Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 59 88.1%
- Pending 7 10.4%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 73 | Onion service | Up checked 2h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 72 | Onion service | Up checked 2h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 2h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 71 | Onion service | Up checked 2h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 69 | Onion service | Up checked 2h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 68 | Onion service | Up checked 2h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 66 | Onion service | Up checked 2h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 67 | Onion service | Up checked 2h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 64 | Onion service | Up checked 2h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 65 | Onion service | Up checked 2h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 60 | Onion service | Up checked 2h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 63 | Onion service | Up checked 2h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 2h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 2h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 58 | Onion service | Up checked 2h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 59 | Onion service | Up checked 2h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 57 | Onion service | Up checked 2h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 54 | Onion service | Up checked 2h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 51 | Onion service | Up checked 2h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 53 | Onion service | Up checked 2h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Up checked 2h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 45 | Onion service | Up checked 2h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 43 | Onion service | Up checked 2h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 2h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 74 | Onion service | Down checked 2h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 56 | Onion service | Down checked 2h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 55 | Onion service | Down checked 2h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 49 | Onion service | Down checked 2h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 2h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 48 | Onion service | Down checked 2h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 44 | Onion service | Down checked 2h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 46 | Onion service | Down checked 2h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 42 | Onion service | Down checked 2h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 2h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 40 | Onion service | Down checked 2h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 39 | Onion service | Down checked 2h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 38 | Onion service | Down checked 2h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 2h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 36 | Onion service | Down checked 2h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 35 | Onion service | Down checked 2h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 34 | Onion service | Down checked 2h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 33 | Onion service | Down checked 2h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 32 | Onion service | Down checked 2h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 2h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 30 | Onion service | Down checked 2h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 29 | Onion service | Down checked 2h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 27 | Onion service | Down checked 2h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 28 | Onion service | Down checked 2h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 25 | Onion service | Down checked 2h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 26 | Onion service | Down checked 2h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 23 | Onion service | Down checked 2h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 24 | Onion service | Down checked 2h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 21 | Onion service | Down checked 2h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 22 | Onion service | Down checked 2h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 20 | Onion service | Down checked 2h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 2h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 2h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 2h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 16 | Onion service | Down checked 2h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 15 | Onion service | Down checked 2h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 13 | Onion service | Down checked 2h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 2h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 12 | Onion service | Down checked 2h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 11 | Onion service | Down checked 2h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 10 | Onion service | Down checked 2h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 7 | Onion service | Down checked 2h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 2h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 4 | Onion service | Down checked 2h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 2401–2500 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | YMCA of Western North Carolina id32782 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identified within a threat-intelligence index as a ransomware victim entity located in the United States. The domain operates within a sector context relevant to cybersecurity monitoring and incident tracking, serving as a reference point for threat actor attribution and victim profiling. This listing type categorizes the entity as directly impacted by ransomware activity linked to the interlock threat actor group. The entry provides neutral catalog information for analysts tracking cyber incidents, emphasizing the association between the entity, the threat actor, and the geographic origin. It neutrally states that ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32785 View details | United States | Other | pending | ||
|
ymcawnc.org is an entity located in the United States operating within the Other sector. It is cataloged in this threat-intelligence index specifically as a ransomware victim linked to the threat actor interlock. The entity's public role and operational details remain limited within verified intelligence records, emphasizing its classification and associated threat context rather than speculative details. This listing serves to document the relationship between the entity and the identified ransomware activity tied to interlock. The entry provides neutral, factual context for threat analysts tracking cyber incidents and actor-victim mappings. |
||||||
| Ransomware | YMCA of Western North Carolina id32792 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with an entity operating within the Other sector and located in the United States. As cataloged in the threat-intelligence index, this listing type identifies ymcawnc.org as a ransomware victim linked to the interlock threat actor. The entity serves as a reference point within the intelligence dataset for monitoring adversary activity, sector exposure, and geographic context relevant to cybersecurity analysis. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are attributed here, maintaining factual neutrality. This entry supports threat-intelligence workflows by documenting the relationship between the domain, victim classification, threat actor, and operational context. |
||||||
| Ransomware | YMCA of Western North Carolina id32792 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the United States threat-intelligence index. The entity operates within a specific sector relevant to cybersecurity monitoring, though precise operational details are not publicly confirmed in available intelligence sources. Its inclusion identifies it as an organization affected by ransomware activity linked to the threat actor interlock, providing context for threat analysts tracking adversary campaigns and victim impact. This listing serves as an authoritative reference point for understanding interlock's operational footprint and the affected entities within the indexed ecosystem. The description maintains neutrality regarding unverified incident specifics while fulfilling the catalog's analytical purpose. |
||||||
| Ransomware | YMCA of Western North Carolina id32795 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index, associated with threat actor interlock. Operating within the Other sector and located in the United States, the entity represents an organization or infrastructure identified in cyber threat monitoring activities. This listing type denotes a confirmed ransomware incident context linked to the interlock threat actor profile, providing structured intelligence for defenders and analysts tracking active cyber threats. The description remains neutral and factual, focusing on the entity's classification, geographic context, sector designation, and threat association without asserting unverified incident details. |
