Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 59 88.1%
- Pending 7 10.4%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 74 | Onion service | Up checked 3h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 73 | Onion service | Up checked 3h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 72 | Onion service | Up checked 3h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 3h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 71 | Onion service | Up checked 3h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 68 | Onion service | Up checked 3h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 69 | Onion service | Up checked 3h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 67 | Onion service | Up checked 3h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 66 | Onion service | Up checked 3h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 65 | Onion service | Up checked 3h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 63 | Onion service | Up checked 3h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 3h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 3h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 60 | Onion service | Up checked 3h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 58 | Onion service | Up checked 3h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 56 | Onion service | Up checked 3h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 57 | Onion service | Up checked 3h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 55 | Onion service | Up checked 3h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 54 | Onion service | Up checked 3h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 51 | Onion service | Up checked 3h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 43 | Onion service | Up checked 3h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 4h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 64 | Onion service | Down checked 3h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 59 | Onion service | Down checked 3h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 53 | Onion service | Down checked 3h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Down checked 3h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 48 | Onion service | Down checked 3h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 49 | Onion service | Down checked 3h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 3h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 46 | Onion service | Down checked 3h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 45 | Onion service | Down checked 3h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 44 | Onion service | Down checked 3h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 42 | Onion service | Down checked 3h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 3h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 39 | Onion service | Down checked 3h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 40 | Onion service | Down checked 3h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 38 | Onion service | Down checked 3h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 3h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 35 | Onion service | Down checked 3h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 36 | Onion service | Down checked 3h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 33 | Onion service | Down checked 3h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 34 | Onion service | Down checked 3h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 32 | Onion service | Down checked 3h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 3h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 29 | Onion service | Down checked 3h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 30 | Onion service | Down checked 3h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 28 | Onion service | Down checked 3h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 27 | Onion service | Down checked 3h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 26 | Onion service | Down checked 3h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 25 | Onion service | Down checked 3h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 24 | Onion service | Down checked 3h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 23 | Onion service | Down checked 3h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 22 | Onion service | Down checked 3h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 21 | Onion service | Down checked 3h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 20 | Onion service | Down checked 3h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 3h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 3h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 3h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 15 | Onion service | Down checked 3h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 16 | Onion service | Down checked 3h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 13 | Onion service | Down checked 3h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 3h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 11 | Onion service | Down checked 3h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 12 | Onion service | Down checked 4h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 10 | Onion service | Down checked 4h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 4h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 4h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 6 | Onion service | Down checked 4h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 7 | Onion service | Down checked 4h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 4h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 4 | Onion service | Down checked 4h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 4h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 5101–5200 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Goodwill id32747 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is located in the United States, providing business and professional services under its domain identity. The entity is cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor interlock. This listing reflects the organization's documented relationship with the identified cyber threat actor within the index's ransomware incident coverage. The description remains factual and neutral, focusing on the entity's classification, sector context, geographic origin, and the specific association with interlock as the linked threat actor. No additional incident details, such as data stolen, ransom demands, or breach confirmation specifics, are included per strict factual guidelines. |
||||||
| Ransomware | Goodwill id32748 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and service-oriented industries. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the intelligence assessment linking the organization to a ransomware incident connected to interlock activity. The description maintains neutrality regarding specific incident details, avoiding assumptions about data stolen, ransom demands, or confirmed breach specifics. Goodwill Inc. serves as a reference point within cybersecurity monitoring for understanding ransomware exposure patterns in the Services sector across the United States. |
||||||
| Ransomware | Goodwill id32752 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented offerings to clients and partners. It has been cataloged within this threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor interlock. This designation reflects its inclusion in cybersecurity intelligence records related to malicious activity targeting service-oriented organizations in the region. The entry serves to inform defenders and analysts about entities impacted by coordinated cyber threats. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Goodwill id32755 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States. The entity provides professional services consistent with its organizational profile, though specific operational details remain outside verified incident documentation. Within the threat-intelligence index, goodwillinc.org is formally categorized as a ransomware victim associated with the threat actor interlock. This listing reflects the entity's presence in cybersecurity incident records tied to this actor's activity. The description maintains neutrality regarding unconfirmed technical specifics while accurately representing the listing context. |
||||||
