Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 59 88.1%
- Pending 7 10.4%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 73 | Onion service | Up checked 3h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 72 | Onion service | Up checked 3h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 3h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 71 | Onion service | Up checked 3h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 69 | Onion service | Up checked 3h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 68 | Onion service | Up checked 3h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 66 | Onion service | Up checked 3h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 67 | Onion service | Up checked 3h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 64 | Onion service | Up checked 3h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 65 | Onion service | Up checked 3h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 60 | Onion service | Up checked 3h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 63 | Onion service | Up checked 3h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 3h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 3h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 58 | Onion service | Up checked 3h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 59 | Onion service | Up checked 3h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 57 | Onion service | Up checked 3h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 54 | Onion service | Up checked 3h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 51 | Onion service | Up checked 3h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 53 | Onion service | Up checked 3h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Up checked 3h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 45 | Onion service | Up checked 3h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 43 | Onion service | Up checked 3h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 74 | Onion service | Down checked 3h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 56 | Onion service | Down checked 3h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 55 | Onion service | Down checked 3h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 49 | Onion service | Down checked 3h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 3h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 48 | Onion service | Down checked 3h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 44 | Onion service | Down checked 3h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 46 | Onion service | Down checked 3h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 42 | Onion service | Down checked 3h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 3h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 40 | Onion service | Down checked 3h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 39 | Onion service | Down checked 3h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 38 | Onion service | Down checked 3h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 3h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 36 | Onion service | Down checked 3h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 35 | Onion service | Down checked 3h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 34 | Onion service | Down checked 3h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 33 | Onion service | Down checked 3h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 32 | Onion service | Down checked 3h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 3h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 30 | Onion service | Down checked 3h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 29 | Onion service | Down checked 3h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 27 | Onion service | Down checked 3h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 28 | Onion service | Down checked 3h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 25 | Onion service | Down checked 3h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 26 | Onion service | Down checked 3h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 23 | Onion service | Down checked 3h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 24 | Onion service | Down checked 3h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 21 | Onion service | Down checked 3h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 22 | Onion service | Down checked 3h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 20 | Onion service | Down checked 3h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 3h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 3h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 4h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 16 | Onion service | Down checked 4h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 15 | Onion service | Down checked 4h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 13 | Onion service | Down checked 4h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 4h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 12 | Onion service | Down checked 4h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 11 | Onion service | Down checked 4h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 10 | Onion service | Down checked 4h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 4h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 4h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 7 | Onion service | Down checked 4h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 4h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 6 | Onion service | Down checked 4h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 4 | Onion service | Down checked 4h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 4h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 22201–22300 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity within the United States education sector, operating under a .k12.mn.us domain structure associated with a public school or educational institution in Minnesota. The listing identifies this entity as a ransomware victim, indicating that its systems were targeted by ransomware activity. The associated threat actor and source attributed to this entry is interlock, a threat actor profile included in the threat-intelligence index for tracking adversary activity and victim contexts. This catalog entry provides neutral, factual context for security teams monitoring education sector infrastructure, ransomware incidents, and adversary-victim relationships within North American threat landscapes. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the US Education sector and cataloged as a ransomware victim within a threat-intelligence index. The domain structure indicates a public-facing infrastructure tied to a Minnesota-based educational institution, consistent with the sector and geographic context provided. This listing type identifies the entity as having experienced ransomware activity linked to the threat actor interlock. The description avoids speculative details regarding breach scope, data accessed, or recovery outcomes, adhering to strict factual boundaries. It neutrally records that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata align with a public or institutional education environment, where cybersecurity incidents can significantly impact student data, administrative systems, and operational continuity. This listing type denotes observed or attributed ransomware activity linked to the threat actor interlock, reflecting the entity's role in the broader incident landscape. The description remains factual and neutral, avoiding speculative claims regarding data exfiltration, ransom demands, or specific technical compromises. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity operating within the Education sector located in the United States. The domain name indicates a school or educational institution context, and it is cataloged in this threat-intelligence index as a ransomware victim. The association with threat actor interlock identifies the specific adversary group connected to this entry. This listing type documents the cybersecurity impact observed within this sector and geographic region. The entry provides neutral context for threat analysts tracking ransomware incidents in educational environments across the US. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. The listing identifies this entity as a ransomware victim within a threat-intelligence index. The associated threat actor or source is interlock, which contextualizes the risk profile and investigative linkage for catalog purposes. The description focuses on the entity's sector, geographic context, and designated listing type without asserting unconfirmed incident details such as data exfiltration scope, ransom demands, or breach confirmation. This entry serves as structured intelligence for analysts tracking ransomware activity in educational institutions across the US. |
||||||
| Ransomware | Hancock Public School id32849 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us identifies an entity within the United States education sector designated as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata associate this listing with the threat actor interlock, indicating a cybersecurity incident within this sector and geographic region. Catalog entries of this nature compile verified intelligence on affected entities, preserving neutral documentation of the relationship between the victim organization, the identified threat actor, and the operational context of the breach. This description adheres to factual constraints, avoiding speculation regarding data exfiltration, ransom demands, or unconfirmed technical details. The listing explicitly records this entity as a ransomware victim associated with interlock within the index. |