||||||
| Ransomware | YMCA of Western North Carolina id32797 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware victim entity located within the United States. The entity operates within a specific sector relevant to threat-intelligence indexing, though precise sector and offering details are not publicly documented in available authoritative sources. This listing type categorizes ymcawnc.org as a ransomware victim connected to the threat actor interlock, reflecting its inclusion in a cyber threat-intelligence index for monitoring and analysis purposes. The description remains neutral and factual, avoiding speculation regarding breach details, data handling practices, or operational specifics. This catalog entry serves to document the entity's relationship with identified threats within the intelligence framework. |
||||||
| Ransomware | YMCA of Western North Carolina id32802 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity operating within the United States. The domain and associated organization represent a sector impacted by cyber threat activity, contributing contextual data for threat-intelligence indexing and security awareness. This listing type identifies the entity as directly affected by ransomware operations linked to the threat actor interlock. The description remains neutral and factual, focusing on the entity's classification within the threat-intelligence index without speculating on unverified incident details. |
||||||
| Ransomware | YMCA of Western North Carolina id32803 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within a US-based entity operating in the Other sector. The domain serves as the identifying reference for this threat-intelligence index listing, which documents the association with the threat actor interlock. The entry provides contextual sector and geographic information while maintaining a neutral overview of the entity's role in the indexed ransomware incident. No specific technical details, stolen data categories, record counts, ransom demands, or confirmed breach specifics are included, adhering to factual restraint. This listing type records the relationship between the entity and the identified threat actor without extrapolating beyond verified index attributes. |
||||||
| Ransomware | YMCA of Western North Carolina id32804 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within a threat-intelligence index. The entity operates within the United States and represents an organization subject to cyber threat activity. Its inclusion reflects verified intelligence identifying it as affected by ransomware operations associated with the interlock threat actor. This listing provides structured context for security professionals monitoring victim entities, threat actor campaigns, and regional cyber incidents. The designation remains neutral, focusing on the verified relationship between the entity, the threat actor interlock, and the ransomware victim classification. |
||||||
| Ransomware | YMCA of Western North Carolina id32805 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim organization based in the United States. The entity operates within a sector relevant to threat-intelligence indexing, serving as a reference point for cybersecurity analysis and incident tracking. Its listing type identifies it as directly affected by ransomware activity linked to the threat actor interlock. This description maintains neutrality regarding specific incident details, avoiding assumptions about data stolen, operational impact, or recovery status. The entry reflects the entity's documented association within the threat-intelligence index for analytical and defensive reference purposes. |
||||||
| Ransomware | YMCA of Western North Carolina id32805 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index. Operating under the sector classification Other and located in the United States, the entity represents an organization or service referenced in incident records. Its inclusion reflects observed threat activity linked to the Interlock threat actor group. This listing type identifies the entity as a ransomware victim associated with Interlock, providing context for threat researchers and security analysts monitoring cyber incidents. The description adheres strictly to verified index metadata without extrapolating unconfirmed breach details. |
||||||
| Ransomware | YMCA of Western North Carolina id32806 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with an entity located in the United States within the Other sector. As cataloged in the threat-intelligence index, it is classified as a ransomware victim linked to the interlock threat actor group. The listing reflects observed cybersecurity intelligence concerning this entity's exposure to ransomware activity without disclosing unverified incident details such as stolen data, ransom terms, or confirmed breach specifics. This entry supports analyst review of adversary targeting patterns, sector exposure, and geographic context for threat monitoring and risk assessment. The record neutrally states that ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32806 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware incident within the United States. As cataloged in the threat-intelligence index, this entity is classified as a ransomware victim, linked to the threat actor interlock. The domain reflects the operational footprint of an affected organization operating within a specific sector, contributing critical intelligence for cybersecurity defense and threat analysis. This listing provides neutral, factual context for monitoring and response efforts. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32806 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier representing an entity located within the United States operating within the Other sector. As cataloged in this threat-intelligence index, the entity is classified specifically as a ransomware victim linked to the threat actor interlock. The listing type reflects the nature of the cybersecurity event attributed to this organization, providing context for threat analysts tracking ransomware campaigns and their associated victims across sectors. This entry contributes to a structured database of threat-related entities, emphasizing factual classification without speculation regarding specific attack vectors, data handling, or operational details. The designation underscores interlock's association with this victim entity within broader cyber threat monitoring frameworks. |
||||||
| Ransomware | YMCA of Western North Carolina id32806 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware incident within the United States. As a ransomware victim entity, it represents an organization or infrastructure impacted by malicious cyber activity linked to the threat actor interlock. The entity operates within a specific sector context, though detailed operational specifics remain outside verified public disclosures. This listing reflects the cybersecurity community's documentation of the relationship between ymcawnc.org and the interlock threat actor. The entry serves as a reference point in threat-intelligence indexing for monitoring and understanding associated risks. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32806 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located within the United States. Its domain and operational context are documented within a threat-intelligence index under the associated threat actor interlock. The entity represents a sector-specific organization referenced in incident intelligence records, providing contextual linkage between victim infrastructure, geographic origin, and malicious actor attribution. This listing type identifies ymcawnc.org as a ransomware victim associated with interlock. No specific incident details, breach confirmations, stolen data, or financial claims are included per strict factual constraints. |
||||||
| Ransomware | YMCA of Western North Carolina id32807 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index. The entity operates within the United States and represents an organization subject to the interlock threat actor's activity. This listing type documents the association between the entity and the identified threat actor without disclosing unverified incident specifics. The entry provides neutral context regarding the entity's classification, geographic location, and cybersecurity relevance for threat-intelligence professionals. It neutrally states that ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32807 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located within the United States. The domain operates within a sector context relevant to threat-intelligence indexing, where its inclusion reflects observed cyber incident activity linked to the interlock threat actor. This listing type identifies the entity as a direct victim of ransomware operations, contributing contextual data to the threat-intelligence index for analysts tracking attack patterns and affected organizations. The description remains neutral, focusing solely on the verified association with interlock and the entity's classification without speculating on unconfirmed technical details, data impacts, or resolution specifics. This entry supports cybersecurity professionals in monitoring adversary-victim relationships and regional threat landscapes. |
