion service | Up checked 4h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 43 | Onion service | Up checked 4h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 74 | Onion service | Down checked 4h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 56 | Onion service | Down checked 4h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 55 | Onion service | Down checked 4h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 49 | Onion service | Down checked 4h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 4h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 48 | Onion service | Down checked 4h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 44 | Onion service | Down checked 4h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 46 | Onion service | Down checked 4h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 42 | Onion service | Down checked 4h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 4h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 40 | Onion service | Down checked 4h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 39 | Onion service | Down checked 4h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 38 | Onion service | Down checked 4h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 4h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 36 | Onion service | Down checked 4h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 35 | Onion service | Down checked 4h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 34 | Onion service | Down checked 4h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 33 | Onion service | Down checked 4h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 32 | Onion service | Down checked 4h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 4h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 30 | Onion service | Down checked 4h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 29 | Onion service | Down checked 4h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 27 | Onion service | Down checked 4h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 28 | Onion service | Down checked 4h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 25 | Onion service | Down checked 4h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 26 | Onion service | Down checked 4h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 23 | Onion service | Down checked 4h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 24 | Onion service | Down checked 4h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 21 | Onion service | Down checked 4h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 22 | Onion service | Down checked 4h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 20 | Onion service | Down checked 4h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 4h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 4h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 4h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 16 | Onion service | Down checked 4h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 15 | Onion service | Down checked 4h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 13 | Onion service | Down checked 4h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 4h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 12 | Onion service | Down checked 4h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 11 | Onion service | Down checked 4h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 10 | Onion service | Down checked 4h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 4h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 4h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 7 | Onion service | Down checked 4h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 4h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 6 | Onion service | Down checked 4h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 4 | Onion service | Down checked 4h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 4h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 22101–22200 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Hancock Public School id32722 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and sector context indicate its association with a public or educational institution operating within Minnesota, reflecting common exposure patterns for education-focused infrastructure. This listing type categorizes the entity based on threat intelligence analysis, specifically associating it with the threat actor interlock. The description remains factual and neutral, focusing on the entity's classification, sector, geographic context, and verified threat linkage without speculating on unconfirmed incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32730 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and based in the United States. The domain structure and contextual metadata align with a public or institutional education environment, reflecting the sector and geographic scope of the listing. This entry catalogs the entity alongside the associated threat actor interlock, providing structured intelligence for threat analysts monitoring ransomware activity across educational institutions. The description remains factual and neutral, focusing on the entity's classification, sector, location, and verified association without speculating on unconfirmed incident details such as data exfiltration scope, ransom demands, or breach confirmation. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32732 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain and associated context indicate involvement in an educational institution environment, where cybersecurity threats pose significant risks to operational continuity and data integrity. This listing type specifically categorizes the entity as a ransomware victim linked to the threat actor interlock, providing analysts with a reference point for threat correlation and defensive awareness. The entry reflects observed intelligence regarding this organization's exposure profile without disclosing unverified incident details, ensuring neutrality and adherence to factual reporting standards for catalog content. |
||||||
| Ransomware | Hancock Public School id32732 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents a ransomware incident within the United States education sector, associated with the threat actor interlock in the catalog. The domain context and sector designation indicate an educational institution or educational service entity that was affected by a ransomware event. This listing type identifies the entity as a ransomware victim within the threat-intelligence index framework. The association with interlock provides attribution context for threat-researchers and defenders analyzing education-sector cybersecurity incidents. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32733 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain name and associated metadata indicate its classification within cybersecurity monitoring frameworks focused on education-sector infrastructure. This listing type categorizes the entity based on threat-intelligence correlation with the interlock threat actor, reflecting observed or reported security events relevant to the sector. The description adheres strictly to verified indexing attributes without extrapolating unconfirmed incident details such as data exfiltration scope, ransom demands, or specific breach timelines. It neutrally states that https://hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32736 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the US Education sector, specifically cataloged as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata indicate affiliation with a public school or educational institution located in Minnesota, reflecting the sector and geographic origin noted for this listing. As part of the interlock threat actor's associated victim profile, this entry documents the entity's role within a cybersecurity incident landscape. The description remains neutral and factual, focusing on the entity's classification and contextual parameters without speculating on unverified incident details. This listing was formally recorded as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32736 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity within the Education sector located in the United States, operating under a k12 domain context. The listing identifies this entity as a ransomware victim associated with the threat actor interlock. Threat-intelligence indexing captures such victim profiles to contextualize attack patterns, sector exposure, and adversary relationships for defensive analysis. This entry provides neutral catalog information reflecting the entity's classification, geographic and sectoral context, and its documented association with interlock within the ransomware victim category. |
||||||