| Ransomware | Goodwill id32756 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based company operating within the Services sector, providing professional and commercial services to clients and partners. As documented in the threat-intelligence index, Goodwill Inc. is classified as a ransomware victim associated with the interlock threat actor. The entity's inclusion reflects its involvement in an incident attributed to this specific cyber threat group, highlighting risks within the Services industry. This listing serves as a reference point for cybersecurity professionals monitoring ransomware activity and related threat actor campaigns. The description remains factual and neutral, focusing solely on the indexed association without elaborating on unverified incident details. |
||||||
| Ransomware | Goodwill id32758 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization identified within the threat-intelligence index as a ransomware victim associated with the threat actor interlock. The entity operates within the professional and services industry, where ransomware incidents can disrupt operations and require coordinated security response. This listing reflects the indexed association between Goodwill Inc. and interlock without confirming specific breach details, data exfiltration, or operational impact. The catalog entry provides neutral context for researchers, defenders, and stakeholders monitoring threat actor activity and affected organizations across the Services sector in the United States. |
||||||
| Ransomware | Goodwill id32766 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented offerings. As documented in the threat-intelligence index, this entity is cataloged as a ransomware victim linked to the threat actor interlock. The listing type identifies the organization's involvement within a cybersecurity incident context, reflecting its status as a compromised entity in threat reporting records. This description maintains neutrality regarding specific incident details, focusing solely on the verified classification and associated threat actor attribution. The catalog entry serves to inform threat analysts and security professionals about this entity's documented relationship with interlock within ransomware activity tracking. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing organizational services and maintaining digital infrastructure relevant to enterprise operations. This entity is documented within the threat-intelligence index under the listing type ransomware victim, with its association specifically attributed to threat actor interlock. The record reflects the cybersecurity context in which the organization was identified in relation to this threat actor's activity. No specific incident details, such as data stolen, ransom demands, or breach confirmation metrics, are included per analytical protocol. The entry serves to catalog the relationship between the entity and the threat actor for threat-intelligence purposes. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing business and professional services. It is cataloged in the threat-intelligence index under the designation ransomware victim, associated with threat actor interlock. This listing reflects its inclusion within cybersecurity intelligence datasets monitoring active threat actors and affected entities. The description avoids speculative details regarding breach specifics, data exposure, or operational impact. It neutrally records the entity's classification and its connection to the identified threat actor within the index framework. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing organizational services aligned with its industry classification. As documented in the threat-intelligence index, this entity is categorized specifically as a ransomware victim associated with the threat actor interlock. The listing reflects the cybersecurity event classification without disclosing unverified technical details or incident specifics. This entry serves to catalog the affected organization's context within broader cyber threat intelligence frameworks for researchers and defenders. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based services sector organization operating within professional and commercial service offerings. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the intelligence assessment linking the organization to an active cyber threat actor profile, without disclosing unverified incident details. The entry provides context for security professionals monitoring service-sector entities targeted by coordinated cyber campaigns. Official disclosure specifics, such as breach confirmation or remediation steps, are not included per strict factual boundaries. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing professional and business-oriented offerings. As documented in the threat-intelligence index, this entity is categorized as a ransomware victim linked to the interlock threat actor. The listing reflects the organization's inclusion in the ransomware incident catalog associated with interlock's activity. This entry serves as a reference point within the broader cyber threat intelligence landscape for tracking affected entities. The description remains factual and neutral, focusing solely on the verified listing context without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based company operating within the Services sector, providing professional and commercial services. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, explicitly associated with the threat actor interlock. This designation reflects its inclusion in intelligence records documenting cybersecurity incidents and adversary activity. The description remains factual and neutral, focusing on the entity's operational context and its verified association with interlock within the ransomware victim classification. No additional incident details, such as breach specifics or disclosure timelines, are included per strict factual constraints. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based company operating within the Services sector, providing professional and commercial services. The entity is documented within this threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock identifies the cybersecurity threat profile linked to this entry. This catalog entry serves as a reference point for threat analysts tracking ransomware incidents across sectors and geographic regions. The description adheres to verified intelligence sources without extrapolating unconfirmed details regarding the attack itself. |
||||||
| Ransomware | Goodwill id32768 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing business and professional services. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, linked to the threat actor interlock. This designation reflects its inclusion in intelligence records documenting cybersecurity incidents and adversary activity. The description maintains neutrality regarding specific incident details, avoiding assumptions about data handling, breach confirmation, or operational impact. It serves as factual catalog information for researchers and defenders monitoring threat actor interlock activity across affected organizations. |
||||||
| Ransomware | Goodwill id32769 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services. As a ransomware victim listed in this threat-intelligence index, the entity is documented alongside threat actor interlock, which is associated with ransomware campaigns targeting organizations. This entry provides neutral, factual context regarding the company's sector, geographic location, and its classification within the ransomware victim category for cybersecurity monitoring and intelligence analysis. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are included per strict analytical guidelines. The listing serves to inform stakeholders of the entity's presence in threat intelligence records tied to interlock's activity. |
||||||
| Ransomware | Goodwill id32769 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States. The entity provides business and professional services, though specific operational details are not disclosed in this threat-intelligence listing. This listing identifies goodwillinc.org as a ransomware victim linked to the threat actor interlock. The designation reflects inclusion within a cyber threat-intelligence index documenting adversary-associated victims across sectors and geographies. No additional incident specifics, such as stolen data, ransom demands, or confirmed breach details, are provided here to maintain factual neutrality. |
||||||