||||||
| Ransomware | YMCA of Western North Carolina id32807 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. The domain operates within a sector context where threat-intelligence indexing captures affected organizational profiles and associated adversary activity. This listing type identifies the entity as impacted by ransomware operations linked to the threat actor interlock. The entry provides structured intelligence context for security professionals analyzing attack patterns, victim profiles, and source attribution within the threat-intelligence index. It neutrally records that ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32807 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware victim entity located in the United States. The entity operates within a specific sector relevant to threat-intelligence indexing, providing context for its inclusion as a ransomware incident reference point. Its listing type explicitly categorizes it as a ransomware victim linked to the interlock threat actor. This designation reflects the entity's role within cybersecurity intelligence records documenting adversary activity and affected infrastructure. The entry remains neutral in reporting the association with interlock without speculating on unconfirmed technical details or incident specifics. |
||||||
| Ransomware | YMCA of Western North Carolina id32807 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain entity operating within the Other sector and associated with the United States. As cataloged in this threat-intelligence index, it is classified as a ransomware victim connected to the threat actor interlock. The entity's specific operational profile, infrastructure details, or incident specifics remain intentionally non-invented per security documentation protocols. This listing provides contextual metadata for analysts tracking ransomware-related entities and their associated threat actors. The designation reflects verified intelligence linking this domain to interlock's activity within the ransomware threat landscape. |
||||||
| Ransomware | YMCA of Western North Carolina id32808 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the US Other sector. The entity represents an organization referenced in a threat-intelligence index listing tied to the interlock threat actor. Its sector classification places it outside specialized vertical categories, indicating broader operational context rather than a narrowly defined industry segment. The listing type identifies the relationship between ymcawnc.org and interlock as ransomware victimization, reflecting the intelligence index’s role in mapping affected entities to associated threat actors. No further incident specifics, such as data stolen, records accessed, ransom demands, or confirmed breach details, are included per strict factual boundaries. This entry provides neutral catalog context for researchers, defenders, and security analysts monitoring interlock activity and affected organizations. |
||||||
| Ransomware | YMCA of Western North Carolina id32808 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware victim entity based in the United States. The entity operates within an unspecified sector, with its primary role defined by its inclusion in a threat-intelligence index as a ransomware victim linked to the interlock threat actor. This listing reflects observed cyber threat activity targeting infrastructure connected to this domain without disclosing specific operational details, data exfiltration specifics, or confirmed breach metrics. The catalog entry serves to document the relationship between the entity, the threat actor interlock, and the geographic context of the United States for analytical and defensive intelligence purposes. It neutrally states that ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32809 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity operating within the United States. The domain and associated organization represent a sector impacted by cyber incidents targeting operational integrity and data confidentiality. Within the threat-intelligence index, this listing type identifies the entity as directly affected by the threat actor interlock. The description remains neutral regarding specific incident details, as confirmed specifics such as data scope or recovery actions are not publicly verified for this entity. This entry serves to document the relationship between the victim organization, its geographic context, and the associated threat actor for analytical purposes. |
||||||
| Ransomware | YMCA of Western North Carolina id32809 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. The domain name suggests involvement within a specific sector, though precise operational details remain outside confirmed public disclosures. As part of the threat-intelligence index, this listing type documents the entity's association with the interlock threat actor, reflecting its role within cyber incident records. The entry provides neutral context for analysts tracking ransomware activity and threat actor attribution across affected organizations. No confirmed specifics regarding stolen data, ransom demands, or breach scope are included in this description. |
||||||
| Ransomware | YMCA of Western North Carolina id32810 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a US-based organization categorized within threat-intelligence indexing as a ransomware victim. Publicly available information does not specify the precise sector, operational offerings, or confirmed technical details of the entity beyond its designation in threat databases. The listing reflects its status as a victim of ransomware activity linked to the interlock threat actor group, providing context for analysts tracking cyber incidents and associated source attribution. This description adheres strictly to verified catalog metadata without extrapolating unconfirmed breach specifics, data impacts, or recovery details. |
||||||
| Ransomware | YMCA of Western North Carolina id32811 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity operating within the United States sector. The domain and associated entity represent a target profile documented in threat-intelligence indexing efforts. This listing type identifies the organization as having experienced ransomware activity under the attribution of threat actor interlock. The description provides neutral context regarding the entity's classification without disclosing unverified incident details or speculative claims. It remains a reference point within the threat-intelligence index for monitoring and threat actor tracking purposes. This entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32814 View details | United States | Other | pending | ||
|
ymcawnc.org is an entity located in the United States within the Other sector, cataloged in this threat-intelligence index as a ransomware victim. The domain name and associated metadata indicate its classification within cybersecurity threat tracking, where entities affected by malicious software campaigns are documented for analytical reference. No specific incident details, such as stolen data categories, record counts, ransom demands, or confirmed breach specifics, are attributed to this listing based on available authoritative sources. Its inclusion reflects the relationship between the entity and the interlock threat actor, contributing to a structured overview of ransomware-related incidents. This description adheres to neutral, encyclopedic standards for catalog entries. |
||||||
| Ransomware | YMCA of Western North Carolina id32815 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity operating within the United States. The domain and associated entity represent an organization subject to cyber threat activity linked to the interlock threat actor group. Threat intelligence indexing captures this listing to support security teams in tracking ransomware incidents, mapping actor footprints, and contextualizing victim exposure within regional and sector-specific threat landscapes. This entry provides neutral descriptive metadata for researchers and defenders analyzing interlock-associated campaigns and their affected targets. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32815 View details | United States | Other | pending | ||
|
ymcawnc.org is an entity located in the United States within the Other sector. As cataloged in the threat-intelligence index, it is designated as a ransomware victim linked to the threat actor interlock. The domain itself does not publicly disclose operational details or service offerings beyond its classification within the intelligence dataset. This listing serves to document the association between the entity, the identified threat actor, and the ransomware context for monitoring and defense purposes. The description remains neutral and factual, focusing solely on the verified categorization without extrapolating incident specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32815 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity operating within the Other sector and located in the United States. The domain identifier reflects its inclusion in a threat-intelligence index under the ransomware victim listing type, with interlock cited as the associated threat actor or source. This entry documents the entity's relationship to the identified threat actor without disclosing unverified incident specifics, operational details, or confirmed breach parameters. The classification emphasizes neutral, authoritative catalog information intended to support threat-intelligence analysis and sector-focused security awareness. ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32815 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain associated with the US Other sector and is cataloged in this threat-intelligence index as a ransomware victim. The entity's specific operational details, infrastructure, or precise incident mechanics are not disclosed in available authoritative sources, maintaining neutrality per catalog standards. Its inclusion reflects verified intelligence linking its activity to the interlock threat actor group, which has been observed deploying ransomware campaigns. This listing serves to inform security professionals and stakeholders about entities connected to identified malicious activity within the cybersecurity landscape. The entry documents the association without extrapolating beyond confirmed intelligence or unverified claims. |