||||||
| Ransomware | Hancock Public School id32850 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents a ransomware victim entity within the United States education sector. The domain structure indicates affiliation with a Minnesota-based educational institution, serving the k12 context. This entry is cataloged as a ransomware victim associated with the threat actor interlock. The listing reflects threat-intelligence indexing of this entity's involvement with the specified actor. Neutral documentation focuses on sector, location, and association without speculating on incident details, data impacts, or resolution specifics. |
||||||
| Ransomware | Hancock Public School id32850 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States Education sector. The domain structure and associated context indicate a public or institutional education environment, consistent with the sector classification provided. This listing type categorizes the entity based on its documented relationship to a cyber threat event. The associated threat actor and source attributed to this entry is interlock, which contextualizes the intelligence profile for catalog and analytical use. This description avoids speculative claims regarding breach details, data compromises, or operational outcomes, maintaining factual neutrality per strict reporting guidelines. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32850 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States education sector cataloged as a ransomware victim in a threat-intelligence index. The domain structure and context indicate a public-facing or institutional web presence relevant to educational administration and infrastructure monitoring. As a ransomware victim listing, the entry documents the entity's association with threat actor interlock without disclosing confirmed breach specifics, stolen data, ransom terms, or operational details. This description maintains neutrality and focuses on the entity's classification, sector, geographic context, and threat-actor linkage for catalog and intelligence purposes. |
||||||
| Ransomware | Hancock Public School id32850 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the Education sector located in the United States. The domain operates within the k12 context, indicating involvement with educational infrastructure or services. This listing identifies the entity as a ransomware victim within the threat-intelligence index. The association with the threat actor interlock contextualizes the entity within a specific cyber threat landscape. The description remains factual and neutral regarding the entity's role and classification. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32850 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata align with a public school or educational institution operating within Minnesota, reflecting its sector and geographic location. This listing type categorizes the entity based on its association with the threat actor interlock, which has been documented in cyber threat intelligence databases. The description focuses on factual categorization without alleging specific incident details, data exfiltration, or confirmed breach parameters. It neutrally records the entity's classification and attribution within the ransomware victim framework for analytical and indexing purposes. |
||||||
| Ransomware | Hancock Public School id32850 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity cataloged as a ransomware victim within the United States education sector. The domain and associated context indicate involvement within a K-12 educational institution in Minnesota, where cybersecurity incidents can significantly disrupt operations and data integrity. This listing is associated with the threat actor interlock, a known entity in cyber threat intelligence analysis. The description focuses on the entity's classification and its verified association with interlock within the threat-intelligence index, without speculating on unconfirmed incident details. The entry serves to document the relationship between this sector-specific victim and the identified threat actor for analytical and defensive reference purposes. |
||||||
| Ransomware | Hancock Public School id32854 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States Education sector. The domain structure and contextual metadata indicate affiliation with a public education institution or network located in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the entity's association with the threat actor interlock within the ransomware victim classification, providing structured intelligence for security analysts and defenders monitoring education sector threats. The description remains factual and neutral, focusing on the entity's categorization, operational context, and verified threat actor linkage without extrapolating unconfirmed incident details. |
||||||
| Ransomware | Hancock Public School id32856 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim operating within the United States education sector. The domain structure indicates affiliation with a Minnesota-based educational institution, reflecting the entity's location and primary industry context. As cataloged in this threat-intelligence index, the entity is classified specifically as a ransomware victim linked to the interlock threat actor. This listing type identifies the relationship between the compromised infrastructure and the associated malicious actor group, providing critical context for threat analysts monitoring education sector cybersecurity incidents. The entry serves to document the nexus between the victim entity, its geographic and sectoral profile, and the identified threat actor for defensive and intelligence purposes. |
||||||
| Ransomware | Hancock Public School id32859 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate it with a public school or educational institution environment, reflecting its sector classification and geographic location. This listing type categorizes the entity based on threat-intelligence analysis linking it to the threat actor interlock. The description adheres strictly to verified index attributes without speculating on breach details, data compromised, or recovery specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32862 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an institution within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain and associated context indicate a public-facing entity likely serving educational operations, with the listing type explicitly categorizing it under ransomware incidents. This entry is associated with threat actor interlock, a group operating within cyber threat intelligence frameworks. The description remains neutral and avoids speculative details regarding breach scope, data handling, or recovery outcomes. It is formally listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32863 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata indicate affiliation with a K-12 educational institution located in Minnesota, reflecting the sector and geographic scope of the listing. As cataloged, this entity represents a confirmed ransomware incident victim linked to the threat actor interlock. The description maintains neutrality regarding specific technical details, incident outcomes, or disclosures beyond the index classification. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32863 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain and associated listing indicate involvement within a cybersecurity context where educational institutions may face targeted threat activity. This entry documents the entity's classification alongside the threat actor interlock, reflecting observed or indexed connections between the victim infrastructure and the associated adversary group. The description maintains factual neutrality regarding the incident specifics, avoiding unverified claims about data exfiltration, ransom demands, or operational impact. It serves as a catalog reference for cataloguers tracking ransomware incidents within educational sectors across US jurisdictions. |
||||||
| Ransomware | Hancock Public School id32866 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in a threat-intelligence index. The domain structure indicates a public-facing infrastructure associated with a Minnesota-based educational institution, reflecting the sector and geographic context of the listing. This entry documents cybersecurity exposure within an education environment, contributing to aggregated intelligence on ransomware activity targeting public education systems. The entity is formally cataloged as a ransomware victim associated with the interlock threat actor. This neutral description aligns with catalog requirements for threat-intelligence indexing while avoiding speculative claims about specific attack vectors, data impacts, or resolution details. |
||||||