| Ransomware | Goodwill id32769 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is located in the United States, delivering business services aligned with its organizational profile. As cataloged in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. This listing reflects the observed relationship between the entity and the identified threat actor without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The entry serves to document the entity's status within the ransomware victim category for analytical and defensive reference. Neutral documentation ensures clarity for security professionals monitoring actor-linked incidents across sectors. |
||||||
| Ransomware | Goodwill id32769 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States. The entity provides business services aligned with its organizational sector and geographic presence. It has been documented within this threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This designation reflects its inclusion in records correlating the entity with this specific threat actor profile for cybersecurity awareness and defensive intelligence purposes. The description remains neutral regarding incident details, focusing solely on the entity's classification and contextual association. |
||||||
| Ransomware | Goodwill id32769 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is located in the United States, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor interlock. This designation reflects the inclusion of the organization within cybersecurity intelligence records documenting adversary activity and impacted entities. The description remains neutral regarding incident details, focusing solely on the verified listing context and associated threat actor attribution. Additional specifics such as breach confirmation, data exposure, or operational impact are intentionally excluded per strict factual constraints. |
||||||
| Ransomware | Goodwill id32769 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based services sector organization operating within professional and service-oriented industries. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as interlock. This designation reflects inclusion within an analytical framework tracking cybersecurity incidents and adversary activity relevant to affected organizations. No specific incident details such as data stolen, records compromised, ransom demands, or confirmed breach evidence are provided here, in accordance with strict factual neutrality. The entry documents the association neutrally and serves as a reference point for threat researchers and security professionals monitoring service-sector exposure. |
||||||
| Ransomware | Goodwill id32773 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based company operating within the Services sector, providing professional and business-oriented offerings. This entity has been cataloged in the threat-intelligence index under the listing type ransomware victim, linked to threat actor interlock. The record reflects the organization's documented association with this specific cyber threat actor within the index framework. No further incident details, such as data exfiltration specifics or ransom terms, are included to maintain factual neutrality and avoid speculation beyond verified index classifications. This entry serves as a reference point for threat actors, defenders, and analysts monitoring ransomware activity within the Services sector. |
||||||
| Ransomware | Goodwill id32775 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based services sector organization. The entity operates within the professional and service industries, providing offerings aligned with its sector classification. According to the threat-intelligence index, goodwillinc.org is cataloged as a ransomware victim linked to the interlock threat actor. This listing reflects the cybersecurity context in which the entity was identified within the index. No additional incident specifics, such as data stolen, ransom demands, or confirmed breach details, are provided here to maintain factual accuracy and neutrality. |
||||||
| Ransomware | Goodwill id32778 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing business and operational services. The entity is formally listed within this threat-intelligence index under the designation ransomware victim. Its inclusion reflects threat-intelligence analysis correlating the organization with the interlock threat actor profile. This catalog entry supports security teams in monitoring adversary activity and assessing potential exposure within relevant service sectors. The listing remains a factual reference point without elaboration on unverified incident details. |
||||||
| Ransomware | Goodwill id32781 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This entry provides neutral, factual context regarding the organization's sector, geographic location, and its documented relationship to this specific threat actor within ransomware incident tracking. The description adheres to encyclopedic standards, avoiding speculation about breach details while fulfilling the catalog's analytical purpose. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Goodwill id32782 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing business and professional services. The entity has been cataloged in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects its inclusion within records documenting cybersecurity incidents and adversary activity targeting organizations in its sector and geographic region. The description maintains factual neutrality regarding the incident details while accurately conveying the entity's classification and its relationship to the identified threat actor. No specific breach metrics, data details, or financial impacts are included per strict factual guidelines. |
||||||
| Ransomware | Goodwill id32782 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and commercial service offerings. The entity is cataloged within a threat-intelligence index under the designation of ransomware victim. Its association with the threat actor interlock indicates a cybersecurity incident where interlock was identified as the responsible actor or source in the intelligence record. This listing reflects the indexed relationship without disclosing unverified technical details regarding the attack vector, data exposure, or remediation actions. The record serves threat analysts and defenders as part of a structured ransomware victim index for monitoring and risk assessment. |
||||||
| Ransomware | Goodwill id32785 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is located in the United States. The entity provides business services aligned with its sector classification, though specific operational details remain limited to verified threat-intelligence records. This listing identifies goodwillinc.org as a ransomware victim linked to the threat actor interlock, reflecting the cybersecurity context in which the entity appears within the index. The description adheres to neutral, authoritative standards for cataloging affected organizations without speculating on unconfirmed breach details. This entry serves threat analysts and defenders seeking structured context on ransomware-related entities and their associated actors. |
||||||
| Ransomware | Goodwill id32785 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing specialized business and professional services. The entity has been identified within a threat-intelligence index under the listing type ransomware victim. This classification associates the organization with the threat actor interlock, reflecting cybersecurity intelligence observations regarding its exposure profile. The description maintains factual neutrality regarding the nature of the incident without disclosing unconfirmed specifics. This catalog entry serves to document the relationship between the entity, its sector and geographic location, and the associated threat actor within the ransomware victim index. |
||||||
| Ransomware | Goodwill id32785 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing specialized business and operational services. The entity is documented within this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an association with the threat actor interlock, a cybersecurity identifier noted in threat intelligence repositories. This entry provides neutral context regarding the entity's sector, geographic location, and its classification within cybersecurity threat reporting frameworks. No specific incident details, such as data stolen or ransom demands, are included per strict factual guidelines. |
||||||