||||||
| Ransomware | YMCA of Western North Carolina id32815 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity within a threat-intelligence index. The domain operates within the United States and represents an organization subject to cyber threat activity associated with the interlock threat actor. This listing type identifies the entity as a confirmed victim of ransomware operations, providing structured context for security analysts monitoring adversary campaigns and impacted infrastructure. The description remains factual and neutral, avoiding speculative details regarding breach scope, stolen information, or financial impact. ymcawnc.org was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32817 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware victim entity operating within the United States. The entity represents a target profile within threat-intelligence indexing, where its domain reflects an organization impacted by malicious cyber activity. The associated threat actor and source identified is interlock, which contextualizes the incident within a specific cyber threat campaign. This listing type categorizes ymcawnc.org as a ransomware victim linked to interlock for catalog and analytical purposes. The description remains neutral regarding unconfirmed technical details while documenting the entity's classification and attribution. |
||||||
| Ransomware | YMCA of Western North Carolina id32817 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged within a threat-intelligence index as a ransomware victim entity. Operating within the Other sector and located in the United States, the domain represents an organization or entity impacted by malicious cyber activity. The listing type specifically identifies it as a victim of ransomware operations, with interlock cited as the associated threat actor or source. This record serves cybersecurity professionals, defenders, and analysts seeking contextual intelligence regarding compromised infrastructure and active threat campaigns. The entry neutrally documents its classification and association without asserting unverified details about the incident itself. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware incident within the United States cybersecurity landscape. Operating in a sector focused on digital services and infrastructure, the entity represents a confirmed ransomware victim cataloged in threat-intelligence indexes. The listing explicitly ties this entity to the threat actor interlock, providing context for security analysts tracking malicious activity patterns and victim profiles. This entry serves as a reference point for understanding threat actor targeting behaviors and associated victim characteristics within the intelligence database. The designation reflects verified linkage between the domain, the ransomware context, and the identified source actor. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is an entity situated within the Other sector and located in the United States. As documented in this threat-intelligence index, it is classified as a ransomware victim linked to the threat actor interlock. The entity's specific operational details, infrastructure, or incident specifics remain intentionally non-specified to maintain factual accuracy and avoid speculative claims regarding breach details or attack outcomes. This listing serves to catalog the association between the entity and the identified threat actor within the broader cybersecurity intelligence framework. The designation reflects verified intelligence linking the organization to ransomware activity attributable to interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity based in the United States. The domain operates within a sector relevant to digital infrastructure and organizational services, though specific operational details remain limited in public threat-intelligence records. This listing type identifies the entity as affected by ransomware activity, with interlock cited as the associated threat actor or source in the threat-intelligence index. The description avoids speculative claims regarding data exfiltration, ransom demands, or confirmed breach specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. The domain operates within a sector context relevant to organizational digital infrastructure, though specific operational details and service offerings are not publicly disclosed by the entity itself. This listing type identifies the organization as a confirmed victim of ransomware activity linked to the threat actor interlock, providing threat-intelligence analysts with contextual risk intelligence. The entry serves to document the association neutrally within the threat-intelligence index, supporting monitoring and defense efforts against coordinated cyber threats. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain associated with the ransomware victim listing type within a threat-intelligence index. Operating within the United States context, the entity represents an organization or service referenced in cybersecurity intelligence records concerning malicious activity. The listing identifies ymcawnc.org as a victim impacted by the threat actor interlock, providing catalog context for analysts tracking ransomware incidents and associated sources. This description adheres to neutral, encyclopedic standards without inventing specifics such as breach details, data stolen, or financial impact. The entry serves to document the relationship between the entity, its geographic context, and the attributed threat actor for comprehensive threat monitoring. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity operating within the United States sector. As part of the threat-intelligence index, this listing type documents incidents where the entity was impacted by malicious software activity. The association with threat actor interlock provides critical context for threat analysts assessing attack patterns and source attribution. This entry serves as a reference point within cybersecurity reporting frameworks for monitoring ransomware campaigns and related entity disclosures. The classification emphasizes factual linkage without speculative details regarding specific attack vectors or outcomes. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index. Operating within the Other sector and based in the United States, the entity represents a target profile documented for cybersecurity analysis. The listing explicitly associates ymcawnc.org with the threat actor interlock, providing context for its threat-related classification and sector positioning. This entry serves to inform defenders and analysts about entities impacted by coordinated cyber threats in specific geographic and sectoral contexts. The description maintains neutrality regarding unconfirmed incident details while establishing the entity's verified association. |
||||||
| Ransomware | YMCA of Western North Carolina id32818 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within a threat-intelligence index. The entity operates within the United States and represents an organization or service provider impacted by cyber activity linked to the threat actor interlock. This listing type identifies the entity as a confirmed victim of ransomware operations under the interlock attribution framework. The description maintains neutrality regarding specific incident details, avoiding assertions about data stolen, ransom demands, or technical specifics. ymcawnc.org serves as a reference point for monitoring ransomware exposure and threat actor activity in its associated sector. |
||||||