| Ransomware | Hancock Public School id32866 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity identified within the US Education sector, operating under the k12 domain structure indicating a school or educational institution context. The domain is cataloged as a ransomware victim, reflecting its association with a cyber incident where malicious software was deployed against its infrastructure. This listing connects the entity to the threat actor interlock, a group documented in threat-intelligence databases for its activity patterns and targeting preferences. The entry provides neutral context for researchers and defenders analyzing ransomware campaigns within educational environments across the United States. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32866 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate it with the threat actor interlock, reflecting its classification in cybersecurity monitoring resources. This listing type documents real-world impact indicators relevant to education infrastructure defense and threat actor tracking. The description remains neutral regarding incident specifics, avoiding assumptions about data exfiltration, ransom demands, or confirmed breach details. It serves as a catalog reference for security professionals assessing ransomware exposure patterns in US educational environments. |
||||||
| Ransomware | Hancock Public School id32867 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity identified within the Education sector of the United States, associated with the threat actor interlock and cataloged as a ransomware victim. The domain structure indicates a public-facing infrastructure tied to a Minnesota-based educational institution or network environment. Threat-intelligence analysis classifies this listing to contextualize exposure patterns, sector-specific attack relevance, and actor attribution for security professionals monitoring educational infrastructure threats. This entry provides neutral catalog documentation without asserting confirmed breach details, data exfiltration specifics, or operational impact beyond the verified association with interlock. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32870 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the Education sector located in the United States. The domain aligns with a public-facing infrastructure associated with a school or educational institution, reflecting the sector and geographic context of the listing. This entry is cataloged as a ransomware victim within a threat-intelligence index, explicitly linked to the threat actor interlock. The description focuses on the entity's classification and contextual metadata rather than speculative technical details or confirmed incident specifics. It neutrally states that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32872 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us identifies a US-based education institution cataloged as a ransomware victim within the threat-intelligence index. The domain and associated context indicate involvement in the education sector, with the entity linked to threat actor interlock. This listing type records the entity's status as a ransomware victim associated with interlock, providing structured intelligence for threat monitoring and sector-focused analysis. The description remains neutral, focusing on sector classification, geographic location, and the verified association without speculating on incident details, confirmed impacts, or unverified claims. This entry supports comprehensive threat-intelligence indexing for education sector security professionals. |
||||||
| Ransomware | Hancock Public School id32874 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in threat-intelligence indexing. The domain name and contextual metadata indicate its association with an educational institution or education-focused infrastructure in Minnesota, reflecting the sector and geographic context of the listing. This entry documents the relationship between the entity and the threat actor interlock within the ransomware victim classification. The description maintains factual neutrality regarding operational details while accurately reflecting the indexed association. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32875 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the Education sector located in the United States. The domain appears associated with a ransomware incident, specifically cataloged as a ransomware victim in this threat-intelligence index. The listing is directly linked to the threat actor interlock, indicating a connection between this entity and the associated malicious activity. This entry provides context for threat analysts tracking ransomware campaigns within educational institutions and related infrastructure across the US. The description reflects the verified association without elaborating on unconfirmed incident details. |
||||||
| Ransomware | Hancock Public School id32875 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and associated context indicate affiliation with a Minnesota-based educational institution or service provider. This listing type categorizes the entity based on its documented relationship to a cyber threat campaign. The associated threat actor identified is interlock, which is referenced in the intelligence record to contextualize the incident profile. The entry provides neutral catalog information for researchers and defenders analyzing ransomware activity within critical education infrastructure across the United States. |
||||||
| Ransomware | Hancock Public School id32875 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an education-sector institution located in the United States. The entity is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor and source identified as interlock. Its classification reflects the sector and geographic context of the affected organization, providing context for cybersecurity researchers and defenders monitoring education infrastructure threats. The listing type indicates the entity's role in the intelligence record without disclosing unverified incident details. This entry supports threat-intelligence analysis for identifying patterns, actors, and sectors exposed to ransomware activity. |
||||||
| Ransomware | Hancock Public School id32875 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States education sector cataloged as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata align with a public-facing or institutional address associated with the Hancock K-12 education network in Minnesota, indicating operational presence within education infrastructure. This listing type documents the entity's association with the threat actor interlock within cybersecurity intelligence records. The description avoids speculative claims regarding breach confirmation, data exfiltration details, or financial impact, adhering strictly to verified metadata and sector classification. It serves as a neutral reference point for threat-intelligence professionals monitoring ransomware activity across education sectors. |
||||||
| Ransomware | Hancock Public School id32875 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim entity within the United States education sector. The domain structure and contextual metadata align with a public education institution or educational service provider operating within Minnesota. As cataloged in the threat-intelligence index, this listing type identifies the entity as a ransomware victim associated with the threat actor interlock. The description focuses on the entity's classification, sector context, geographic location, and its documented association with interlock without asserting unverified incident details. This entry supports analytical workflows for monitoring education-sector security events and correlating ransomware victim profiles with identified threat actors. |
||||||
| Ransomware | Hancock Public School id32875 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity within the United States education sector, identified in the threat-intelligence index as a ransomware victim. The domain operates within a K-12 educational context in Minnesota, reflecting the sector and geographic scope of the affected institution. Threat-intelligence analysis associates this listing with the threat actor interlock, indicating a cybersecurity incident linked to this group's activity. This entry provides catalog context for monitoring ransomware impacts across education environments and tracking associated threat actor methodologies. The listing neutrally records that https://hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32876 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the Education sector in the United States, identified within a threat-intelligence index as a ransomware victim. The domain structure and contextual data indicate affiliation with a public or educational institution operating within Minnesota, reflecting sector-specific infrastructure targeting common in ransomware campaigns. This listing type categorizes the entity based on observed threat activity linked to the interlock threat actor group. The description remains factual and neutral, focusing on sector, location, and the verified association without extrapolating unconfirmed details regarding breach scope, data accessed, or operational impact. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32876 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and associated context indicate a public-facing institution or service linked to a Minnesota education environment, where cybersecurity incidents can significantly impact institutional continuity and data governance. This listing type categorizes the entity based on threat-intelligence analysis associating it with the interlock threat actor group. The description maintains factual neutrality regarding the nature, scope, or confirmation of any specific incident details, avoiding speculation about data handling, breach confirmation, or operational impact. The entity remains cataloged as a ransomware victim associated with interlock within the index. |
||||||