| Ransomware | Goodwill id32786 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services. The entity is documented in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. This entry reflects the cybersecurity context in which the organization was assessed and recorded by the index. No specific incident details, such as data stolen, ransom demands, or breach confirmation, are included per strict factual guidelines. The listing neutrally records that goodwillinc.org was identified as a ransomware victim associated with interlock. |
||||||
| Ransomware | Goodwill id32789 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing professional services aligned with its organizational profile. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This designation reflects inclusion within a structured repository of entities impacted by cyber threats, intended to support threat-aware security assessment and intelligence workflows. No specific incident details, such as data exfiltration scope or ransom terms, are asserted here; the entry focuses on the entity's classification and its documented association with interlock. The description adheres to a neutral, encyclopedic tone suitable for premium catalog use. |
||||||
| Ransomware | Goodwill id32791 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing business services aligned with its organizational profile. This entity is formally listed within the threat-intelligence index under the designation ransomware victim, associated with the threat actor interlock. The listing reflects cybersecurity intelligence compiled regarding this organization's exposure profile and its connection to identified malicious activity. The description remains factual and neutral, focusing on the entity's classification, sector context, geographic origin, and the specific threat actor attribution without disclosing unverified incident details or speculative claims. This entry supports threat-monitoring workflows for security teams assessing service-sector risk exposure linked to interlock activity. |
||||||
| Ransomware | Goodwill id32793 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States. The entity provides professional and service-oriented offerings, though specific operational details remain outside the scope of this threat-intelligence catalog entry. According to the threat-intelligence index, this organization was formally listed as a ransomware victim associated with the threat actor interlock. This designation reflects the index's classification of the entity within the ransomware incident landscape linked to interlock. The entry serves as a reference point for cybersecurity professionals monitoring threat actor activity and victim profiles. |
||||||
| Ransomware | Goodwill id32794 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing business and professional services. The entity is documented within this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects its association with the threat actor interlock in the cybersecurity threat landscape. This catalog entry serves to inform stakeholders about organizational exposure and relevant cyber risk indicators without disclosing unverified incident details. The description adheres to neutral, authoritative standards for threat intelligence documentation. |
||||||
| Ransomware | Goodwill id32794 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented offerings. It has been cataloged in this threat-intelligence index as a ransomware victim associated with the threat actor interlock. The listing reflects the entity's status within the dataset and does not specify incident details, data exposure, or recovery outcomes. This entry serves to document the relationship between the entity, its sector and geographic location, and the identified threat actor for analytical and informational purposes. |
||||||
| Ransomware | Goodwill id32794 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional service offerings. The entity appears in this threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This designation reflects inclusion within an analytical framework tracking adversary-targeted entities and incident correlations. The description remains neutral regarding specific incident details, avoiding assumptions about data handling, breach confirmation, or operational impact. Goodwill Inc. serves as a catalog reference point for monitoring threat actor activity within the Services sector across the United States. |
||||||
| Ransomware | Goodwill id32794 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with threat actor interlock. This designation reflects its inclusion in threat-intelligence records linking the organization to this actor's activity. The description remains factual and neutral, focusing on the entity's sector, location, and its documented association within the ransomware victim classification. No additional incident details, such as breach specifics or disclosure timelines, are included per strict factual constraints. |
||||||
| Ransomware | Goodwill id32794 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing business and professional services. It is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The description reflects the entity's classification without disclosing unverified incident details, operational specifics, or confirmed breach elements. This entry supports threat-aware cataloging and contextual intelligence for security professionals monitoring service-sector organizations against identified threat actors. |
||||||
| Ransomware | Goodwill id32794 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization identified within the threat-intelligence index under the ransomware victim listing type. The entity operates within professional and service-oriented markets, with public information limited to its organizational profile and sector classification. This entry documents the association between Goodwill Inc. and the threat actor interlock within the ransomware victim context, without disclosing unverified technical incident details. The catalog description maintains a neutral, authoritative stance consistent with threat-intelligence indexing standards. It records the entity name, geographic location, sector classification, listing classification, and attributed threat actor without extrapolating beyond confirmed index data. |
||||||
| Ransomware | Goodwill id32795 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an incident linked to the threat actor interlock, which has been documented in cyber threat intelligence records. This description maintains factual neutrality regarding the nature and scope of the event, avoiding speculation on data handling, operational impact, or resolution details. The listing serves to inform security professionals and stakeholders about this specific entity's association with the identified threat actor within the ransomware incident landscape. |
||||||
| Ransomware | Goodwill id32795 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and service-oriented industries. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an assessed association with the threat actor interlock, a group operating within cyber threat landscapes targeting service-sector entities. This description provides neutral context regarding the organization's sector, geographic location, and classification without asserting unverified incident details such as data exfiltration scope, ransom demands, or confirmed breach specifics. The listing serves to index the entity's relationship to the identified threat actor for security and intelligence purposes. |
||||||
| Ransomware | Goodwill id32795 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing business and professional services under its domain. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, explicitly linked to the threat actor interlock. This designation reflects its inclusion in threat-related records documenting cybersecurity incidents affecting organizations. The description maintains neutrality regarding specific incident details, as confirmed facts remain limited to the listing association. This entry supports threat-intelligence analysis for monitoring ransomware activity across sectors and geographies. |
||||||
| Ransomware | Goodwill id32795 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based company operating within the Services sector, providing professional and commercial services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association is specifically tied to the threat actor interlock, indicating a cybersecurity incident context linked to this actor's activity. This description focuses on the entity's profile and its recognized classification within the intelligence dataset without elaborating on unconfirmed technical or operational details of the incident. The listing reflects verified intelligence linking the organization to the specified threat actor. |
||||||