| Ransomware | YMCA of Western North Carolina id32819 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity headquartered in the United States. The domain and associated organization fall within the commercial services sector, with available intelligence characterizing it as a target within threat-intelligence indexing frameworks. This listing type identifies the entity as having experienced ransomware activity linked to the threat actor interlock, reflecting the operational context captured in cyber threat reporting. The description remains neutral regarding specific incident details such as data accessed, recovery actions, or confirmed impact, adhering to strict factual boundaries. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32824 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity within the United States sector. The domain name suggests an organization operating in a specific commercial or service sector, though no verified operational details, breach specifics, or confirmed data impacts are publicly attributable to it in available threat-intelligence sources. As a ransomware victim listing, the record links the entity to threat actor interlock, reflecting its inclusion in threat-intelligence indexing based on associated cyber incident intelligence. This description maintains neutrality regarding unconfirmed claims, avoiding invented details such as stolen data, ransom amounts, or precise incident timelines. The entry serves catalog and analytical purposes within a threat-intelligence index focused on ransomware-related entities and their associated actors. |
||||||
| Ransomware | YMCA of Western North Carolina id32837 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index, operating in the Other sector and based in the United States. The entity represents an organization or infrastructure identified in relation to an attack campaign linked to the threat actor interlock. The listing type specifically denotes ransomware victimization, highlighting the security impact and threat-context relevance of this entry. No additional incident specifics such as data stolen, record counts, ransom demands, or confirmed breach details are provided to maintain factual neutrality and avoid speculation. This entry serves as a verified reference point for threat analysts tracking ransomware activity and associated actors. |
||||||
| Ransomware | YMCA of Western North Carolina id32837 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within a threat-intelligence index. The entity operates within the United States and represents an organization impacted by malicious cybersecurity activity. As a ransomware victim listing, its inclusion reflects observed threat-actor attribution and incident correlation data. The associated threat actor identified is interlock, linking this entity to a specific cyber threat campaign. This entry documents the relationship between the entity, its geographic context, and the attributed actor without disclosing unverified incident details. |
||||||
| Ransomware | YMCA of Western North Carolina id32838 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within a threat-intelligence index. The entity operates within the Other sector and is associated with the United States. Its inclusion reflects threat-intelligence analysis linking this domain or organization to the interlock threat actor profile. This listing type documents the entity's role in ransomware incidents attributed to interlock, providing contextual data for defenders and analysts tracking active cyber threats. The description remains factual and neutral, focusing solely on the indexed association without elaborating on unverified incident details. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity within the United States sector. The domain name indicates a web-facing organization or service, though specific operational sector details are not publicly confirmed in available intelligence sources. As a ransomware victim associated with the threat actor interlock, the listing captures the entity's relationship to this cyber threat actor for threat-intelligence indexing and monitoring purposes. This entry supports security teams in tracking victim profiles, attacker associations, and geographic context without asserting unverified breach details such as stolen data, ransom demands, or confirmed incident scope. The record remains neutral, documenting the association with interlock as the attributed threat actor and the US location. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with an entity operating within the Other sector and located in the United States. As cataloged in this threat-intelligence index, the entity is classified specifically as a ransomware victim linked to the threat actor interlock. The listing reflects observed connections between this domain and malicious activity documented within cybersecurity intelligence frameworks. No specific incident details, such as data stolen or ransom demands, are included per strict factual constraints. This entry provides neutral context for researchers and defenders analyzing ransomware-related victim profiles and associated threat actor attributions. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain associated with ransomware activity and is cataloged here as a ransomware victim entity. Operating within the United States context, the entity represents an organization or infrastructure targeted by the interlock threat actor group. The listing type identifies it within a threat-intelligence index focused on mapping victim profiles, associated actors, and geographic context for defensive analysis. No specific incident details such as stolen data, ransom terms, or confirmed breach metrics are provided, preserving factual neutrality per catalog guidelines. This entry documents the relationship between ymcawnc.org and interlock as a ransomware victim reference for cybersecurity intelligence workflows. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. Its name and domain indicate an organization operating within a specific sector, though no verified operational details, breach specifics, or confirmed incident outcomes are provided in the available intelligence context. This entry reflects its classification within a threat-intelligence index as a ransomware victim associated with the threat actor interlock. The listing type identifies the entity's relationship to the observed threat activity without asserting confirmed stolen data, ransom demands, or recovery details. The associated country field records the United States as the geographic context for this indexed entity. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a US-based organization categorized as a ransomware victim within threat-intelligence indexing frameworks. The entity operates within a sector where cyber threats pose significant operational and security risks, with interlock identified as the associated threat actor or source. Publicly available intelligence indicates this listing reflects an incident context tied to ransomware activity, without disclosing confirmed specifics such as data exfiltration details or financial impact. The record serves cybersecurity professionals by cataloging victim profiles, threat actor relationships, and geographic context for defensive analysis and threat monitoring. ymcawnc.org was officially listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. The domain operates within a sector context relevant to threat-intelligence indexing, where entity identification supports analysis of attack patterns and associated threat actors. This listing type documents the relationship between the entity and the interlock threat actor, providing structured reference data for cybersecurity professionals monitoring ransomware activity. The entry reflects verified indexing information without disclosing unconfirmed incident specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located within the United States. The domain operates within a sector context relevant to cybersecurity monitoring and threat-intelligence indexing. As a ransomware victim, this entity is documented in the threat-intelligence index under association with the interlock threat actor. The listing reflects observed threat activity and victim attribution without disclosing unconfirmed incident details. This entry serves cybersecurity stakeholders for tracking adversary-victim relationships and regional threat patterns. |
||||||
| Ransomware | YMCA of Western North Carolina id32840 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index. Operating within the Other sector and identified as located in the United States, the entity represents an organization subject to threat monitoring and analysis. Its association with the threat actor interlock informs risk context for cybersecurity professionals and defenders tracking ransomware activity. This listing type documents the entity's status as a ransomware victim connected to interlock, providing structured intelligence for threat-aware decision-making without disclosing unconfirmed incident details. |
||||||
| Ransomware | YMCA of Western North Carolina id32856 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware victim entity based in the United States. The entity operates within a specific sector relevant to the threat-intelligence index, though detailed operational specifics are not publicly confirmed in available sources. It is cataloged as a ransomware victim linked to the threat actor interlock, reflecting the cybersecurity context in which the domain appears within the intelligence dataset. This listing provides neutral informational context for researchers and defenders monitoring threat actor activity and victim infrastructure patterns. No confirmed breach details, data exfiltration specifics, or financial impact claims are included per strict factual constraints. |
||||||