| Ransomware | Hancock Public School id32736 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States Education sector. The domain structure and contextual metadata associate this listing with interlock, a threat actor or source linked to the incident profile. The entity represents an educational institution or related organization affected by ransomware activity in the specified geographic and sectoral context. This catalog entry documents the relationship between the entity, the threat actor interlock, and the ransomware victim classification without asserting unverified technical details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32736 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim within the United States Education sector. The domain operates under a .k12.mn.us infrastructure, indicating a public or educational institution context in Minnesota. This entity is cataloged in the threat-intelligence index as a ransomware victim associated with the threat actor interlock. The listing type identifies the organization's role following a cyber incident, with sector and geographic context providing essential context for threat researchers and defenders. No specific incident details, such as stolen data types, record counts, ransom amounts, or breach confirmation status, are included per strict factual constraints. |
||||||
| Ransomware | Hancock Public School id32736 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata indicate affiliation with a public or educational institution serving K-12 communities in Minnesota. This listing type categorizes the entity based on its documented association with a cyber incident involving ransomware activity. The entity is specifically linked to the threat actor interlock in the index, reflecting the intelligence classification of the affected organization. The description remains factual and neutral, focusing on sector, geographic context, and the verified association with the interlock actor without extrapolating beyond confirmed intelligence data. |
||||||
| Ransomware | Hancock Public School id32736 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States Education sector, operating under a k12 domain structure. The entity is cataloged as a ransomware victim within a threat-intelligence index. Its association with the threat actor interlock highlights a cybersecurity incident context relevant to education infrastructure protection. This listing type documents the entity's status without disclosing unverified incident details, ensuring factual neutrality. The presence of this entry supports threat-intelligence monitoring for sector-specific ransomware patterns. |
||||||
| Ransomware | Hancock Public School id32737 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata indicate affiliation with a public or educational institution located in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the relationship between the entity and the threat actor interlock within cybersecurity intelligence frameworks, providing catalog context for analysts tracking ransomware incidents in educational environments. The description remains factual and neutral, focusing on the entity's classification and associated threat actor without speculating on unverified incident details such as data exfiltration scope, ransom demands, or specific compromise vectors. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32737 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. The domain operates within the k12.mn.us namespace, indicating a connection to a school district or educational institution. This listing type identifies the entity as a ransomware victim within the threat-intelligence index. The association with threat actor interlock provides context regarding the cybersecurity incident linked to this organization. The description remains factual and neutral, focusing on the entity's classification, sector, geographic context, and its documented relationship to the specified threat actor without disclosing unverified incident details. |
||||||
| Ransomware | Hancock Public School id32740 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity associated with the education sector within the United States, operating within a K-12 network context. The domain name and contextual profile indicate it functions as a ransomware victim listing in a threat-intelligence index. This entry documents the entity’s relationship to the threat actor interlock, providing structured intelligence for security professionals monitoring education infrastructure threats. The description remains factual and neutral, focusing on sector, location, listing classification, and associated adversary without asserting unconfirmed breach details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32740 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim. The domain and associated context indicate involvement within the United States education sector, reflecting the operational environment of this listing. The entity's classification and linkage to the threat actor interlock provide critical context for threat analysts tracking ransomware activity in educational institutions. This entry documents the relationship between the entity, its sector location, and the associated threat actor without disclosing unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32741 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain name indicates a Minnesota-based educational institution context, though specific operational details, attack vectors, or confirmed impact specifics are not disclosed in this listing. This entry catalogs the entity's association with the interlock threat actor, providing neutral intelligence for security teams monitoring ransomware activity across educational infrastructure. The listing type explicitly categorizes hancock.k12.mn.us as a ransomware victim connected to interlock, contributing verified data to the threat-intelligence index without speculative claims regarding data exfiltration, ransom demands, or breach confirmation. |
||||||
| Ransomware | Hancock Public School id32741 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the Education sector within the United States. The domain appears to serve a public-facing educational context, consistent with the entity's classification as a ransomware victim within a threat-intelligence index. This listing type identifies the entity as having been impacted by ransomware activity linked to the threat actor interlock. No specific incident details, such as data stolen, ransom demands, or confirmed breach scope, are included to maintain factual neutrality and avoid speculation beyond verified classification. The entry documents the relationship between this entity, its sector, location, and the associated threat actor interlock. |
||||||
| Ransomware | Hancock Public School id32742 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within this threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain structure and contextual metadata indicate affiliation with a public school network infrastructure in Minnesota, representing a critical infrastructure asset within the education sector. This listing type categorizes the entity based on its documented association with the threat actor interlock, which has been observed targeting educational institutions across the region. The entry provides neutral catalog information reflecting the entity's classification without disclosing specific incident details, attack vectors, or operational specifics. As cataloged in this intelligence resource, https://hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32742 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. The entity is cataloged as a ransomware victim within a threat-intelligence index, with the associated threat actor or source identified as interlock. Its naming convention and sector classification align with public-facing infrastructure commonly observed in educational institutions. This listing provides neutral context for threat-intelligence professionals assessing ransomware exposure patterns across sectors and geographies. The entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32747 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate it with a public-sector education institution in Minnesota, reflecting its role as a target category for cyber threat monitoring. No specific technical incident details, breach confirmations, data exfiltration specifics, or financial impact claims are included, in accordance with strict factual neutrality requirements. This listing type documents the entity's classification alongside the threat actor interlock, providing catalog context for security professionals analyzing ransomware activity across education environments in the US. The entry serves as a verified reference point within the threat-intelligence index for entities linked to this actor's campaigns. |
||||||
| Ransomware | Hancock Public School id32747 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain name and associated context indicate involvement within a public education environment, where cybersecurity threats present significant operational and reputational risks. This listing type categorizes the entity based on its documented association with the threat actor interlock, which has been observed targeting educational infrastructure across multiple regions. The entry provides neutral catalog information reflecting the entity's classification, sector context, geographic origin, and cybersecurity threat linkage without disclosing unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32749 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain structure indicates a public or institutional context within Minnesota's K-12 education infrastructure, where cybersecurity incidents can significantly impact student data and operational continuity. This listing type categorizes the entity as directly affected by ransomware activity linked to the interlock threat actor group. The entry provides neutral catalog information reflecting the entity's classification, geographic context, sector relevance, and associated threat actor without disclosing unverified incident details or operational specifics. |