| Ransomware | Goodwill id32795 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented offerings. The entity has been identified within our threat-intelligence index under the listing type ransomware victim, associated with threat actor interlock. This classification reflects the security context in which the organization was documented by intelligence sources. The description remains neutral and avoids speculation regarding specific attack vectors, data handling, or incident details. It serves as a factual reference point for threat analysts tracking ransomware incidents across sectors and geographies. The inclusion underscores the importance of monitoring service-sector entities for emerging cyber threats. |
||||||
| Ransomware | Goodwill id32795 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and service industries. The entity is cataloged as a ransomware victim within a threat-intelligence index, specifically associated with the threat actor interlock. This listing reflects the cybersecurity event classification and intelligence linkage rather than confirmed forensic details of the attack. The inclusion underscores ongoing monitoring of service-sector entities targeted by coordinated cyber threats. Goodwill Inc. remains documented for threat-researcher and defense-stakeholder reference within this intelligence framework. |
||||||
| Ransomware | Goodwill id32798 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services as indicated by its domain and public profile. As cataloged in the threat-intelligence index, the entity is classified as a ransomware victim linked to the threat actor interlock. This listing reflects the organization's documented association with this specific cyber threat actor within the index's ransomware victim category. The entry serves as a reference point for monitoring security implications affecting this entity. No further incident details, such as breach confirmation or specific attack characteristics, are provided in this catalog description. |
||||||
| Ransomware | Goodwill id32805 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business services and operational support to clients. It has been formally listed within this threat-intelligence index under the designation ransomware victim, associated with the threat actor interlock. The entry documents the observed security event linking the entity to this specific adversary group without disclosing unverified technical details or incident specifics. This catalog entry supports threat researchers and defenders in tracking adversary-victim relationships across sectors and geographies. |
||||||
| Ransomware | Goodwill id32805 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization identified within the threat-intelligence index as a ransomware victim. The entity operates within professional services and its inclusion reflects cybersecurity risk assessment and incident correlation activities. As part of this listing, Goodwill Inc. is associated with the threat actor interlock, contributing contextual data for analysts tracking ransomware campaigns and affected entities. This description maintains factual neutrality regarding the incident specifics while documenting the entity's sector, geographic location, listing classification, and threat attribution source. |
||||||
| Ransomware | Goodwill id32808 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States. The entity provides professional services and maintains an online presence at https:goodwillinc.org. According to the threat-intelligence index, goodwillinc.org is cataloged as a ransomware victim associated with the threat actor interlock. This listing type indicates the entity was impacted by ransomware activity connected to interlock, without disclosing specific technical incident details. The record serves to inform defenders and analysts about the affected organization, its sector, geographic context, and the associated threat actor profile. |
||||||
| Ransomware | Goodwill id32810 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing organizational and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the inclusion of the organization within cybersecurity threat records documenting potential or confirmed ransomware-related activity. The description remains factual and neutral, focusing on the entity's sector, geographic location, and its classification within the index without disclosing unverified incident details. Authorities and security researchers continue monitoring such entries to enhance collective threat visibility and response capabilities. |
||||||
| Ransomware | Goodwill id32815 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its association is specifically tied to the threat actor interlock, which has been documented in cyber threat intelligence records. This entry reflects the indexed relationship without disclosing unverified incident details such as data stolen, ransom demands, or confirmed breach specifics. The listing serves to inform stakeholders of the entity's exposure profile within the identified threat actor's activity. |
||||||
| Ransomware | Goodwill id32816 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services to clients and partners. As part of our threat-intelligence catalog, this entity is formally listed as a ransomware victim associated with the threat actor interlock. The listing type reflects the observed relationship between the organization and the identified threat actor within our indexed threat events. This entry contributes contextual intelligence for security professionals monitoring ransomware activity across service-oriented entities in the United States. The description remains neutral and factual, focusing solely on the entity's classification and association without elaborating on unverified incident details. |
||||||
| Ransomware | Goodwill id32817 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing specialized business and operational services. Within the threat-intelligence index, this entity is formally listed as a ransomware victim associated with the threat actor interlock. The listing type identifies the relationship between the organization and the cyber threat actor without disclosing unverified incident details. This entry supports defenders in tracking ransomware activity across sectors and geographic regions, contributing to broader situational awareness of evolving cyber threats targeting service-oriented organizations. |
||||||
| Ransomware | Goodwill id32818 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States. The entity provides professional and business-oriented services, aligning with the sector classification noted in threat-intelligence records. As documented in the threat-intelligence index, goodwillinc.org is categorized as a ransomware victim associated with the threat actor interlock. This listing serves to inform security professionals and stakeholders about potential exposure within this organization profile. The description remains neutral and factual, reflecting the index's purpose in mapping cyber incidents to affected entities and associated actors. |
||||||
| Ransomware | Goodwill id32818 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services to clients. This entity is documented within a threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. The entry reflects cybersecurity intelligence compiled to identify compromised organizations and contextualize attack patterns within specific sectors and geographic regions. The description remains neutral, focusing on the entity's classification and its verified association with interlock without disclosing unconfirmed incident details. |
||||||
| Ransomware | Goodwill id32819 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as interlock. This designation reflects its inclusion within cybersecurity threat datasets focused on identifying and tracking ransomware-related entities and their attacker profiles. The description remains factual and neutral, adhering to the index's standards for threat-related entity documentation. |
||||||
| Ransomware | Goodwill id32819 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and operational services to clients and partners. The entity is documented within this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. This entry contributes contextual intelligence regarding organizational exposure patterns and adversary targeting within the Services industry landscape. The catalog description maintains neutrality regarding specific incident details, focusing on verified listing metadata and sector classification for analytical use. |
||||||
