Ransomware Group intelligence
Interlock
ActiveTrack Interlock with 24841 published victims and 74 known leak locations in a single intelligence view.
Overview
Interlock is tracked by Dark Eye as a ransomware group with 24841 published victims.
United States is currently the most targeted country in this dataset.
74 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 59 88.1%
- Pending 7 10.4%
- Deleted 1 1.5%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (74)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 74 | Onion service | Up checked 5h ago | 4xhhhpooioaz4cre2lmxowbxqvczotik4qqk7nh4wgtxripqj4urdzqd.onion |
| Leak location 73 | Onion service | Up checked 5h ago | dcwatuq6kzwj5i2sx7f2cx5hud2ryo3cnm6n6j2r6am57qskfqvdpeqd.onion |
| Leak location 72 | Onion service | Up checked 5h ago | gpotnbhakwdnrcojjnr4msl3sl64a4gv2n4yizvmbsceiazpqq23s5yd.onion |
| Leak location 70 | Onion service | Up checked 5h ago | mfrgymzi6w34lmxojf7hgteoskqo6j5zelunqh3dwxcmz7bbacqzwcad.onion |
| Leak location 71 | Onion service | Up checked 5h ago | 2nv4huuzjbsqncvuepdmwneo6l4ocgtxzcgdau7obcvaqebkssfpz2ad.onion |
| Leak location 68 | Onion service | Up checked 5h ago | xkqqpb46vk7appesxtmotbrweogkux6gheyonqpk2dxbuqetgt3cvrad.onion |
| Leak location 69 | Onion service | Up checked 5h ago | sq5gowklqcw4uqwzdsebnpxaynffzctjs6r5mmzzpn6jn76au7qwexid.onion |
| Leak location 67 | Onion service | Up checked 5h ago | 5igtvs225ikh2svqvf7zkanyica5jz5p5db44fg2rwj7ifyjipvyimid.onion |
| Leak location 66 | Onion service | Up checked 5h ago | y2yplioc7ybrun2qb4opyc2vdt6lqtxvag3rocayyv2ekbtoa7kjo3qd.onion |
| Leak location 65 | Onion service | Up checked 5h ago | 6p6fubv4udi7kzgh4jojcplujeogmacclxmskfb3y6bknkh7zh7hohyd.onion |
| Leak location 63 | Onion service | Up checked 5h ago | zd4caqa225s2rs2nhst4y5nkt575ohdpfm6zwy6mug6js3izseli24qd.onion |
| Leak location 62 | Onion service | Up checked 5h ago | t26owzk2773mecpebt4l2eztx6lvn5642fn7annaynq7vwvb6wonkrid.onion |
| Leak location 61 | Onion service | Up checked 5h ago | 3kiwpavmpi2eyc2d4cbggo6s4fnodqzlhxirudruptvjx32wlxxzn6ad.onion |
| Leak location 60 | Onion service | Up checked 5h ago | xyaaupqnht5foymeilb67uv5ljjod5o3uyq62llldv4r4jiqxj2nhoqd.onion |
| Leak location 58 | Onion service | Up checked 5h ago | nh2kwgilfzi5mngiiqtcuoueh2oy4dkjq5cnfnjymueoj654fi7qtpid.onion |
| Leak location 56 | Onion service | Up checked 5h ago | pcixe2pw5ho6qpkjwbrsscvdcpzfj7vt3stvyde5ii5wdlqgvtyr4vad.onion |
| Leak location 57 | Onion service | Up checked 5h ago | ixybueqla5otlp5qfud5bcri2qoyxxhujwtrae5dkxnuo2eof3oliiyd.onion |
| Leak location 55 | Onion service | Up checked 5h ago | k6aw4if6phmqcdp5wzfdjfb3plmybzpkcssmgvv5nltv23tndvh4ewid.onion |
| Leak location 54 | Onion service | Up checked 5h ago | awlcpawkphkrrhg6jhwoz5nnrhzz5kfwq2tuzmteyrosgfcpbkisarqd.onion |
| Leak location 51 | Onion service | Up checked 5h ago | 3cpc3v57l7rstjtaelxgnlrzsolz7pd6ltsygjo2tjuonxteyaba2pid.onion |
| Leak location 43 | Onion service | Up checked 5h ago | f53mekzwvscxejfqxtikrzcmqnd3bt5i4d7odvh62sir7eqhdwwjntad.onion |