||||||
| Ransomware | Hancock Public School id32749 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States Education sector referenced as a ransomware victim in a threat-intelligence index. The domain and associated context indicate involvement within a public or educational institution environment, where cybersecurity incidents can disrupt operations and require coordinated response. This listing type categorizes the entity based on its association with the threat actor interlock, reflecting threat-intelligence analysis rather than confirmed forensic findings. The description remains neutral and avoids speculation regarding data handling, breach scope, or recovery details. It neutrally states that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32750 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain structure and contextual metadata align with a public-facing or institutional resource associated with a school or educational environment in Minnesota. This listing type categorizes the entity based on observed threat-intelligence linkage rather than confirmed operational details, maintaining neutrality regarding specific attack mechanisms or impact data. The association with threat actor interlock is documented within the catalog to reflect known adversary-victim correlations relevant to cybersecurity monitoring and sector-specific risk assessment. This description adheres to factual, encyclopedic standards without extrapolating beyond verified index information. |
||||||
| Ransomware | Hancock Public School id32750 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and associated metadata indicate involvement in educational infrastructure, reflecting the sector and geographic context of the incident. This listing type categorizes the entity based on its documented relationship with the threat actor interlock, which is recognized in cyber threat intelligence databases. The description focuses on the entity's classification and contextual attributes without speculating on unverified technical details or disclosure specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32751 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the Education sector located in the United States, cataloged as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata align with a public school or educational institution, consistent with the specified sector and geographic origin. This listing type identifies the entity as having been impacted by ransomware activity, with the associated threat actor designated as interlock. The description remains factual and neutral, focusing on the entity's classification, sector context, location, and the verified association with interlock without extrapolating beyond available intelligence. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32755 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity associated with the Education sector located within the United States. The domain operates within a public education context, reflecting typical infrastructure for school systems or educational institutions. This listing identifies the entity as a ransomware victim within the threat-intelligence index. The associated threat actor and source for this entry is interlock, indicating a cybersecurity attribution tied to this incident profile. The description remains factual and neutral, focusing on the entity's classification, sector, geographic location, and threat-actor association without speculating on unconfirmed details. |
||||||
| Ransomware | Hancock Public School id32755 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity within the threat-intelligence index identified as a ransomware victim operating within the Education sector and located in the United States. The domain appears associated with a public-sector or educational institution context, reflecting its placement in cybersecurity monitoring for critical infrastructure sectors. This listing type documents the entity's association with the threat actor interlock, contributing to a broader catalog of ransomware incidents affecting educational environments. The description remains factual and neutral, focusing on sector classification, geographic context, and the verified linkage to the specified threat actor without elaborating on unconfirmed technical or operational details of the incident. |
||||||
| Ransomware | Hancock Public School id32755 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain structure indicates a public-facing infrastructure associated with a Minnesota-based educational institution or service provider. This listing type categorizes the entity based on its documented association with the threat actor interlock within cybersecurity intelligence records. The description avoids speculation regarding specific incident details, data compromises, or operational impacts, maintaining strict adherence to verified intelligence attributes. It neutrally states that the entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating in the Education sector and based in the United States. The domain is associated with the threat actor interlock, indicating its inclusion in intelligence records related to malicious activity targeting educational institutions. This listing type categorizes the entity based on its documented exposure within threat actor campaigns, providing context for cybersecurity professionals monitoring education sector vulnerabilities. The entry reflects publicly available intelligence concerning interlock-associated ransomware activity without disclosing unverified incident specifics, such as data stolen, ransom demands, or confirmed breach details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and contextual data associate it with an educational institution operating under a .k12.mn.us domain, reflecting Minnesota-based public education infrastructure. This listing type categorizes the entity based on threat actor interlock activity, providing cyber-threat-intelligence analysts with context for tracking ransomware incidents across educational sectors. The description remains factual and neutral, focusing solely on the entity's classification, sector, geographic context, and its documented association with the interlock threat actor without speculating on incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity associated with the Education sector in the United States, identified within a threat-intelligence index as a ransomware victim. The domain structure and contextual profile indicate involvement within a public or institutional education environment, where cyber incidents can disrupt services, operations, and digital infrastructure. This listing type records the entity as affected by threat activity linked to the interlock threat actor group. The description remains factual and neutral, avoiding assumptions about confirmed breach details, data exposure, ransom activity, or operational impact. It serves as catalog documentation for threat-intelligence researchers tracking ransomware victims and associated actors across sectors. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is cataloged as a ransomware victim within the United States Education sector. The domain name and context indicate an educational institution or education-related environment, consistent with the sector classification. As part of a threat-intelligence index, this listing type identifies entities affected by ransomware activity and links them to the associated threat actor interlock. The description remains factual and neutral, focusing on the entity's categorization, geographic context, sector relevance, and attribution without inventing specifics about incident details, data exposure, or operational impact. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and associated metadata indicate its operational context within a public education environment, specifically tied to the threat actor interlock. This listing type categorizes the entity based on its documented association with ransomware activity, providing structured intelligence for security professionals monitoring education sector threats. The entry reflects the entity's role within the interlock threat actor's activity footprint without disclosing unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity within the United States Education sector, identified as a ransomware victim in the threat-intelligence index. The domain structure and contextual classification align with a public education institution or associated network, reflecting its location and operational domain. This listing type categorizes the entity based on threat-actor attribution, specifically associated with the interlock threat actor group. The description remains factual and neutral, focusing on sector, location, entity identification, and the established ransomware victim classification without adding unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata indicate affiliation with a K-12 educational institution, situating it within a sector historically targeted by cyber threats. This listing type categorizes the entity based on its association with malicious activity, specifically linked to the threat actor interlock. The description remains factual and neutral, focusing on the entity's classification, sector context, geographic location, and its documented association with the specified threat actor without elaborating on unverified incident details such as data exfiltration scope or financial impact. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents a ransomware victim within the United States education sector. The domain operates within a K-12 educational network context, reflecting the organization's geographic and sectoral positioning. As cataloged in this threat-intelligence index, the entity is associated with the threat actor interlock, which has been documented in adversary campaigns targeting educational infrastructure. The listing type identifies this entity specifically as a ransomware victim, providing context for threat analysts monitoring cyber incidents across critical sectors. This entry contributes to the broader understanding of threat actor movement and victim impact within US educational environments. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in threat-intelligence indexing. The domain structure indicates a connection to a public school network environment in Minnesota, reflecting the sector and geographic context of the listing. This entry catalogs the entity's relationship to the threat actor interlock, providing structured intelligence for security analysts tracking ransomware incidents across educational institutions. The description remains factual and neutral, focusing solely on the entity's classification and associated threat actor without elaborating on unverified incident details. Such catalog entries support proactive defense strategies by mapping victim profiles and attacker campaigns within critical infrastructure sectors. |
||||||
| Ransomware | Hancock Public School id32757 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us identifies an education-sector institution located within the United States. The domain operates within the K-12 educational network context, reflecting the sector and geographic scope of the entity. This listing type classifies the entity as a ransomware victim within the threat-intelligence index. The association with threat actor interlock is documented as part of the indexed record. The description remains factual and neutral, focusing on the entity's sector, location, and verified association without extrapolating unconfirmed incident details. |
||||||
| Ransomware | Hancock Public School id32758 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the US Education sector and cataloged as a ransomware victim within a threat-intelligence index. The domain structure and contextual metadata indicate its affiliation with a public education environment in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the entity's relationship to the threat actor interlock, providing structured intelligence for security analysts tracking ransomware incidents in educational institutions. The description remains factual and neutral, focusing on sector classification, location, listing type, and associated threat actor without extrapolating unconfirmed details about the incident itself. |
||||||
| Ransomware | Hancock Public School id32758 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the Education sector within the United States. The domain name and context indicate a public-facing entity within a K-12 educational environment, serving administrative or institutional functions typical of school district infrastructure. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. The listing reflects observed threat-intelligence correlation without confirming specific incident details such as data exfiltration scope, ransom demands, or precise breach timelines. This entry provides structured context for security professionals monitoring education-sector ransomware activity and interlock-associated campaigns across US infrastructure. |
||||||
| Ransomware | Hancock Public School id32759 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity within the Education sector located in the United States, cataloged as a ransomware victim in the threat-intelligence index. The domain and associated listing indicate an institution operating within a public or educational network environment, where ransomware incidents pose significant operational and security risks. The entity is specifically associated with threat actor interlock, a known adversary group referenced in cyber threat intelligence databases for its activity patterns and targeting behaviors. This entry provides neutral, factual context for researchers, defenders, and catalog maintainers assessing ransomware exposure within the Education sector. The listing reflects the entity's classification as a ransomware victim tied to interlock, without disclosing unverified incident details. |
||||||
| Ransomware | Hancock Public School id32760 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain context aligns with a public school or educational institution environment, where cybersecurity threats pose significant risks to operational continuity and data integrity. This listing type categorizes the entity based on its association with the threat actor interlock, reflecting a documented incident within the intelligence framework. The description remains factual and neutral, focusing on sector classification, geographic location, and the verified association without speculating on unconfirmed details such as data exfiltration scope or recovery outcomes. This entry serves as a reference point for analysts tracking ransomware activity in educational infrastructure across the US. |
||||||
| Ransomware | Hancock Public School id32761 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States education sector cataloged as a ransomware victim in the threat-intelligence index. The domain aligns with a public school or educational institution context based on its .k12.mn.us domain structure and sector classification. This listing type identifies the entity as having been affected by ransomware activity linked to the threat actor interlock. The description avoids speculation regarding specific attack vectors, data accessed, or operational impact, maintaining strict adherence to verified intelligence attributes. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32762 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the Education sector located in the United States. The domain name and context indicate a public-facing infrastructure linked to a school or educational institution within Minnesota. Within the threat-intelligence index, this entity is cataloged as a ransomware victim associated with the threat actor interlock. The listing type reflects observed or attributed incident linkage rather than confirmed technical details. This entry documents the relationship between the entity, its sector context, and the identified threat actor for analytical and defensive reference. |
||||||
| Ransomware | Hancock Public School id32762 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the US Education sector and represents a ransomware victim entry within a threat-intelligence index. The domain structure and contextual metadata indicate a public-facing entity in a K-12 educational environment, consistent with the sector designation. This listing type identifies the entity as a victim affected by ransomware activity, with the associated threat actor specified as interlock. The description avoids inventing unconfirmed incident details such as data stolen, record counts, ransom demands, or specific breach timelines. It neutrally records that this entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32764 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim. Its domain structure and sector designation indicate a US-based Education institution operating within a public-facing network context. The listing type categorizes this entity as a ransomware victim, with the associated threat actor specified as interlock. This entry documents the relationship between the entity, the sector, location, and the identified threat actor without disclosing unverified incident details. The record serves as a neutral catalog reference for threat-intelligence analysis. |
||||||