| Ransomware | Goodwill id32819 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing business and professional services. It has been documented within a threat-intelligence index under the listing type ransomware victim, linked to the threat actor interlock. The entry reflects the entity's classification based on observed cyber incident intelligence and associated malicious activity attribution. No specific technical details regarding the attack, data handling, or recovery measures are included here, adhering to strict factual boundaries. This neutral description serves catalog and analytical purposes for threat-intelligence professionals. |
||||||
| Ransomware | Goodwill id32819 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States. The entity provides professional services and is cataloged in this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an association with the threat actor interlock, which has been documented in cyber threat intelligence databases. This description focuses on the entity's profile and the nature of its listing without disclosing unverified incident details. The entry serves security teams monitoring ransomware activity and threat actor repercussions across service-oriented organizations. |
||||||
| Ransomware | Goodwill id32819 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This entry documents the relationship between the organization and the threat actor without disclosing unverified incident details, such as data stolen, ransom demands, or confirmed breach specifics. The profile serves to support threat-intelligence research and contextual awareness regarding ransomware activity targeting Services sector entities in the United States. Official disclosure details for this incident are not confirmed in available public records. |
||||||
| Ransomware | Goodwill id32820 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and service-oriented offerings. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. The description reflects the indexed association without confirming specific incident details such as data stolen, ransom demands, or breach validation. This entry supports threat-intelligence analysis by documenting the victim profile alongside the attributed actor context for cybersecurity researchers and defenders. |
||||||
| Ransomware | Goodwill id32820 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services to clients. The entity is documented within the threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an assessed association with the threat actor interlock, which has been identified as a relevant source in cybersecurity threat analysis. This catalog entry serves to inform stakeholders about the entity's status and the cybersecurity context surrounding its classification. The description remains factual and neutral, focusing on the verified listing parameters without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | Goodwill id32820 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing business and professional services. The entity has been cataloged within this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an assessed cybersecurity incident linked to the threat actor interlock. The description focuses on the entity's operational context, geographic origin, and sector classification without disclosing unverified incident details. This entry supports threat-intelligence monitoring and contextual analysis for security professionals tracking ransomware-related entities and associated actors. |
||||||
| Ransomware | Goodwill id32820 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing professional and business-oriented offerings. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor interlock. This designation reflects its inclusion in threat-related records linking the organization to this actor's activities. The description remains factual and neutral, focusing on the entity's classification and contextual association without elaborating on unverified incident details. This entry supports comprehensive monitoring and analysis within cybersecurity intelligence frameworks. |
||||||
| Ransomware | Goodwill id32820 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing professional and business-oriented offerings. The organization is documented in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This classification reflects its inclusion in records tracking cyber incidents involving this specific adversary group. The description remains factual and neutral, focusing on the entity's sector, geographic context, and verified association without elaborating on unconfirmed breach details or incident specifics. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Goodwill id32821 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based company operating within the Services sector, providing professional and commercial services. The entity is cataloged as a ransomware victim within a threat-intelligence index, with the associated threat actor identified as interlock. This listing reflects the organization's status in relation to a cybersecurity incident attributed to interlock, without disclosing confirmed breach specifics. The description maintains neutrality regarding operational impact while documenting the entity's sector, geographic location, and threat association for analytical reference. |
||||||
| Ransomware | Goodwill id32821 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and business services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This designation reflects inclusion within an index tracking cybersecurity incidents and adversary-linked entities without asserting unverified breach details. The description remains neutral regarding specific compromise elements, data exposure, or operational impact. Goodwill Inc. serves as a reference point for monitoring threat actor interlock activity within the Services sector across the United States. |
||||||
| Ransomware | Goodwill id32822 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented services. The entity has been cataloged within this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects its documented association with the threat actor interlock in the cybersecurity threat landscape. This description maintains neutrality regarding specific incident details, focusing on the entity's profile, sector, geographic location, and verified listing context as reported by the intelligence source. |
||||||
| Ransomware | Goodwill id32822 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and service-oriented industries. The entity is cataloged within the threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as interlock. This designation reflects the intelligence assessment linking Goodwill Inc. to an incident attributed to interlock without disclosing unverified technical or operational details. The entry provides neutral context regarding the organization's sector, geographic location, and its classification within the ransomware victim index associated with the specified threat actor. All information remains factual and avoids speculation regarding breach specifics, data handling, or recovery status. |
||||||
| Ransomware | Goodwill id32823 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional service offerings. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the intelligence assessment linking the organization to this specific cyber threat actor profile without disclosing unverified incident details. The entry provides neutral context for security professionals monitoring ransomware activity across the Services sector in the United States. Official incident specifics remain outside the scope of this catalog description. |
||||||
| Ransomware | Goodwill id32824 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is located in the United States. The entity provides professional services aligned with its organizational sector and geographic presence. This listing type identifies goodwillinc.org as a ransomware victim within the threat-intelligence index. The association links the entity to the threat actor interlock, reflecting the cybersecurity event classification documented in the index. The description remains neutral and avoids speculative details regarding attack mechanisms, data exposure, or financial impact. |
||||||
| Ransomware | Goodwill id32827 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services. The entity is documented within this threat-intelligence index under the listing type ransomware victim. Its association is specifically tied to the threat actor interlock, which is recognized in cyber threat reporting. This entry serves to catalog the organization's exposure within the context of active cyber threats targeting the Services industry in the United States. The listing reflects verified intelligence linking the entity to this threat actor profile. |