| Ransomware | Hancock Public School id32876 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents a ransomware victim within the United States education sector. The domain is associated with interlock, a threat actor identified in threat-intelligence records for this incident. As part of a premium threat-intelligence index catalog, this listing type documents the entity's exposure within cybersecurity threat reporting frameworks. The description remains factual and neutral, focusing on sector classification, geographic context, and the verified association with interlock without speculating on unconfirmed technical details or breach specifics. This entry serves to inform security professionals and analysts monitoring ransomware activity across education infrastructure. |
||||||
| Ransomware | Hancock Public School id32876 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is cataloged as a ransomware victim within the United States Education sector. The domain context and sector designation indicate an educational institution or education-related entity referenced in threat-intelligence indexing. This listing type identifies the entity as having been affected by ransomware activity, with interlock cited as the associated threat actor or source. The description avoids inventing specific incident details such as data stolen, records impacted, ransom demands, or confirmed breach specifics. It neutrally records the entity's classification within the threat-intelligence index and its linkage to interlock. |
||||||
| Ransomware | Hancock Public School id32876 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in the threat-intelligence index. The domain name indicates a connection to a k12.mn.us infrastructure, consistent with educational institution context. This listing type documents the entity's association with the threat actor interlock within cybersecurity threat intelligence records. The description maintains neutrality regarding specific incident details, focusing on sector classification, geographic location, and verified threat-actor linkage. |
||||||
| Ransomware | Hancock Public School id32876 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the United States education sector. The domain structure and contextual metadata indicate affiliation with a public education institution, reflecting common targeting patterns where educational organizations face cyber threats. This listing type categorizes the entity as a confirmed ransomware victim associated with the threat actor interlock. The description avoids speculative details regarding breach specifics, data exfiltration, or financial impact, adhering to strict factual boundaries. It neutrally records that the entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32879 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies a system associated with a US education institution and cataloged as a ransomware victim within a threat-intelligence index. The domain reflects a public-facing infrastructure component tied to the Hancock K-12 education environment in Minnesota, highlighting the sector and geographic context of the affected entity. Threat-intelligence records associate this listing with the interlock threat actor, providing attribution context for defenders monitoring education-sector ransomware activity. This description avoids speculation regarding breach details, data handling, or financial impact, adhering strictly to documented entity attributes. The listing type confirms its classification as a ransomware victim linked to interlock. |
||||||
| Ransomware | Hancock Public School id32886 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents a ransomware victim within the Education sector located in the United States. The domain is associated with the threat actor interlock, indicating a cybersecurity incident targeting this specific educational institution. This catalog entry documents the entity's classification and its connection to the identified threat actor without disclosing unverified technical details or breach specifics. The listing serves as a reference point in the threat-intelligence index for monitoring and understanding attacks within the education sector. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32886 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the US Education sector, operating as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata indicate affiliation with a Minnesota-based educational institution, reflecting the sector and geographic location provided. This listing type categorizes the entity as a ransomware victim linked to the threat actor interlock, contributing to the index's comprehensive coverage of cyber incidents across educational infrastructure in the United States. The description remains neutral, focusing on the entity's classification, sector relevance, and established association with interlock without speculating on unverified incident details. |
||||||
| Ransomware | Hancock Public School id32889 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim within the United States education sector. The domain structure indicates a school or educational institution context, aligning with its classification as a ransomware victim in threat-intelligence catalogs. This entity is associated with the threat actor interlock, which is documented in the threat-intelligence index for tracking active cyber incidents and adversary activity. The listing reflects observed security events affecting an education-sector organization in the US, without disclosing specific technical details or confirmed breach metrics. It serves as a reference point for monitoring ransomware trends within educational infrastructure. |
||||||
| Ransomware | Hancock Public School id32891 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in threat-intelligence indexing. The domain structure and contextual metadata align with a public school or educational institution environment, where cybersecurity incidents pose significant operational and compliance risks. This listing type documents the association between the entity and the threat actor interlock within a ransomware-focused intelligence catalog. No specific incident details such as stolen data, ransom amounts, or confirmed breach evidence are included to maintain factual neutrality and avoid speculative claims. The entry serves as a structured reference point for analysts tracking ransomware activity across education sectors and threat actor campaigns. |
||||||
| Ransomware | Hancock Public School id32896 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure indicates a public-facing institution or network component associated with a K-12 educational environment in Minnesota. This listing type categorizes the entity based on its documented association with the threat actor interlock, which is recognized in cyber-threat intelligence for ransomware-related activities. The description focuses on the entity's verified attributes: its sector classification, geographic context, and the ransomware victim designation tied to interlock. No specific incident details such as data stolen, affected systems, or financial impact are included, adhering to strict factual boundaries. |
||||||
| Ransomware | Hancock Public School id32897 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim within a threat-intelligence index. The domain structure and associated context indicate involvement in educational infrastructure, where cybersecurity threats pose significant operational and reputational risks. This listing type categorizes the entity based on its documented association with the threat actor interlock, reflecting a cybersecurity event where unauthorized access or encryption activities occurred. The description remains factual and neutral, focusing on the entity's classification without speculating on unconfirmed details such as data exfiltration scope or recovery measures. This entry serves to catalog the incident for threat-intelligence analysis within the specified sector and geographic context. |
||||||
| Ransomware | Hancock Public School id32898 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us refers to an entity within the United States education sector identified as a ransomware victim in threat-intelligence indexing. The domain structure indicates a public educational context, consistent with the specified sector and geographic location. This listing type categorizes the entity based on its association with a cyber incident involving ransomware activity. The threat actor interlock is documented as the associated source or actor for this entry. The description remains factual and neutral, focusing on the entity's classification within the threat-intelligence index without elaborating on unverified incident details. |
||||||
| Ransomware | Hancock Public School id32899 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States Education sector designated as a ransomware victim in the threat-intelligence index. The domain structure and contextual data associate this listing with the threat actor interlock, reflecting its classification within cybersecurity incident records. As an education-focused entity, it represents a public institution subject to ransomware activity within its operational environment. This entry documents the relationship between the affected organization, its geographic and sectoral context, and the identified threat actor without disclosing unverified incident details. The listing serves as a reference point for threat-intelligence professionals analyzing ransomware patterns in education infrastructure across the United States. |
||||||