| Leak location 1 | Onion service | Up checked 5h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 2 | Onion service | Up checked 5h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion |
| Leak location 52 | Web location | Up checked 5h ago | ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/leaks.php |
| Leak location 64 | Onion service | Down checked 5h ago | 2gvprypcd3wemjghnnassqtro7nwhocr5ry4bngx7x7xhks7f7oillqd.onion |
| Leak location 59 | Onion service | Down checked 5h ago | pal3f65j4qj7b2hz2mlmimu4vhl4wz7sfdlvp3g2ry3qwk5nc6pbakid.onion |
| Leak location 53 | Onion service | Down checked 5h ago | ex55if4jgsdyi6do4gtyzpishq2tvwatjrhoclqcihxcsipam3uxrryd.onion |
| Leak location 50 | Onion service | Down checked 5h ago | efs3fkrjyvqsk7nugzteelo5i5jxoch5ziqhf37dzmmlmzzlymhawmid.onion |
| Leak location 48 | Onion service | Down checked 5h ago | hz7krqig75lgdzl7rtxynw26m3vornjl24ikeyqb5vagbae2iectorqd.onion |
| Leak location 49 | Onion service | Down checked 5h ago | kcykitrgt5sceuap4wrgeqdx53z2kgailaa5a62qxmdl7mbqarfgt3id.onion |
| Leak location 47 | Onion service | Down checked 5h ago | 3ssy6kepkwajapmra262il4tnufgbujf2boz7odgigc3e46dzdqd6wad.onion |
| Leak location 46 | Onion service | Down checked 5h ago | pgjf3dfkamnprahggbw4yojyb7sot3no2glnbfwyzbzqbnaislpv52yd.onion |
| Leak location 45 | Onion service | Down checked 5h ago | x2ol75zago3z2nrp7lnmbcwoq3okiexuwi456oe6jqurbprg6lljz3yd.onion |
| Leak location 44 | Onion service | Down checked 5h ago | hu5zd7ek6glyoke5kfc4mvt6s3cmia6ebtqptumvbogzdo2vrn5e7bid.onion |
| Leak location 42 | Onion service | Down checked 5h ago | c7bgta4watnqu64jnfgp4tzvhfhxgwveqnes65q3mcu4f34xvn7rumad.onion |
| Leak location 41 | Onion service | Down checked 5h ago | efgmr2vxwynrn7vlemidwf4ffwl4vljsb4eusaz3bplwk3apthpkpsad.onion |
| Leak location 39 | Onion service | Down checked 5h ago | fbvrolfvadyhigunc5hfw5hextwqn4lvq7d5ieeivcizsxh3avn6dryd.onion |
| Leak location 40 | Onion service | Down checked 5h ago | 2tlkuy2qn7bfxyvbfpxqaqveoezctbrnk6yvbvin6dueiuk4rdoosyqd.onion |
| Leak location 38 | Onion service | Down checked 5h ago | qfxx5gxyh53a32itguxez6dqcsm3vkrron3nmxhzkn3g64qld5lijoyd.onion |
| Leak location 37 | Onion service | Down checked 5h ago | 24nmjyf6g5otaydjtintzmqv3qme3fnrt62ui2anqdz2hmxnwps4e2ad.onion |
| Leak location 35 | Onion service | Down checked 5h ago | 3y5p4cq7bke5exre4smsgueqzfwdy7u4z3rp7o3dgxm27lhsx6vqraid.onion |
| Leak location 36 | Onion service | Down checked 5h ago | x6obl6pfmqsasvwj72hr22s2mpsdaklwkoa46zk3h7kbkcznu6whdmad.onion |
| Leak location 33 | Onion service | Down checked 5h ago | ihbpu7nworzao2klqeeahnz7wcuavltny3p2cmfkhe5tko3vl3zcowyd.onion |
| Leak location 34 | Onion service | Down checked 5h ago | mpyeixjqjufjki2qg7dutvxk6tjjzv2jf7qc63bljzfqrtbjcdktziqd.onion |
| Leak location 32 | Onion service | Down checked 5h ago | zsjvoqymwx5gdwntsrrk3pvnkfyoxy3knhoxitpdaobxznwc5iwcj4id.onion |
| Leak location 31 | Onion service | Down checked 5h ago | vhs6omcvvqdtmgae5cvpy4jfxfrw2l4b7e64j7fn7xeaqeppzab67oad.onion |
| Leak location 29 | Onion service | Down checked 5h ago | hhzt3me6rtxg5rwjbikojbxioosmiprsjrd25ovjhxirx4ocjdwuoqad.onion |
| Leak location 30 | Onion service | Down checked 5h ago | gobj3ph5sj332iithgescrsejiszhaey5l4ffwnou4nwanbcf37phdqd.onion |