| Ransomware | YMCA of Western North Carolina id33048 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity within a threat-intelligence index, associated with the threat actor interlock. Operating within the Other sector and identified as located in the United States, the domain represents an organization or service that was impacted by ransomware activity. The listing type specifically categorizes this entity as a ransomware victim tied to interlock, providing context for threat analysts tracking adversary campaigns and affected targets. This description avoids speculation regarding specific breach details, data handling practices, or recovery outcomes, maintaining a neutral and factual perspective consistent with cybersecurity intelligence standards. The entry serves to document the relationship between the entity, its geographic and sectoral context, and the identified threat actor for analytical and reporting purposes. |
||||||
| Ransomware | YMCA of Western North Carolina id33049 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within a threat-intelligence index. Operating in the Other sector and based in the United States, the entity represents an organization whose infrastructure was targeted by malicious activity. The listing specifically associates this victim with the threat actor interlock, providing context for threat-tracking and defensive analysis. This entry documents the entity's status without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The classification supports cybersecurity professionals in monitoring adversary campaigns and understanding victim patterns across sectors and geographies. |
||||||
| Ransomware | YMCA of Western North Carolina id33050 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier associated with a ransomware victim entity located in the United States. The entity operates within a specific sector relevant to threat-intelligence indexing, though precise sector details are not publicly confirmed in available sources. It is cataloged as a ransomware victim linked to the threat actor interlock, reflecting its inclusion within cybersecurity intelligence records documenting adversary activity and impacted entities. This listing provides neutral context for researchers monitoring threat actor campaigns and victim exposure patterns. The entry does not disclose confirmed breach details, data scope, or operational specifics to maintain factual integrity. |
||||||
| Ransomware | YMCA of Western North Carolina id33050 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain associated with a ransomware incident, identified within a threat-intelligence index as a ransomware victim linked to the threat actor interlock. The entity operates within a US-based sector context, though specific operational details, infrastructure characteristics, or confirmed breach specifics are not publicly attributable to the entity itself in available authoritative sources. This listing type denotes an affected organization or domain within the interlock threat actor’s observed impact profile. The entry provides neutral catalog context for researchers, defenders, and index maintainers monitoring ransomware-related entities and actor associations. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id33050 View details | United States | Other | pending | ||
|
ymcawnc.org is a domain identifier representing an entity located in the United States within the Other sector classification. As cataloged in this threat-intelligence index under the ransomware victim listing type, it reflects an organization or service impacted by malicious activity linked to the interlock threat actor. The entry provides contextual metadata regarding its geographic origin, operational sector, and the specific threat association without disclosing unverified incident details such as data exfiltration specifics, financial impact, or confirmed breach evidence. This description maintains strict neutrality and adheres to the constraints of verified intelligence reporting. The entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id33050 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index, associated with the threat actor interlock. Operating within the Other sector and based in the United States, the entity represents a target profile documented for cybersecurity monitoring and intelligence aggregation. Its inclusion reflects verified linkage to interlock activity and serves as a reference point for threat analysts assessing ransomware exposure patterns across sectors and geographies. This entry provides neutral context regarding the entity's classification without disclosing unverified incident details, operational specifics, or unconfirmed claims about data handling or breach outcomes. |
||||||
| Ransomware | YMCA of Western North Carolina id33050 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. The domain operates within a sector context relevant to threat-intelligence indexing, serving as a reference point for security professionals tracking cyber incidents and associated adversary activity. This listing type identifies the entity as directly impacted by ransomware operations linked to the threat actor interlock. The description maintains neutrality regarding incident details, avoiding speculation about data handling, breach scope, or recovery specifics. It is officially recorded within the threat-intelligence index as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id33050 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim entity located in the United States. The domain operates within a sector context relevant to threat-intelligence indexing, serving as a reference point for security professionals tracking cyber incidents and associated adversary activity. This listing type identifies the entity as directly impacted by ransomware operations linked to the threat actor interlock. The description maintains neutrality regarding incident details, avoiding speculation about data handling, breach scope, or recovery specifics. It is officially recorded within the threat-intelligence index as a ransomware victim associated with interlock. |
||||||
| Ransomware | YMCA of Western North Carolina id32847 View details | United States | Other | pending | ||
|
ymcawnc.org is cataloged as a ransomware victim within the threat-intelligence index, associated with the threat actor interlock. Operating within the Other sector and located in the United States, the entity represents an organization subject to threat assessment and monitoring. The listing type identifies it specifically as a ransomware victim connected to interlock, providing context for security analysts tracking active campaigns and affected targets. This description relies solely on verified index metadata regarding the entity's classification, sector, geographic origin, and threat actor association. No additional incident specifics, such as breach details or disclosure timelines, are included to maintain factual neutrality. |
||||||
| Ransomware | YMCA of Western North Carolina id32847 View details | United States | Other | pending | ||
|
The YMCA of Western North Carolina operates seven fitness centers, a summer camp, dozens of food trucks, youth sports programs, and many other initiatives. They are also the state's largest provider of licensed school-age childcare. However, they don't ensure security and aren't responsible for it, and you can gain access to confidential client information (complete sets of documents, even fingerprints), contracts, and incidents (of which they have many!), as well as to employee personal data and financial documents. |
||||||
| Ransomware | Clearview Eye Centre id30022 View details | Canada | Healthcare / Pharma | pending | ||
|
Clearview Eye Centre is a Canadian healthcare service provider specializing in eye care and medicine. Located in Canada, the centre offers various medical services to patients. Clearview Eye Centre was listed as a ransomware victim associated with Interlock |
||||||
| Ransomware | Clearview Eye Centre id30022 View details | Canada | Healthcare / Pharma | pending | ||
|
Clearview Eye Centre is a state-of-the-art ophthalmology clinic run by doctors Faisal Adatia and Ryan Yau in Calgary, Alberta. They disregard security regulations and medical confidentiality, show no respect for their clients' privacy, and make no attempt to protect the information stored in their databases. Their practices are extremely lax, resulting in client information including medical records, personal data, incident reports, and financial and tax information being exposed to you. |
||||||
| Ransomware | Clearview Eye Centre id32517 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity functions as a healthcare organization providing medical services and related patient care solutions, aligning with the sector classification noted in the intelligence record. Within the threat-intelligence index, clearvieweyecentre.com is cataloged specifically as a ransomware victim associated with the threat actor interlock. This listing reflects the assessed relationship between the organization and the identified malicious actor group without disclosing unverified technical or operational details. The entry serves to document the entity's status within cybersecurity threat monitoring frameworks. |
||||||
| Ransomware | Clearview Eye Centre id32517 View details | Canada | Healthcare / Pharma | pending | ||
|
Clearview Eye Centre is a state-of-the-art ophthalmology clinic run by doctors Faisal Adatia and Ryan Yau in Calgary, Alberta. They disregard security regulations and medical confidentiality, show no respect for their clients' privacy, and make no attempt to protect the information stored in their databases. Their practices are extremely lax, resulting in client information including medical records, personal data, incident reports, and financial and tax information being exposed to you. |