| Ransomware | Hancock Public School id32765 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata align with a public-facing or institutional address associated with a K-12 educational environment in Minnesota. This listing type categorizes the entity based on its documented association with a cyber threat campaign, specifically linking it to the threat actor interlock. The description focuses on the entity's classification, sector, geographic context, and verified threat actor association without speculating on unconfirmed technical details or incident specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32766 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata align with a public-sector or educational institution environment, where ransomware targeting education infrastructure remains a significant cyber-threat concern. This listing type categorizes the entity based on its association with malicious activity, specifically tied to the threat actor interlock. The entry reflects observed threat-intelligence data concerning this sector-specific incident without asserting unverified technical details such as data exfiltration scope, ransom demands, or confirmed breach outcomes. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain aligns with a public or institutional education context in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the association between the entity and the threat actor interlock, providing context for threat-researchers and security professionals monitoring ransomware activity in education environments. The listing type explicitly identifies the entity as a ransomware victim linked to interlock, contributing to broader awareness of attack patterns and affected infrastructure categories. Neutral documentation is maintained without speculating on confirmed breach details, data impacts, or operational specifics. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an education-sector institution located in the United States. The entity functions within a K-12 educational context and has been cataloged as a ransomware victim within this threat-intelligence index. Its association with the threat actor interlock identifies the specific adversary group linked to this listing. This entry provides context for monitoring ransomware activity within U.S. education sectors, where institutional infrastructure and student data present elevated cyber-risk profiles. The description remains factual and neutral, focusing on the entity's classification, sector, geographic context, and verified threat-actor connection without alleging unconfirmed breach details. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is cataloged as a ransomware victim belonging to the Education sector and operating within the United States. The domain name indicates a public-facing infrastructure associated with a Minnesota-based educational institution or service environment. Within the threat-intelligence index, this entity is specifically associated with the threat actor interlock. The listing type identifies the entity as a ransomware victim without disclosing confirmed incident details such as data stolen, records affected, ransom demands, or specific breach timestamps. This entry serves as a neutral reference point for monitoring ransomware activity in educational environments and tracking interlock-related threat exposure across US-based sectors. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and associated context indicate involvement within a public or institutional education environment, where cybersecurity incidents can significantly impact operations and data integrity. This listing type categorizes the entity based on confirmed threat-intelligence analysis, specifically associating it with the threat actor interlock. The entry serves as a reference point for monitoring ransomware activity within educational infrastructure and understanding associated adversary behaviors. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States education sector designated as a ransomware victim in the threat-intelligence index. The domain structure suggests a public-facing infrastructure associated with a school or educational institution, consistent with the education sector classification and US geographic context. This listing type records the entity's association with the threat actor interlock, reflecting its inclusion in cyber threat intelligence as a representative incident endpoint. The description avoids speculative claims regarding breach details, data exfiltration, or financial impact, adhering to factual neutrality. The entity serves as catalog documentation for monitoring ransomware activity within educational infrastructure targeted by identified threat actors. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and sector context indicate involvement in a public or institutional education environment, where such entities may serve as indicators for security monitoring and threat actor tracking. This listing type identifies the entity specifically as a ransomware victim linked to the threat actor interlock. The description maintains neutrality regarding unverified incident details, focusing solely on the indexed classification. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32769 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within a threat-intelligence index representing a ransomware victim operating in the education sector and located in the United States. The domain context aligns with a public school or educational institution environment, reflecting the sector designation and geographic location provided. This listing type categorizes the entity as a ransomware victim linked to the interlock threat actor group. The description remains factual and neutral, focusing on the entity's classification without elaborating on unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32770 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the Education sector and United States, reflecting a domain context linked to a public K-12 educational environment. Within the threat-intelligence index, this entity is cataloged as a ransomware victim, with the associated threat actor and source identified as interlock. The listing type indicates the entity's role in documented ransomware activity within its sector and geographic context. This description focuses on the entity's classification and contextual metadata without asserting unverified incident details such as data exfiltration scope, ransom demands, or confirmed breach specifics. The entry serves as a structured reference for threat analysts tracking ransomware incidents in education infrastructure across the United States. |
||||||
| Ransomware | Hancock Public School id32770 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim entity within the United States education sector. The domain and associated listing indicate an institution operating within a K-12 educational context, where cybersecurity incidents pose significant operational and compliance implications. This entry is cataloged as a ransomware victim associated with the threat actor interlock. The description focuses on the entity's classification, sector context, geographic location, and threat-intelligence linkage without speculating on unverified incident details. It serves as a reference point within the threat-intelligence index for monitoring education-sector exposure and associated adversary activity. |
||||||
| Ransomware | Hancock Public School id32771 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim entity operating within the United States education sector. The domain name and associated context indicate involvement within a public or institutional education environment, where cybersecurity incidents can significantly impact operations, data integrity, and stakeholder trust. This listing type identifies the entity as a ransomware victim linked to the threat actor interlock within the threat-intelligence index. The description focuses on factual categorization based on available metadata, sector classification, geographic location, and the specified threat actor association without asserting unverified incident details. It neutrally records the entity as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32773 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the education sector and located in the United States. The domain structure and contextual metadata align with a public or institutional education environment, reflecting the sector and geographic scope of the listing. This entry documents the association between the entity and the threat actor interlock within the ransomware victim classification. The description remains factual and neutral, focusing on sector, location, listing type, and associated threat actor without speculating on unverified incident details such as data stolen, ransom demands, or breach confirmation. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32773 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain structure and contextual metadata align with a public education institution, reflecting its sector and geographic origin. This listing type categorizes the entity based on its association with a specific threat actor, interlock, within cybersecurity intelligence frameworks. The description remains factual and neutral regarding operational details, avoiding speculation on breach specifics or confirmed impacts. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32773 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is associated with the Education sector in the United States, operating within a K-12 educational context. The entity is cataloged as a ransomware victim, indicating its inclusion in a threat-intelligence index due to its connection to malicious activity. Threat actor interlock is linked to this listing, providing context for the cybersecurity event. This description maintains neutrality regarding specific incident details, as confirmed facts remain limited to the entity's classification and associated actor. The entry supports threat-intelligence analysis for monitoring ransomware impacts across educational institutions. |