| Leak location 28 | Onion service | Down checked 5h ago | glsvddrnd4qu56uhx65mrepgaoer6vtfr6q6qgsbpnml3b3fm2h7lcid.onion |
| Leak location 27 | Onion service | Down checked 5h ago | pzbd27cw7pkctovnmfaoeldjf32bc63mwqwhcxcftkqntest2bkkuaid.onion |
| Leak location 26 | Onion service | Down checked 5h ago | wp5yyng6znkcsijil5w4bug7b6uww573ut3czz3amjpfdusnuu4u5kad.onion |
| Leak location 25 | Onion service | Down checked 5h ago | j76ts5r62mwtfqg6t2po7komao65jzgglaavnvloeltfenazpt57vaad.onion |
| Leak location 24 | Onion service | Down checked 5h ago | f4fjja74gn766x5fwxqepl4aa7wyzuu3tj6fllt6oy6j5e27zxwskeid.onion |
| Leak location 23 | Onion service | Down checked 5h ago | d55ahmrs2mbfcmframropdz4epz3is77ex2fbkbowhrqtxv7knunkxqd.onion |
| Leak location 22 | Onion service | Down checked 5h ago | ycgykop5f4te6yaptg57ze75kgnqo6u2e3yyeo3hkjgjxakjx2g5ksqd.onion |
| Leak location 21 | Onion service | Down checked 5h ago | viqh6qmehdkpn7jrfhthyejxtg3gd5hg4bch7sjetvkdaipeu3k6anad.onion |
| Leak location 20 | Onion service | Down checked 5h ago | 5s2rv76limdt3eelmoh2vw6xovckjl563tjdifplvyxezdchcyn5xxyd.onion |
| Leak location 19 | Onion service | Down checked 5h ago | u2q76zahlrpgvktr3i2j6o2emzcre67et2kvz43kj2gbrhokc2othqyd.onion |
| Leak location 18 | Onion service | Down checked 5h ago | y3zfr23ubg7zvzdlo2incm55ro2ybtmzth67eklxpxo55aux2jiqpbid.onion |
| Leak location 17 | Onion service | Down checked 5h ago | xqcx7b57dd5vrqllokebwuvub4hk3viktn4lsgyt2bg67oujd42xolqd.onion |
| Leak location 15 | Onion service | Down checked 5h ago | sogw6fz6swsg42esmor63wj3iijpmoydt7sizwgzf2k6na6nglqt52ad.onion |
| Leak location 16 | Onion service | Down checked 5h ago | vecdwhichsjnv3x7t5b4o2hk23iwjurmcp2wrwd25jp3smvsth6e6nid.onion |
| Leak location 13 | Onion service | Down checked 5h ago | ljurl2gqwtgfqzk6pkz5ggtdrdrpzpzzkdvf4jhpkk33dnwkcsmdi4ad.onion |
| Leak location 14 | Onion service | Down checked 5h ago | ph2ilpfayyumhbetpdu6zovwy4vvm7qz3puh7k4zbre7bsf4e4ym5lqd.onion |
| Leak location 11 | Onion service | Down checked 5h ago | ir3oqafizlapipdyrebrfuk5bxd56zqjemljvfkeb42nzpxvkxwmqpqd.onion |
| Leak location 12 | Onion service | Down checked 5h ago | k6oor2g5bfvdxhxr2g6fczu3iqldbzyavydk56lh6z7ex7n7wqg4eryd.onion |
| Leak location 10 | Onion service | Down checked 5h ago | if6cf3llwqht3bs2glotrlsj4ayowc4pipadzbf7bkztln5ykifkjpyd.onion |
| Leak location 9 | Onion service | Down checked 5h ago | ewalffgokvo5x547bygn6c7ne56urhhwrl6q6t34fnryq65qf4oqnoqd.onion |
| Leak location 8 | Onion service | Down checked 5h ago | dnyyuk3nevegj37tnv3xav57c5twomc7uqsfbjlkwto3p4spzfop47qd.onion |
| Leak location 6 | Onion service | Down checked 5h ago | b5yuydwoxorp2qvirovzavbhpj72lcisv5unwblohkb6443u7m2mzuad.onion |
| Leak location 7 | Onion service | Down checked 5h ago | c4xaaynebochyp6ccvxi2bzbvncosdhqcb65cjuqwgqcljlul5gbrhyd.onion |
| Leak location 5 | Onion service | Down checked 5h ago | 6oqw2koek4nbmbb7ic3y4jr6scqsypg5en4h6mcqyrgg3jkny4sgaiyd.onion |
| Leak location 4 | Onion service | Down checked 5h ago | 523gzulwswe5tfevqlrxvqqh2fxo2mwrs2irnjel4mtu7qodgdu2ccyd.onion |