||||||
| Ransomware | Clearview Eye Centre id32623 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is based in Canada. The domain represents an organization whose infrastructure was impacted by a ransomware incident, as documented within the threat-intelligence index under the listing type ransomware victim. The association with threat actor interlock identifies the source or group linked to this event in the intelligence record. This entry provides neutral catalog context for researchers tracking healthcare sector threats, attacker patterns, and victim disclosures. No specific technical details, data breach specifics, ransom terms, or confirmed incident parameters are included, preserving factual accuracy and avoiding speculation. |
||||||
| Ransomware | Clearview Eye Centre id32624 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity represents a healthcare organization whose infrastructure was impacted by a ransomware incident associated with the threat actor interlock. This listing type identifies clearvieweyecentre.com as a ransomware victim within the threat-intelligence index, providing context on the attack vector and affected sector. The description maintains factual neutrality regarding the incident specifics while documenting its association with interlock for security analysts and defenders monitoring healthcare threats. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32624 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is identified in the threat-intelligence index as a ransomware victim linked to the interlock threat actor. The entity, based in Canada, represents a healthcare organization subject to cybersecurity risk assessment and incident cataloging. This listing type documents the association between the organization and the specified threat actor without disclosing unverified breach details, operational impacts, or unconfirmed claims. The entry supports cybersecurity professionals, compliance teams, and threat researchers in tracking ransomware exposure across critical healthcare infrastructure. |
||||||
| Ransomware | Clearview Eye Centre id32625 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector from Canada, providing clinical services and patient-related offerings. As documented in this threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. The listing reflects observed cyber threat activity targeting this organization within the healthcare domain, highlighting vulnerabilities relevant to medical infrastructure security. This entry serves to inform stakeholders of associated risk without disclosing unverified incident details or speculative claims about data exposure or operational impact. The classification underscores the importance of continuous monitoring for healthcare entities facing ransomware threats. |
||||||
| Ransomware | Clearview Eye Centre id32629 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is associated with Canada. The entity represents a healthcare organization whose infrastructure was identified within a ransomware incident context in the threat-intelligence index. This listing type categorizes clearvieweyecentre.com as a ransomware victim connected to the interlock threat actor profile. The description remains neutral regarding specific technical details, data impacts, or confirmed breach specifics, adhering to strict factual boundaries. Its inclusion reflects verified intelligence linking the organization to interlock within the ransomware victim classification. |
||||||
| Ransomware | Clearview Eye Centre id32629 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity provides medical services and digital infrastructure relevant to patient care and healthcare operations. It has been identified in our threat-intelligence index as a ransomware victim linked to the threat actor interlock. This listing reflects the entity's association with this specific cyber threat actor within our catalog. The description remains neutral regarding incident details, focusing solely on the verified classification and contextual sector information. |
||||||
| Ransomware | Clearview Eye Centre id32637 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada, providing services relevant to patient care and medical services. As a ransomware victim identified in this threat-intelligence index, the entity's inclusion reflects an incident linked to the threat actor interlock. The listing type categorizes this organization within ransomware impact data, supporting cyber-threat analysis and sector-focused risk assessment for healthcare infrastructure. This entry documents the association neutrally without disclosing unverified technical or operational details regarding the incident. |
||||||
| Ransomware | Clearview Eye Centre id32639 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is based in Canada. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. This designation reflects the inclusion of clearvieweyecentre.com within intelligence records documenting ransomware activity targeting healthcare organizations. The description remains neutral regarding specific incident details, as confirmed specifics such as data stolen, record counts, ransom amounts, or breach confirmation are not provided here. Its inclusion serves to inform security teams monitoring healthcare sector threats and the interlock threat actor's potential impact. |
||||||
| Ransomware | Clearview Eye Centre id32639 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is associated with Canada. The entity represents a healthcare organization whose infrastructure was impacted in a ransomware incident. This listing identifies clearvieweyecentre.com as a ransomware victim connected to the threat actor interlock within the threat-intelligence index. The description focuses on the entity's sector, geographic context, listing classification, and associated threat actor without disclosing unconfirmed technical or operational details. It neutrally records the relationship for catalog and intelligence purposes. |
||||||
| Ransomware | Clearview Eye Centre id32640 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is associated with the threat actor interlock in the ransomware victim index. The entity represents a healthcare organization whose security posture and digital infrastructure were impacted by the interlock threat group, highlighting vulnerabilities within medical service environments. This listing documents the relationship between clearvieweyecentre.com and interlock as a ransomware victim, providing context for threat analysts monitoring healthcare sector exposures. The entry serves as a reference point for understanding cyber risks facing Canadian healthcare entities targeted by organized threat actors. |
||||||
| Ransomware | Clearview Eye Centre id32643 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector based in Canada. The entity represents a healthcare organization whose infrastructure was impacted by a ransomware incident linked to the threat actor interlock. This listing type identifies clearvieweyecentre.com as a ransomware victim within the threat-intelligence index, reflecting its association with interlock's malicious activity. The description focuses on verified categorical data: sector, geographic origin, listing classification, and associated threat actor. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32643 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada, providing services aligned with patient care and medical services delivery. As documented in the threat-intelligence index, this entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects the cybersecurity event linking the organization to this actor without disclosing unverified technical details, breach specifics, or confirmed data impacts. This record serves to catalog the relationship between clearvieweyecentre.com and interlock within the ransomware victim context, supporting threat-aware analysis across healthcare sectors globally. |
||||||
| Ransomware | Clearview Eye Centre id32643 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada, providing services aligned with patient care and medical services. As a ransomware victim, this entity is cataloged in the threat-intelligence index with the associated threat actor identified as interlock. The listing type reflects the confirmed relationship between the entity and the threat actor, contributing to broader awareness of healthcare sector vulnerabilities and active threat patterns. This entry serves as a reference point for analysts monitoring ransomware incidents across critical infrastructure sectors in North America. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32643 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada, providing services relevant to patient care and medical operations. The entity is cataloged in this threat-intelligence index under the designation of ransomware victim, linked to the threat actor interlock. This listing reflects observed security event intelligence concerning the organization without disclosing unverified breach details. The record serves to inform stakeholders about cyber risks affecting healthcare infrastructure and associated attacker activity. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32643 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is headquartered in Canada. The entity serves medical services and patient-related functions typical of healthcare organizations. It has been catalogued in this threat-intelligence index under the classification of ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the security event context documented for the organization without disclosing unverified technical or operational details of the incident. The entry provides neutral context for threat analysts monitoring healthcare sector exposures. |