||||||
| Ransomware | Goodwill id32828 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing organizational and professional services. The entity is documented within the threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock indicates a cybersecurity incident classification tied to this specific adversary group. This catalog entry serves to inform analysts and defenders about the entity's exposure context and linked threat profile without disclosing unverified technical or operational details. The description remains factual and neutral, reflecting the indexed classification only. |
||||||
| Ransomware | Goodwill id32828 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services. The entity is documented in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This classification reflects its inclusion in intelligence records concerning cybersecurity incidents and adversary activity. The description remains factual and neutral, focusing on the entity's sector, geographic context, and verified listing association without extrapolating beyond confirmed intelligence. |
||||||
| Ransomware | Goodwill id32828 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented offerings. The entity has been identified within this threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock indicates a cybersecurity incident classified in this context. This entry documents the entity's presence in the ransomware victim category alongside the specified threat actor for analytical and cataloging purposes. No further incident details, such as data stolen or ransom demands, are included to maintain factual neutrality. |
||||||
| Ransomware | Goodwill id32828 View details | United States | Services | — | ||
|
goodwillinc.org is a services-sector organization based in the United States, operating within professional and service-oriented markets. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with threat actor interlock. This designation reflects its inclusion within the indexed records of cybersecurity incidents involving this actor, providing context for threat researchers and defenders analyzing attack patterns in the Services sector. The description remains factual and neutral, focusing solely on the entity's classification and its documented association without elaborating on unverified incident details. |
||||||
| Ransomware | Goodwill id32828 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based Services sector organization operating within the professional services domain, providing business and operational services to clients. The entity has been cataloged in this threat-intelligence index under the designation ransomware victim, linked to the threat actor interlock. This listing reflects the association between the organization and the identified threat actor within cybersecurity intelligence records. No specific incident details, breach confirmations, data loss metrics, or ransom terms are included per strict factual constraints. The entry serves to document this verified relationship for threat monitoring and security awareness purposes. |
||||||
| Ransomware | Goodwill id32830 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing professional and business-oriented offerings. The entity is cataloged as a ransomware victim within this threat-intelligence index, with the associated threat actor and source identified as interlock. This listing reflects the organization's status in relation to a cyber incident linked to the interlock threat actor profile. No specific technical details such as stolen data, ransom demands, or confirmed breach metrics are included to maintain factual neutrality. The record serves as an authoritative reference point for threat analysts monitoring ransomware activity in the Services sector across the US. |
||||||
| Ransomware | Goodwill id32830 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This classification reflects the cybersecurity context in which the organization was recorded, without disclosing unverified incident details such as data stolen, ransom demands, or breach confirmation. The entry serves to inform defenders and analysts about this specific entity's relationship to a documented ransomware threat actor within the indexed dataset. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and business services. Its inclusion in the threat-intelligence index reflects its classification as a ransomware victim associated with the interlock threat actor. This listing documents the entity's exposure within cybersecurity threat databases without disclosing unverified incident specifics. The record serves catalog and analytical purposes for monitoring threat actor activity and victim impact across sectors. Neutral documentation supports threat intelligence workflows and sector-specific risk assessment. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
goodwillinc.org is a company operating within the Services sector based in the United States. The entity provides professional and service-oriented offerings, aligning with the sector classification noted in the threat intelligence record. It is formally cataloged as a ransomware victim linked to the threat actor interlock. This listing reflects its inclusion within the ransomware incident index connected to interlock's activity. The description remains neutral and factual, focusing on the entity's profile and its association without speculating on unconfirmed details. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based services sector organization operating within the professional services domain. The entity appears in the threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects inclusion within an intelligence catalog documenting cybersecurity incidents and adversary relationships without confirming specific breach details. The description remains neutral and factual, limited to the entity’s sector, geographic context, listing classification, and attributed threat actor. It does not speculate on data impacts, ransom terms, attacker methodology, or verified incident chronology. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional and service-oriented markets. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. This designation reflects the intelligence assessment linking the organization to this specific cyber threat actor within the index database. The description remains factual and neutral, focusing on the entity's profile, sector, geographic origin, and the indexed relationship without speculating on incident details. It serves as a reference point for threat analysts monitoring ransomware activity and associated actor footprints in the Services sector. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services to clients and partners. The entity is cataloged within this threat-intelligence index with the listing type designated as ransomware victim. This classification reflects its documented association with the threat actor interlock in the intelligence dataset. The description remains neutral and factual, focusing on the entity's operational context and its inclusion in the ransomware victim category linked to interlock. No specific incident details, such as data stolen or ransom demands, are included per strict analytical guidelines. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and business-oriented offerings. It has been documented within this threat-intelligence index under the listing type ransomware victim. The entity is associated with threat actor interlock, indicating a cybersecurity incident context linked to this specific adversary group. This entry serves as a factual reference point for analysts tracking ransomware activity and associated sources across the Services sector in the United States. No additional incident specifics, such as data stolen, ransom demands, or confirmed breach details, are included per strict factual constraints. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, associated with the threat actor interlock. No specific incident details, such as stolen data categories, record counts, ransom amounts, or confirmed breach evidence, are included to maintain factual neutrality. This entry serves as a structured reference point for threat-aware organizations monitoring ransomware activity across the Services sector in the US. The designation reflects the entity's documented association with interlock within the index's ransomware victim classification. |
||||||