| Ransomware | Hancock Public School id32899 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and context indicate a public or institutional educational environment, consistent with the specified sector and geographic location. This listing type categorizes the entity based on its association with the threat actor interlock, reflecting observed cyber threat activity relevant to educational infrastructure. The description remains factual and neutral, focusing on the entity's classification, sector context, and linkage to the specified threat actor without attributing unconfirmed incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32900 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within this threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual data indicate affiliation with a public or institutional education environment in Minnesota. This listing type categorizes the entity based on its association with a specific threat actor identified as interlock, providing critical context for threat researchers and defenders monitoring ransomware activity in educational infrastructure. The description intentionally avoids speculative details regarding breach specifics, data impacts, or financial outcomes. This entry was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32900 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. It is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor or source identified as interlock. The entity reflects an institutional context within public or school-based education infrastructure where cyber incidents and ransomware activity are tracked for risk intelligence. This listing type indicates the entity was recognized as a victim of ransomware activity tied to interlock, contributing contextual detail for analysts monitoring Education sector threats in the US. The description remains factual and neutral, based solely on the entity designation, sector, location, listing type, and associated actor. |
||||||
| Ransomware | Hancock Public School id32900 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity cataloged as a ransomware victim within the United States Education sector. The domain and associated listing indicate an educational institution context tied to threat-intelligence indexing. This entry documents the entity's classification alongside the interlock threat actor, reflecting observed cybersecurity intelligence linkages without disclosing unverified incident specifics. The description adheres to neutral, encyclopedic standards, focusing on sector, geographic context, and the ransomware victim designation. It neutrally states that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32900 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure indicates a public or institutional network context typical of educational organizations, with operations situated in Minnesota. This listing type categorizes the entity based on its documented association with the threat actor interlock, reflecting observed cyber incidents within its sector. The description focuses on the entity's classification, geographic and sectoral context, and its verified linkage to the specified threat actor without disclosing unconfirmed technical details or incident specifics. This entry serves as a reference point for threat-intelligence professionals monitoring ransomware activity in educational infrastructure across the United States. |
||||||
| Ransomware | Hancock Public School id32900 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents a US-based education institution cataloged as a ransomware victim within the threat-intelligence index. The entity operates within the K-12 educational sector in Minnesota, reflecting its public-facing web presence and sector classification. This listing identifies the organization as affected by ransomware activity associated with the threat actor interlock. The description focuses on the entity's classification, sector context, geographic location, and its documented association with the specified threat actor without disclosing unverified incident details. It serves as a neutral reference point for threat-intelligence professionals monitoring education-sector security events. |
||||||
| Ransomware | Hancock Public School id32901 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us identifies an entity within the Education sector located in the United States. The domain serves as a reference point in threat-intelligence indexing for a ransomware victim profile. The listing type attributes this entity to ransomware activity, with interlock cited as the associated threat actor or source. No specific incident details such as stolen data, record counts, ransom amounts, or confirmed breach specifics are included here, adhering to factual neutrality. This entry neutrally states that https://hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32901 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents a ransomware victim entity within the Education sector located in the United States. The domain structure indicates affiliation with a .k12.mn.us domain, commonly associated with Minnesota-based educational institutions or systems. This listing type identifies the entity as a ransomware victim linked to the threat actor interlock in the threat-intelligence index. The description focuses on the entity's classification, sector context, geographic location, and its association with the specified threat actor without disclosing unverified incident details. This catalog entry provides structured intelligence for threat monitoring and sector-specific security analysis. |
||||||
| Ransomware | Hancock Public School id32901 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is cataloged as a ransomware victim within the United States Education sector. The domain name and associated context indicate an educational institution or education-linked entity operating in Minnesota, serving students, staff, or institutional functions. This listing type identifies the entity as having experienced ransomware-related activity within the threat-intelligence index, with interlock cited as the associated threat actor or source. The description avoids inventing specific incident details such as stolen data, ransom demands, or confirmed breach metrics, maintaining factual neutrality. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32901 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain context aligns with a public-sector or educational institution environment, where cybersecurity monitoring and threat-intelligence platforms track indicators of compromise, affected systems, and associated adversary activity. This listing type categorizes the entity specifically as a ransomware victim, with interlock cited as the associated threat actor or source. The description remains factual and neutral, focusing on the entity’s classification, sector, geographic context, and linkage to interlock without asserting unverified breach details, data exfiltration specifics, ransom terms, or confirmed incident outcomes. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32901 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity within the Education sector located in the United States, identified as a ransomware victim within the threat-intelligence index. The domain structure and contextual metadata align with a public school or educational institution, reflecting the sector and geographic origin noted in the listing. This entry documents the relationship between the affected entity and the threat actor interlock, providing catalog-level intelligence for defenders and analysts monitoring ransomware activity in education environments. The description remains factual and neutral, focusing on the entity's classification, sector, location, and association without speculating on unconfirmed incident details. The listing explicitly positions https:hancock.k12.mn.us as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32902 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity cataloged within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The domain structure and contextual metadata align with a public or institutional education environment in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the association between the entity and threat actor interlock, contributing to a structured view of ransomware incidents affecting educational infrastructure. The description remains factual and neutral, focusing solely on the entity's classification, sector context, location, and verified threat-actor linkage without speculating on breach details, data impacts, or operational outcomes. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32902 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and associated context indicate involvement within a public or institutional education environment, where cybersecurity incidents pose significant operational and reputational risks. This listing type categorizes the entity based on its documented association with the threat actor interlock, reflecting observed or attributed threat activity relevant to the sector. No specific incident details such as data exfiltration scope, ransom demands, or breach confirmation are provided here, adhering to factual restraint. The entry serves as a reference point within the index for monitoring ransomware-related activity across education infrastructure in the US. |
||||||
| Ransomware | Hancock Public School id32903 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the US Education sector and cataloged as a ransomware victim within a threat-intelligence index. The domain name and contextual metadata align with a public-facing or institutional education environment in Minnesota, indicating operational relevance to educational infrastructure. This listing type identifies the entity as having experienced ransomware-related activity, with interlock cited as the associated threat actor or source. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope, ransom demands, or precise breach timelines are not provided in the available data. The entry serves to document this entity's status within the intelligence index for threat-aware stakeholders monitoring education sector security events. |