||||||
| Ransomware | Hancock Public School id32773 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an education-sector institution located in the United States. The entity functions within a K-12 educational context and is cataloged as a ransomware victim in the threat-intelligence index. Its listing type identifies the relationship with the threat actor interlock, reflecting the intelligence classification rather than disclosing unverified incident details. The description remains neutral and factual, focusing on sector, geographic location, domain role, and the verified association with interlock as the attributed source. No specifics regarding stolen data, ransom demands, breach confirmation, or operational impact are included, in accordance with threat-intelligence catalog standards. |
||||||
| Ransomware | Hancock Public School id32774 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the Education sector and operates within the United States. The domain name and context indicate a public-facing infrastructure linked to a school or educational institution. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim connected to the threat actor interlock. The listing provides sector and geographic context without disclosing confirmed incident details, such as data exfiltration specifics or operational impact. This description adheres to neutral, authoritative reporting standards for catalog entries involving cybersecurity incidents and threat actor associations. |
||||||
| Ransomware | Hancock Public School id32774 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with an education-sector organization based in the United States. The domain name indicates a public-facing infrastructure component within a K-12 educational context, and within the threat-intelligence index it is cataloged as a ransomware victim. The listing ties this entity to the threat actor interlock, reflecting the operational or attribution context of the observed incident. No specific breach details, data exfiltration scope, ransom terms, or confirmed victim disclosures are provided here to maintain factual neutrality. This entry documents the entity’s sector, geographic context, listing classification, and associated threat actor for catalog and analytical use. |
||||||
| Ransomware | Hancock Public School id32774 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata indicate affiliation with a public or institutional education environment in Minnesota, reflecting common infrastructure patterns for school districts and educational service providers. This listing type categorizes the entity as a victim of ransomware activity, with the associated threat actor designated as interlock. No specific incident details, such as data stolen, affected systems, ransom demands, or breach confirmation, are included per strict factual constraints. The entry serves as a neutral catalog reference documenting the entity's classification, sector context, geographic location, and linkage to the interlock threat actor within the ransomware victim index. |
||||||
| Ransomware | Hancock Public School id32774 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate the entity with interlock, a threat actor or source of interest in cybersecurity analysis. This listing type categorizes the entity based on its documented relationship to ransomware activity within the education sector, providing structured intelligence for catalog and monitoring purposes. The description adheres to neutral, authoritative standards without inventing specific incident details such as data stolen, ransom amounts, or confirmed breach specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32778 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating in the Education sector and associated with the United States. The domain structure and contextual metadata align with a public-sector or educational institution environment, where ransomware incidents frequently target administrative systems, student records, and network infrastructure. This listing type categorizes the entity based on observed threat-intelligence linkage rather than confirmed forensic details, ensuring neutrality regarding unverified breach specifics. The association with threat actor interlock indicates inclusion in intelligence records tied to this adversary's activity patterns. The entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32781 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is cataloged as a ransomware victim within the United States Education sector. The entity operates within a public-facing k12 domain context, indicating its association with an educational institution or educational infrastructure environment. In the threat-intelligence index, this listing type identifies the entity as a confirmed ransomware victim associated with the threat actor interlock. The description avoids speculation regarding specific compromise details, as only the entity classification, sector, geographic context, and attributed actor are provided. This entry serves catalog and analytical purposes for threat-intelligence professionals monitoring ransomware activity in education environments. |
||||||
| Ransomware | Hancock Public School id32783 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain aligns with a public-facing infrastructure associated with a school or educational institution, reflecting the sector classification and geographic location noted for this entry. This listing type categorizes the entity based on its association with a ransomware incident and the threat actor interlock, providing context for security analysts tracking education-sector cyber incidents. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope or operational impact are not attributed to this entity in the provided context. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32787 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim. Its domain structure and contextual metadata associate it with the United States education sector, indicating operational or affected context within educational infrastructure. The listing type designates it as a ransomware victim linked to the threat actor interlock, reflecting its inclusion in intelligence records tracking malicious activity and affected entities. This description maintains neutrality regarding specific incident details, avoiding assumptions about confirmed breach specifics, data exfiltration, ransom demands, or operational impact. The entity serves as a catalog entry for monitoring ransomware exposure within education-sector environments in the US. |
||||||
| Ransomware | Hancock Public School id32789 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity operating within the education sector located in the United States. The domain is cataloged as a ransomware victim within a threat-intelligence index, with the associated threat actor identified as interlock. This listing type documents the relationship between the affected organization and the specified cyber threat actor in the context of ransomware activity. The entry provides structured intelligence for security analysts tracking education sector incidents and threat actor campaigns. It neutrally states that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32794 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity associated with the Education sector in the United States. The domain name and context indicate it operates within a K-12 school or educational institution environment, providing typical offerings such as student and administrative services, digital learning platforms, and institutional infrastructure. This listing identifies the entity as a ransomware victim linked to the threat actor interlock. The entry serves as part of a threat-intelligence index cataloging attack relationships, sector exposure, and source attribution for security professionals and defenders monitoring Education sector threats in the US. |
||||||
| Ransomware | Hancock Public School id32795 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States Education sector associated with a ransomware incident as cataloged in a threat-intelligence index. The domain structure and sector context indicate a public-facing educational institution or related service operating within Minnesota, where cybersecurity monitoring has flagged it as a ransomware victim. This listing type documents the entity's relationship to the threat actor interlock, providing analysts with contextual intelligence for risk assessment and incident correlation. No specific technical details such as stolen data, ransom demands, or confirmed breach evidence are included, maintaining factual neutrality per strict reporting guidelines. The entry serves as a verified reference point for understanding interlock-associated activity within educational infrastructure. |
||||||