| Ransomware | Goodwill id32831 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional service offerings. It has been cataloged within the threat-intelligence index under the designation ransomware victim, with an associated threat actor identified as interlock. The listing reflects the entity's inclusion in intelligence records documenting cybersecurity incidents and adversary activity relevant to its operational profile. This entry provides neutral context regarding the organization's relationship to the specified threat actor without disclosing unverified incident details. The classification supports threat monitoring and situational awareness for stakeholders analyzing ransomware activity across the Services sector in the United States. |
||||||
| Ransomware | Goodwill id32832 View details | United States | Services | — | ||
|
https://goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services. It has been documented within a threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor interlock. This classification reflects the entity's inclusion in cybersecurity records detailing incidents involving ransomware activity linked to interlock. The description maintains neutrality regarding the nature or specifics of the incident while accurately conveying its categorization within the intelligence catalog. |
||||||
| Ransomware | Goodwill id32837 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization identified within this threat-intelligence index as a ransomware victim. The entity operates in the professional and services industries, with its public identity and sector context documented for cybersecurity monitoring and intelligence cataloging. This listing associates Goodwill Inc. with the threat actor interlock, reflecting the entity's classification within the ransomware victim index based on available intelligence. The description remains factual and neutral, focusing on the entity's sector, location, listing type, and associated threat actor without adding unverified incident details. Such entries support threat-resilience workflows by indexing affected organizations and their linked adversary activity. |
||||||
| Ransomware | Goodwill id32850 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based company operating within the Services sector, providing professional and business-oriented offerings. The entity has been cataloged in the threat-intelligence index under its designation as a ransomware victim. This listing is specifically linked to threat actor interlock, which is documented as the associated source or adversary group in the index records. The description focuses on the entity's operational profile and its verified association within the ransomware victim classification, without elaborating on unconfirmed incident details. This entry supports threat analysts in mapping victim profiles, sector exposure, geographic context, and adversary linkages for comprehensive cybersecurity intelligence. |
||||||
| Ransomware | Goodwill id32850 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector based in the United States, providing business and professional services to clients. The entity is documented within this threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock identifies a cybersecurity incident classification relevant to monitoring and defense efforts. This description reflects the indexed classification only and does not confirm specific breach details, data handling, or operational impact beyond the listed relationship. The profile supports contextual analysis of affected organizations within the Services sector across the US. |
||||||
| Ransomware | Goodwill id32851 View details | United States | Services | — | ||
|
goodwillinc.org is a United States-based organization operating within the Services sector, providing professional and commercial services. The entity is documented within a threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock indicates a cybersecurity incident context relevant to threat tracking and defensive awareness. This description maintains factual neutrality regarding the nature of the event while preserving essential identifiers: entity, sector, geographic location, listing classification, and linked actor. No specific technical, operational, or financial details of the incident are asserted. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based services sector organization operating within professional services and related commercial offerings. Within the threat-intelligence index catalog, the entity is classified as a ransomware victim associated with the threat actor Interlock. This listing reflects the observed relationship between Goodwill Inc. and Interlock in threat-intelligence records, without confirming specific technical details, data exposure, or recovery outcomes. The entry provides neutral context for researchers, defenders, and stakeholders monitoring ransomware activity across the Services sector in the United States. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States. The entity provides professional and service-oriented offerings, though specific service details are not disclosed in this catalog context. According to the threat-intelligence index, goodwillinc.org has been classified as a ransomware victim linked to the threat actor interlock. This listing reflects the organization's association with this cybersecurity incident within the indexed data. The description remains factual and neutral, focusing solely on the entity's classification and contextual background without elaborating on unverified incident details. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
Goodwill Inc. is a United States-based organization operating within the Services sector, providing professional and commercial services to clients and partners. As documented in the threat-intelligence index, Goodwill Inc. is categorized as a ransomware victim entity. The association with the interlock threat actor contextualizes the incident within the broader cybersecurity landscape. This listing serves to inform defenders and analysts about the entity's exposure profile and the specific threat actor connected to the event. The catalog entry maintains a neutral, factual perspective on the relationship without disclosing unverified technical or operational details of the incident. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business and professional services under its organizational domain. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim. Its inclusion reflects an association with the threat actor interlock, which has been documented in cybersecurity intelligence records related to ransomware activity. This description maintains factual neutrality regarding the nature of the incident without speculating on unverified details such as data exposure scope or operational impact. The listing serves to inform stakeholders about the entity's presence within the ransomware victim index associated with interlock. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is based in the United States, providing business services aligned with its organizational profile. As documented in this threat-intelligence index, the entity is classified as a ransomware victim associated with the threat actor interlock. The listing reflects the cybersecurity community's aggregated assessment of this incident without disclosing unverified technical details such as data stolen, ransom demands, or precise breach timelines. This entry serves to catalog the relationship between the entity, its sector and geographic context, and the identified threat actor for monitoring and defensive analysis purposes. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing business and operational services to clients. As cataloged in the threat-intelligence index, the entity is classified as a ransomware victim linked to the interlock threat actor. This listing reflects the security event context associated with the organization without disclosing unverified incident details. The record supports threat-intelligence analysis for tracking ransomware activity across sectors and geographic regions. Official disclosure specifics remain outside the scope of this neutral catalog description. |
||||||
| Ransomware | Goodwill id32853 View details | United States | Services | — | ||
|
goodwillinc.org operates within the Services sector and is headquartered in the United States, providing business and operational services. The entity is documented within this threat-intelligence index under the listing type ransomware victim. The association connects the organization to the threat actor interlock, indicating a cybersecurity incident classification. This catalog entry synthesizes verified intelligence sources without disclosing unconfirmed breach details, attack vectors, or internal findings. The record serves to inform stakeholders on threat exposure and entity-level risk context. |
||||||