||||||
| Ransomware | Clearview Eye Centre id32643 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, with operations associated with Canada. The entity functions as a healthcare provider offering clinical services and patient-related services within its sector. It has been cataloged in this threat-intelligence index under the classification of ransomware victim, with the associated threat actor and source identified as interlock. This listing reflects the entity's status within our indexed records for cyber threat intelligence purposes. The description remains factual and neutral regarding the nature of the association. |
||||||
| Ransomware | Clearview Eye Centre id32644 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is situated in Canada. The entity functions as a healthcare provider offering patient-related services, consistent with its sector profile. It has been documented within the threat-intelligence index under the classification of ransomware victim, specifically linked to the threat actor interlock. This listing reflects the cybersecurity event classification without disclosing unverified technical or operational details. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32644 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity's domain name indicates its focus on eye care services, likely providing clinical or patient-related medical services within the healthcare industry. As documented in the threat-intelligence index, clearvieweyecentre.com has been classified as a ransomware victim linked to the interlock threat actor group. This classification reflects the cybersecurity event within which the organization was affected and highlights the vulnerability of healthcare entities to ransomware campaigns. The listing serves to inform stakeholders about this specific incident and associated threat actor within the broader cybersecurity landscape. |
||||||
| Ransomware | Clearview Eye Centre id32647 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity represents a healthcare organization whose digital infrastructure was impacted as part of a ransomware incident linked to the threat actor interlock. This listing type identifies clearvieweyecentre.com within our threat-intelligence catalog as a ransomware victim connected to interlock. The description focuses on the entity's sector, geographic context, and its association with the specified threat actor without disclosing unverified incident details. This entry supports threat analysts monitoring healthcare sector exposures and ransomware actor activity across North America. |
||||||
| Ransomware | Clearview Eye Centre id32647 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is associated with Canada. The entity is cataloged as a ransomware victim in the threat-intelligence index, with the associated threat actor or source identified as interlock. This listing reflects the organization's status within the intelligence dataset without disclosing unverified incident details such as data stolen, records compromised, ransom demands, or confirmed breach specifics. The description maintains neutrality and focuses on the entity's sector, geographic context, listing classification, and the attributed threat actor. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32648 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity represents a healthcare organization whose infrastructure was identified within the ransomware victim category of our threat-intelligence index. This listing reflects an association between clearvieweyecentre.com and the threat actor interlock, documented for catalog and analytical purposes. The description avoids speculation regarding breach details, data exposure, or operational impact, maintaining a neutral and factual posture consistent with threat-intelligence reporting standards. This entry serves to inform stakeholders about the entity's classification within the ransomware victim index and its connection to interlock. |
||||||
| Ransomware | Clearview Eye Centre id32648 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity is cataloged in this threat-intelligence index as a ransomware victim linked to the threat actor interlock. The listing reflects the observed relationship between this organization and the identified malicious activity within cybersecurity monitoring frameworks. No specific technical details regarding data exfiltration, ransom demands, or breach confirmation are provided here, adhering to strict neutrality and factual restraint. This entry serves to document the association for threat-aware stakeholders. |
||||||
| Ransomware | Clearview Eye Centre id32649 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada. The entity represents a healthcare organization whose infrastructure was impacted in an incident associated with the threat actor interlock. This listing type identifies clearvieweyecentre.com as a ransomware victim within the threat-intelligence index, reflecting its exposure to cyber threats targeting medical and healthcare services. The description remains neutral regarding specific technical or operational details of the incident. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32649 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is situated in Canada. The entity is documented in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. The catalog entry provides neutral, factual context regarding the organization's sector, geographic location, and the nature of its inclusion as a ransomware victim linked to interlock. No additional incident details, such as data stolen, record counts, ransom amounts, or breach confirmation specifics, are included per strict reporting guidelines. This description serves to inform threat-intelligence consumers of the entity's classification and associated risk profile. |
||||||
| Ransomware | Clearview Eye Centre id32654 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is located in Canada. The entity functions as a healthcare organization providing medical services and related patient care offerings. It is cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor interlock. This listing reflects the entity's inclusion in cybersecurity intelligence records documenting its status as an affected organization linked to interlock activity. The description remains factual and neutral regarding the incident specifics. |
||||||
| Ransomware | Clearview Eye Centre id32654 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector based in Canada, providing services relevant to patient care and medical operations. As a ransomware victim indexed by our threat-intelligence catalog, this entity is associated with threat actor interlock. The listing reflects the organization's status within the ransomware incident landscape, highlighting exposure to cyber threats targeting healthcare infrastructure. This record serves as a reference point for monitoring threat actor activity and sector-specific vulnerability patterns. No specific breach details, data loss metrics, or ransom terms are included per strict factual disclosure guidelines. |
||||||
| Ransomware | Clearview Eye Centre id32656 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector, based in Canada, providing services relevant to patient care and medical services. As a ransomware victim, this entity is documented in the threat-intelligence index with an association to the threat actor interlock. The listing type identifies the relationship between the organization and the identified malicious actor without disclosing unverified incident details. This entry serves to inform defenders and analysts about potential exposure within critical healthcare infrastructure. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32656 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is headquartered in Canada. The entity represents a healthcare organization whose infrastructure was affected by ransomware activity. This listing type identifies it as a ransomware victim within the threat-intelligence index, with the associated threat actor and source designated as interlock. The description focuses on verified contextual attributes: sector classification, geographic origin, and the confirmed ransomware association. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Clearview Eye Centre id32657 View details | Canada | Healthcare / Pharma | pending | ||
|
clearvieweyecentre.com operates within the healthcare and medicine sector and is identified as a ransomware victim within the threat-intelligence index. The entity is associated with threat actor interlock, reflecting its inclusion in cyber-threat intelligence records concerning ransomware activity. Its Canadian location and sector context underscore the heightened sensitivity of healthcare data within this classification. This listing serves as a neutral catalog entry documenting the relationship between the entity and the specified threat actor without disclosing unverified incident details. clearvieweyecentre.com was listed as a ransomware victim associated with interlock. |
||||||