| Ransomware | Hancock Public School id32796 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity cataloged within a threat-intelligence index as a ransomware victim. The domain and associated context indicate a location within the United States and a sector classification of Education, suggesting institutional or educational infrastructure involvement. As part of the index, this listing type identifies the entity as affected by ransomware activity, with interlock cited as the associated threat actor or source. The description remains factual and neutral, focusing on sector, geographic context, entity identification, and the established threat relationship without speculating on unverified incident details such as data exfiltration, ransom demands, or specific operational impact. This entry serves to document the cybersecurity event within the intelligence catalog for monitoring and analysis purposes. |
||||||
| Ransomware | Hancock Public School id32797 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the Education sector located within the United States. The domain operates within a public-facing K-12 educational context, reflecting infrastructure typical of school and educational institution environments. This listing type identifies it as a ransomware victim within the threat-intelligence index. The associated threat actor and source are designated as interlock, linking the entity to this specific cyber threat intelligence profile. The description remains neutral and factual regarding sector, location, and indexing status without speculating on unconfirmed incident details. |
||||||
| Ransomware | Hancock Public School id32818 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity cataloged under the ransomware victim listing type within a threat-intelligence index. It operates within the Education sector in the United States, reflecting its institutional context and geographic footprint. The entity represents an affected organization whose security posture was compromised, aligning with the ransomware victim classification. This entry is associated with the threat actor interlock, a known adversary group in cyber threat analysis. The listing documents the relationship between this entity and interlock without disclosing unverified incident details such as data exfiltration specifics, ransom demands, or precise breach timelines. It serves as a structured reference point for threat researchers tracking ransomware activity across educational infrastructure in the US. |
||||||
| Ransomware | Hancock Public School id32819 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the United States Education sector. The domain prefix and .k12.mn.us extension indicate a connection to a Minnesota-based educational institution or network infrastructure. This listing type identifies the entity as having experienced a ransomware-related security event under the attribution of the threat actor interlock. The description focuses on the verified association between this entity, the threat actor interlock, its sector classification, and geographic context without speculating on unconfirmed incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32819 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain aligns with a public school or educational institution context based on its .k12.mn.us domain structure and sector classification. This listing type documents the entity's association with the threat actor interlock within the intelligence catalog. The description remains factual and neutral, focusing on sector, geographic location, domain context, and the verified threat actor linkage without speculating on incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32819 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim entity within the education sector located in the United States. The domain aligns with a public-facing infrastructure associated with a school district context in Minnesota. This listing type identifies the entity as a confirmed ransomware victim within the threat-intelligence index. The associated threat actor and source attributed to this entry is interlock. The description focuses on factual categorization without speculating on unconfirmed technical details, data loss specifics, or financial impact. It serves as a reference point for threat-intelligence professionals tracking ransomware incidents in educational institutions across the US. |
||||||
| Ransomware | Hancock Public School id32819 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain structure and contextual metadata align with a public or institutional education environment, reflecting typical infrastructure associated with school or educational networks. This listing type categorizes the entity based on its association with a cybersecurity incident involving ransomware activity. The entity is explicitly linked to the threat actor interlock, which is documented within the index for its role in the observed threat landscape. This description provides factual context regarding sector, location, operational nature, and threat association without speculating on unconfirmed technical details or incident specifics. |
||||||
| Ransomware | Hancock Public School id32819 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the US Education sector, operating under a .k12.mn.us domain structure commonly associated with public or educational institutions. It is cataloged as a ransomware victim in the threat-intelligence index, with an associated threat actor or source designated as interlock. The entity represents a real-world incident case where educational infrastructure was targeted, contributing contextual data for threat analysis and defense planning. This listing type documents the relationship between the victim entity, the threat actor interlock, and the affected sector without disclosing unverified technical or operational details. The entry serves to inform security professionals and researchers on ransomware activity within educational contexts in the United States. |
||||||
| Ransomware | Hancock Public School id32820 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain structure and associated context indicate involvement in an educational institution environment, where cybersecurity incidents and threat actor attribution are actively monitored. This listing type categorizes the entity based on its association with the threat actor interlock, reflecting the intelligence profile compiled by the index. The description remains factual and neutral, avoiding speculation regarding specific attack vectors, data handling, or confirmed breach details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32820 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure indicates a connection to a Minnesota-based educational institution, reflecting the sector and geographic context of the listing. This entry documents the entity's association with the threat actor interlock, providing cybersecurity professionals with contextual intelligence for risk assessment and defensive planning. The description remains factual and neutral, focusing on the entity's classification, operational context, and verified threat linkage without extrapolating beyond confirmed intelligence. This catalog entry supports comprehensive monitoring of ransomware incidents within critical infrastructure sectors. |
||||||
| Ransomware | Hancock Public School id32821 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies a system associated with a US education institution operating within the K-12 education sector. The entity functions as a catalog entry for a ransomware victim within a threat-intelligence index, reflecting observed or attributed exposure patterns. Its classification connects the affected location and sector to the interlock threat actor, providing context for threat monitoring and risk assessment. No specific incident details such as data stolen, records accessed, ransom demands, or confirmed breach scope are included per strict factual boundaries. This listing neutrally records that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32822 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain aligns with a public educational institution context based on its .k12.mn.us domain structure and sector classification. This listing type categorizes the entity under confirmed ransomware incident associations within cybersecurity intelligence frameworks. The associated threat actor is interlock, a designated source in the index's attribution model. This entry serves catalog and analytical purposes for monitoring education-sector cyber threats and threat actor activity. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32822 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in threat-intelligence indexing. The domain and associated context indicate institutional infrastructure, consistent with the education sector classification and geographic location. This listing type categorizes the entity based on its documented relationship with the threat actor interlock, reflecting observed cyber activity targeting educational environments. The entry provides neutral catalog information without speculating on specific breach details, operational tactics, or unconfirmed claims. It neutrally states that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32822 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity associated with the US Education sector and cataloged as a ransomware victim within the threat-intelligence index. Its domain context and sector designation indicate involvement within a public or educational institution environment in Minnesota, United States. The listing identifies interlock as the associated threat actor or source connected to this entity. This entry provides structured intelligence context for monitoring ransomware activity in education environments, linking the entity to its geographic sector, operational classification, and threat actor association without asserting unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32822 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an education-sector institution located in the United States. The entity functions within the K-12 educational context and is cataloged as a ransomware victim within the threat-intelligence index. Its association with the threat actor interlock indicates a cybersecurity incident classification tied to this actor's activity. This listing provides neutral context regarding the entity's sector, geographic location, operational domain, and confirmed threat-intelligence linkage without disclosing unverified incident details. The entry serves as a reference point for monitoring ransomware exposure in educational infrastructure. |