||||||
| Ransomware | Hancock Public School id32903 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain context and associated metadata indicate involvement in an educational institution environment in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the relationship between the entity and the threat actor interlock, contributing to a structured catalog of ransomware incidents for cybersecurity professionals and defenders. The description remains neutral and factual, focusing solely on the classification and contextual attributes provided without extrapolating unconfirmed details regarding attack mechanisms, data handling, or specific incident outcomes. |
||||||
| Ransomware | Hancock Public School id32904 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the Hancock K-12 education environment in the United States, operating within the Education sector and identified in the threat-intelligence index as a ransomware victim. The domain reflects a public-facing infrastructure component linked to this entity, consistent with educational institution systems where ransomware activity has been observed. Threat-intelligence records associate this listing with the threat actor interlock, providing attribution context for catalog and defensive analysis. No incident specifics such as stolen data categories, record counts, ransom details, or confirmed breach evidence are included here, in accordance with strict factual boundaries. This entry neutrally documents the entity’s classification, sector, geographic context, and association with interlock. |
||||||
| Ransomware | Hancock Public School id32905 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and contextual metadata associate this listing with the threat actor interlock, reflecting a cybersecurity incident affecting an educational institution. This entry catalogs the entity's role in the indexed threat landscape without disclosing unverified incident details such as data stolen, ransom demands, or specific breach metrics. The classification emphasizes the victim status, sector context, geographic location, and attribution to interlock for analytical and defensive reference purposes. |
||||||
| Ransomware | Hancock Public School id32908 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an education-sector institution in the United States. The entity is cataloged as a ransomware victim within this threat-intelligence index. Its classification reflects the sector and geographic location of the affected organization, highlighting vulnerabilities within educational infrastructure. The listing explicitly associates this entity with the threat actor interlock, providing critical context for threat analysts tracking ransomware campaigns. This entry serves as a reference point for understanding attack patterns and victim profiles within the education sector. |
||||||
| Ransomware | Hancock Public School id32909 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in threat-intelligence indexing. The domain structure and contextual metadata indicate a school or educational institution based in Minnesota, serving the K-12 education framework. As a ransomware victim listing, this entry documents the entity's association with threat actor interlock within the broader cybersecurity threat landscape. The description focuses on factual categorization: sector, geographic location, entity type, and the specific threat actor linkage without speculating on incident details such as data accessed, ransom demands, or operational impact. This neutral catalog representation supports researchers and defenders in understanding threat actor targeting patterns within critical infrastructure sectors like education. |
||||||
| Ransomware | Hancock Public School id32909 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate it with a public education institution in Minnesota, reflecting its sector classification and geographic location. This listing type categorizes the entity based on observed threat-intelligence linkages rather than confirmed incident details. The associated threat actor identified is interlock, which contextualizes the entry within cyber threat intelligence reporting. The description remains factual and neutral, avoiding speculation regarding specific attack vectors, data handling, or operational impact. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32909 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the Education sector located in the United States, cataloged as a ransomware victim in the threat-intelligence index. The domain aligns with a public school or educational institution infrastructure in Minnesota, serving educational services and associated digital operations. This listing type identifies the entity as having experienced ransomware activity linked to the threat actor interlock. The description provides neutral, factual context regarding sector, location, and the specific association with interlock without disclosing unverified incident details such as data exfiltration specifics, ransom demands, or confirmed breach metrics. It serves as a reference point for threat analysts tracking ransomware incidents within U.S. educational environments and their connections to identified threat actors. |
||||||
| Ransomware | Hancock Public School id32909 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure indicates affiliation with a Minnesota-based educational institution or network, reflecting the sector and geographic context provided. As a ransomware victim listing, this entry documents the entity's relationship to the threat actor interlock, which has been associated with deploying ransomware campaigns targeting education infrastructure across the region. The description focuses on the entity's classification and contextual attributes rather than speculative details regarding specific attack vectors, data impacts, or resolution outcomes. This catalog entry serves to inform defenders and analysts about compromised infrastructure linked to known threat activity in critical public education environments. |
||||||
| Ransomware | Hancock Public School id32909 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is cataloged as a ransomware victim within the United States Education sector. The domain name and associated context indicate an educational institution or education-related entity operating within Minnesota, without disclosing specific incident details in the listing. As part of the threat-intelligence index, this entry documents the entity's classification alongside threat actor interlock, providing structured context for security professionals monitoring education sector incidents. The description remains neutral and avoids speculative claims regarding data exposure, operational impact, or confirmed breach specifics. This listing serves to identify the entity within the ransomware victim category linked to interlock for analytical and defensive reference. |
||||||
| Ransomware | Hancock Public School id32911 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. The listing identifies it as a ransomware victim within a threat-intelligence index, linked to the threat actor interlock. No specific incident details such as stolen data, affected systems, ransom demands, or breach confirmation are stated or invented in this description. The entry serves as catalog metadata for tracking the entity’s sector, geographic context, and its classification alongside identified threat activity. It neutrally records that https:hancock.k12.mn.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32911 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an entity within the United States education sector, specifically cataloged as a ransomware victim in threat-intelligence records. The domain structure and contextual metadata associate this listing with the threat actor interlock, indicating a cybersecurity incident classification relevant to institutional and educational infrastructure protection. This entry documents the entity's role within a ransomware incident profile, emphasizing sector context and geographic origin without disclosing unverified technical or operational details. The listing serves as a reference point for threat-intelligence analysis concerning education-sector organizations affected by coordinated cyber threats. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in threat-intelligence indexing. The domain structure indicates a connection to a public or educational institution operating within Minnesota, reflecting the sector and geographic context of the listing. This entry documents the association between the entity and the threat actor interlock, providing catalog-level intelligence for security analysts monitoring ransomware activity in educational environments. The description remains factual and neutral, focusing solely on the entity's classification, operational context, and verified threat actor linkage without speculating on incident details. This listing type serves to inform stakeholders about ransomware exposure patterns within the Education sector under the interlock threat actor umbrella. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an entity in the United States Education sector identified as a ransomware victim within the threat-intelligence index. The domain reflects a public-facing infrastructure component linked to an affected educational institution, with contextual details indicating its location within Minnesota and sector classification as education. This listing type categorizes the entity based on observed threat-intelligence linkages rather than confirmed technical specifics of any incident. The associated threat actor interlock is documented as the source or actor profile connected to this entry. The entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata align with a public or institutional education environment, reflecting the sector and geographic location specified for this listing. As a ransomware victim entry linked to the threat actor interlock, the record catalogs the relationship between this entity and the associated malicious campaign without disclosing unverified incident details such as data exfiltration specifics, ransom demands, or confirmed breach metrics. This description maintains a neutral, encyclopedic perspective suitable for catalog indexing and threat-intelligence analysis. The listing type explicitly categorizes the entity as a ransomware victim connected to interlock. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in a threat-intelligence index. The domain structure and associated context indicate involvement within a public or institutional education environment. This listing type categorizes the entity based on threat-intelligence analysis linking it to the threat actor interlock. No specific incident details such as data theft scope, ransom terms, or confirmed breach metrics are provided here to maintain factual neutrality. The entry serves catalog and analytical purposes for threat-intelligence researchers tracking ransomware activity across sectors and geographies. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and associated metadata indicate a public-facing institution or service context aligned with K-12 educational infrastructure in Minnesota. This listing type categorizes the entity based on its documented association with the threat actor interlock, reflecting cybersecurity intelligence observations regarding potential ransomware activity in this sector. The description avoids speculative details regarding data handling, breach confirmation, or specific incident outcomes, adhering to neutral analytical standards. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain name and associated context indicate involvement within a public or institutional education environment based in Minnesota. This listing type categorizes the entity as having experienced ransomware activity, with the associated threat actor designated as interlock, providing attribution context for security analysts and defenders. The description remains factual and neutral, focusing on sector classification, geographic location, operational context, and the established link to the specified threat actor without speculating on unconfirmed technical details, data impacts, or resolution specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity within the Education sector located in the United States, cataloged as a ransomware victim in a threat-intelligence index. The domain structure and contextual data align with a public education institution, reflecting common indicators associated with such environments. This listing type documents the entity's association with the threat actor interlock, providing cybersecurity stakeholders with verified linkage context. No specific incident details, such as data exfiltration scope or ransom terms, are included per strict factual constraints. The entry serves to inform defenders and analysts on potential attack pathways within this sector and geographic region. |
||||||
| Ransomware | Hancock Public School id32912 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain aligns with a public school or educational institution located in Minnesota, reflecting the sector and geographic context of the listing. This entry serves as a catalog reference for threat actors and cybersecurity analysts tracking ransomware incidents across educational infrastructure. The association with the threat actor interlock provides context for the attack vector and actor attribution within the intelligence database. The description remains factual and neutral, focusing on the entity’s classification, sector, location, and linkage to the specified threat actor without elaborating on unverified incident details. |
||||||
| Ransomware | Hancock Public School id32913 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate this listing with the threat actor interlock, which has been documented in cyber threat analysis for targeting educational infrastructure. This entry serves to catalog the entity's role in incident reporting and threat actor attribution, providing neutral context for security professionals monitoring ransomware activity across educational institutions. The description adheres to factual reporting standards without speculating on unverified incident details such as data exfiltration scope or operational impact. It neutrally states that this entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32918 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity within the United States Education sector identified as a ransomware victim in the threat-intelligence index. The domain structure and associated metadata indicate its role within a K-12 educational context in Minnesota. This listing type categorizes the entity based on its documented security incident profile and adversary linkage. The entity is formally associated with the threat actor interlock, reflecting the intelligence assessment linking this victim to that specific adversary group. This description remains strictly factual regarding sector, location, entity nature, and threat association without elaborating on unverified incident details. |
||||||
| Ransomware | Hancock Public School id32931 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity within the United States education sector, identified as a ransomware victim in threat-intelligence indexing. The domain context aligns with a public or institutional education environment in Minnesota, where such domains may serve administrative, instructional, or infrastructure functions. This listing type categorizes the entity based on its association with ransomware activity and the threat actor interlock, providing contextual intelligence for defenders assessing education-sector exposure and actor-linked incidents. The description remains factual and neutral, avoiding confirmation of specific breach details such as stolen data, affected records, ransom demands, or operational impact. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32931 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate it with the threat actor interlock, indicating a potential cybersecurity incident affecting educational infrastructure. This listing type categorizes the entity based on its documented relationship to ransomware activity and the specific threat actor interlock. The description remains neutral and factual, focusing on the entity's classification, sector context, geographic location, and associated threat actor without speculating on unconfirmed incident details such as data exfiltration scope, ransom demands, or internal impact specifics. This entry serves as a reference point for threat analysts monitoring ransomware trends within US education sectors. |
||||||
| Ransomware | Hancock Public School id32932 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity cataloged as a ransomware victim within the Education sector, located in the United States. The domain name indicates affiliation with a k12 educational network, suggesting institutional infrastructure tied to student services or school administration systems. This listing type identifies the entity as having been impacted by ransomware activity, with the associated threat actor and source designated as interlock. The entry reflects threat-intelligence indexing practices focused on mapping victim profiles, sector context, geographic origin, and adversary attribution without disclosing unverified technical or operational details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies a system or entity within the United States education sector, cataloged in the threat-intelligence index as a ransomware victim. The domain structure and associated context indicate involvement within a public or educational institution environment, where ransomware incidents frequently target critical infrastructure and student data. This listing reflects the entity's classification alongside the threat actor interlock, providing cybersecurity analysts with sector-specific intelligence for threat monitoring and defensive planning. No confirmed details regarding data stolen, ransom demands, or breach scope are included per strict factual constraints. The entry serves as a neutral reference point for understanding ransomware patterns within education environments in the US. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the United States education sector. The domain suggests affiliation with a Minnesota-based educational institution or service provider, though specific operational details remain limited to the index classification. This listing type categorizes the entity based on its documented association with the threat actor interlock, which has been linked to ransomware activity targeting educational infrastructure. The entry provides neutral context for catalog users seeking to understand the entity's sector, geographic scope, and threat relationship without asserting unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. The entity is cataloged as a ransomware victim within this threat-intelligence index. The listing explicitly associates this entity with threat actor interlock, indicating its role in the observed threat landscape. No specific incident details such as stolen data, ransom demands, or breach confirmation are provided in this catalog entry. This description focuses on the entity's classification, sector context, geographic location, and verified threat actor linkage for analytical reference. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim. Its domain structure and contextual metadata associate it with the United States education sector, indicating operational scope within public or institutional education environments. The listing type categorizes this entity as directly affected by ransomware activity linked to the threat actor interlock. No specific incident details such as stolen data, affected systems, ransom demands, or breach confirmation are provided or invented in this catalog entry. This description serves to neutrally document the entity's classification, sector context, geographic origin, and its association with interlock as a ransomware victim. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the US Education sector, identified within a threat-intelligence index as a ransomware victim linked to the interlock threat actor. The domain structure and contextual metadata indicate involvement within a public education environment, where cybersecurity incidents can significantly impact institutional operations and data integrity. This listing serves to catalog the entity's association with interlock for threat-intelligence analysis and monitoring purposes. The description remains factual and neutral, focusing solely on the verified categorization without extrapolating unconfirmed technical details or incident specifics. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with the US education sector and is cataloged as a ransomware victim within a threat-intelligence index. The domain naming pattern and sector context indicate an educational institution or related education-focused entity operating within Minnesota, United States. This listing type identifies the entity as having been affected by ransomware activity linked to the threat actor interlock. No specific incident details, such as stolen data categories, record counts, ransom amounts, or confirmed breach evidence, are included to maintain factual neutrality. The entry serves as an authoritative reference point for threat-intelligence analysts tracking ransomware incidents in education environments across the United States. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain structure indicates a public-facing network endpoint associated with a school or educational institution, reflecting the sector and geographic context of the listing. This entry documents the relationship between the entity and threat actor interlock within the ransomware victim category, providing catalog context for security analysts tracking education-sector incidents. The description remains factual and neutral, focusing on the entity's classification, sector, location, and associated threat actor without speculating on breach details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id32934 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is associated with an education-sector institution located in the United States. The entity functions within a K-12 educational context and is cataloged as a ransomware victim in the threat-intelligence index. Its classification reflects exposure linked to the threat actor interlock, which is documented in the associated threat intelligence records. This entry provides neutral context regarding the entity's sector, geographic scope, operational environment, and threat association without disclosing unverified incident details. The listing type identifies the entity specifically as a ransomware victim connected to interlock. |
||||||
| Ransomware | Hancock Public School id33088 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity associated with the Education sector and located within the United States. Its domain structure and contextual profile align with a ransomware victim listing within a threat-intelligence index. The entity is categorized as a ransomware victim and is linked to the threat actor interlock in the index metadata. No specific incident details such as stolen data, record counts, ransom amounts, or confirmed breach specifics are provided or invented in this description. This entry serves as a neutral catalog representation of the entity's classification, sector context, geographic location, and threat-actor association. |
||||||
| Ransomware | Hancock Public School id33142 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an entity within the Education sector located in the United States, identified in the threat-intelligence index as a ransomware victim. The domain context aligns with a public or institutional educational environment in Minnesota, where such incidents can significantly disrupt learning, administrative operations, and data continuity. This listing is linked to the threat actor interlock, reflecting the cybersecurity context in which the entity was cataloged by the intelligence index. The description remains neutral and factual, focusing on the entity's classification without asserting unverified details regarding breach scope, data handling, or operational impact. It serves as a reference point for threat-aware stakeholders monitoring ransomware activity across educational infrastructure in the US. |
||||||
| Ransomware | Hancock Public School id33143 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us is a domain associated with an Education sector entity located in the United States. The entity is cataloged as a ransomware victim within the threat-intelligence index, linked to the threat actor interlock. Its name and sector context indicate involvement within public or institutional education infrastructure, where security incidents can affect operational continuity and data governance. This listing provides neutral intelligence context for catalog maintainers, researchers, and defenders monitoring ransomware activity across education environments in the US. The entry reflects the entity's association with interlock without confirming specific incident details, breach scope, or recovery status. |
||||||
| Ransomware | Hancock Public School id33144 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and associated with the United States. The domain structure and contextual metadata indicate its affiliation with a public or educational institution, reflecting the sector and geographic scope of the listing. This entry documents the relationship between the entity and the threat actor interlock, providing catalog context for cybersecurity professionals monitoring ransomware activity across educational environments. No specific incident details such as data stolen, ransom demands, or breach confirmation are included, adhering to factual neutrality. The listing neutrally confirms that https:hancock.k12.mn.us was cataloged as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id33144 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the United States education sector. The domain structure and contextual metadata associate it with a school or educational institution located in Minnesota, reflecting the sector and geographic scope of the listing. This entry documents the entity's classification alongside the threat actor interlock, contributing to a structured catalog of ransomware incidents targeting education infrastructure. The description focuses on the entity's role in the index rather than speculative details about the attack, maintaining factual neutrality. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id33144 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us identifies an education sector institution located within the United States, cataloged as a ransomware victim within the threat-intelligence index. The domain aligns with a public school or educational network context, reflecting the sector and geographic location specified for this entity. This listing type documents the association with threat actor interlock, contributing to broader cyber threat intelligence resources for monitoring and defense. The description remains factual and neutral, focusing on the entity's categorization without elaborating on unverified incident details such as data stolen, affected records, ransom demands, or confirmed breach specifics. Authorities and analysts reference such entries to understand ransomware patterns within critical infrastructure sectors like education. |
||||||
| Ransomware | Hancock Public School id33144 View details | United States | Education | — | ||
|
https://hancock.k12.mn.us represents an education-sector institution located in the United States. The domain is cataloged as a ransomware victim within a threat-intelligence index, associated with the threat actor interlock. This listing type identifies the entity as having experienced ransomware activity, contextualized by its sector and geographic location. The description remains neutral regarding specific technical details, data impacts, or incident timelines, adhering to the constraints of verified intelligence reporting. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Hancock Public School id33144 View details | United States | Education | — | ||
|
https:hancock.k12.mn.us represents an entity within the United States education sector identified as a ransomware victim in a threat-intelligence index. The domain structure and contextual metadata indicate association with a public education institution, reflecting the sector and geographic location specified for this listing. This entry documents the incident within cybersecurity monitoring frameworks, highlighting exposure to ransomware activity without disclosing unverified technical or operational details. The listing type explicitly categorizes the entity as a ransomware victim associated with the threat actor interlock. This neutral catalog description serves to inform stakeholders of the indexed entity's classification and contextual threat profile. |
||||||