||||||
| Ransomware | Hancock Public School id32823 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an Education sector institution located in the United States. The entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor or source designated as interlock. Its listing reflects observed or attributed cyber activity concerning this educational organization and the interlock threat actor group. The description avoids speculative details regarding data exfiltration, ransom demands, or confirmed breach specifics, focusing strictly on the entity classification, sector context, geographic location, and verified threat attribution. This entry serves as a structured reference point for threat analysts tracking ransomware incidents within U.S. education environments and their connections to identified actors. |
||||||
| Ransomware | Hancock Public School id32823 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain and associated context indicate involvement within a public or institutional education environment, with the listing explicitly tied to the threat actor interlock. This entry catalogs the relationship between the entity, its sector and geographic location, and the ransomware incident classification without disclosing unverified technical or operational specifics. The description adheres to neutral, authoritative standards for threat-intelligence documentation, focusing on verified associations and sector context. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32828 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain and associated listing contextualize its role in cybersecurity monitoring, reflecting incidents affecting educational institutions and highlighting exposure to threat actor interlock activity. This entry documents the relationship between the entity, its sector classification, and the identified threat actor without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach metrics. The listing serves as part of a structured intelligence catalog designed to support threat analysis, sector-specific risk awareness, and informed security decision-making for organizations and defenders monitoring ransomware-related activity in education environments across the US. |
||||||
| Ransomware | Hancock Public School id32829 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. It appears within a threat-intelligence index as a ransomware victim, with the associated threat actor or source identified as interlock. The entity operates within the K-12 educational context, reflecting the sector and geographic scope noted in the listing. This entry catalogs the relationship between the domain, its victim classification, and the interlock threat actor for defensive analysis and monitoring purposes. The description remains factual and neutral, focusing solely on the indexed associations without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | Hancock Public School id32833 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in threat-intelligence indexing. The domain structure and sector context indicate an educational institution or related education-sector entity operating within Minnesota, with public-facing infrastructure associated with the Hancock K-12 network environment. This listing type categorizes the entity based on threat-intelligence analysis linking it to the interlock threat actor group. The description focuses on factual classification: sector, geographic context, entity type, and associated threat actor without asserting unverified incident details such as data exfiltration scope, ransom demands, or confirmed breach specifics. Its inclusion reflects the ransomware victim designation tied to interlock within the threat-intelligence index. |
||||||
| Ransomware | Hancock Public School id32836 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States Education sector associated with a ransomware incident. The domain structure indicates a public-facing infrastructure component linked to a school or educational institution operating within Minnesota. As cataloged in the threat-intelligence index, this listing type classifies the entity as a ransomware victim connected to the threat actor interlock. The description focuses on verified contextual attributes including geographic location, industry sector, and the specific threat actor association without speculating on breach details, data exfiltration specifics, or recovery outcomes. This entry serves to document the entity's presence in ransomware-related intelligence for sector-focused analysis. |
||||||
| Ransomware | Hancock Public School id32837 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the United States Education sector, associated with the listing type ransomware victim. The domain structure indicates a public-facing infrastructure linked to a Minnesota-based educational institution, though specific operational details, incident specifics, or confirmed breach evidence are not provided in available public knowledge. This entry documents the entity's classification within a threat-intelligence index, noting its association with the threat actor interlock. The description remains neutral and factual, focusing on sector, location, listing context, and attributed actor without extrapolating unverified claims regarding data exposure, attack methodology, or resolution. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32839 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate this listing with the threat actor interlock, indicating a cybersecurity incident relevant to educational institutions. This entry documents the entity's classification without disclosing unverified incident details such as data stolen, system impact, or financial loss. The listing serves to catalog the relationship between the affected education-sector entity and the identified threat actor interlock for analytical and defensive purposes. It reflects the entity's status as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32847 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain structure indicates a public-facing infrastructure associated with a K-12 educational institution, reflecting its operational context and regional location. This listing type categorizes the entity based on documented threat-intelligence linkages rather than confirmed incident details. The associated threat actor interlock is referenced in the index to contextualize the risk profile and attribution framework. This description maintains neutrality regarding specific breach confirmations, data impacts, or operational outcomes while accurately reflecting the entity's classification and sector relevance within the intelligence catalog. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the US Education sector and cataloged as a ransomware victim within a threat-intelligence index. The domain appears tied to a public school or educational institution environment, reflecting the sector and geographic context of the listing. Threat-intelligence records categorize this entity under the ransomware victim designation, linking it to the associated threat actor interlock for contextual analysis of potential attack patterns and affected infrastructure. The description avoids speculative claims regarding confirmed breach details, data exfiltration, ransom requirements, or specific operational impact. It neutrally states that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain structure and sector context indicate its association with a public or institutional education environment, where such incidents are critically monitored for cybersecurity intelligence purposes. This listing type categorizes the entity based on its documented relationship to the threat actor interlock, providing catalog value for analysts tracking ransomware campaigns across sectors. The description remains factual and neutral, focusing on the entity's classification without speculating on unverified technical details or incident specifics. It was listed as a ransomware victim associated with interlock. |
||||||