| Leak location 3 | Onion service | Down checked 5h ago | 4k6hj4ash2oo5svymxxrsycex3mdv5dqzom5rlyoojpe6map2lqgmqad.onion |
Top Activity Sectors (15)
- Education 49
- Services 23
- Manufacturing / Engineering 22
- Communication / Marketing 21
- Public Sector 18
- Finance / Legal / Insurance 17
- IT 16
- Healthcare / Pharma 16
- Retail / E-commerce 12
- Construction / Real Estate 11
- Not identified 6
- NGOs / Associations 6
- Agriculture / Food 3
- Hospitality / Food & Beverage / Tourism 2
- Transportation / Travel / Logistics 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Interlock, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: interlock leverages domain accounts harvested during initial access for persistence and privilege escalation.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: interlock exploits public-facing applications to gain initial access to victim networks.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1059.001 PowerShell Execution
What they do: interlock executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: interlock disables or modifies security tools like EDR agents to hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1110 Brute Force Credential Access
What they do: interlock performs brute force attacks against user accounts to obtain valid credentials.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1057 Process Discovery Discovery
What they do: interlock uses process discovery to identify critical services and processes for targeting.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: interlock moves laterally through SMB/Windows Admin Shares to access additional systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: interlock exfiltrates sensitive victim data before deployment to enable double extortion.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: interlock encrypts victim data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: interlock inhibits system recovery by destroying Volume Shadow Copies and backup mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (17)
▼Software Interlock has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
OffSec
Offensive security tooling
RMM Tools
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Dark Eye.
Ransom Notes (4)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README__.txt
INTERLOCK - CRITICAL SECURITY ALERT
To Whom It May Concern,
Your organization has experienced a serious security breach. Immediate action is required to mitigate further risks. Here are the details:
THE CURRENT SITUATION
- Your systems have been infiltrated by unauthorized entities.
- Key files have been encrypted and are now inaccessible to you.
- Sensitive data has been extracted and is in our possession.
WHAT YOU NEED TO DO NOW
1. Contact us via our secure, anonymous platform listed below.
2. Follow all instructions to recover your encrypted data.
Access Point: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
Use your unique Company ID: [snip]
DO NOT ATTEMPT:
- File alterations: Renaming, moving, or tampering with files will lead to irreversible damage.
- Third-party software: Using any recovery tools will corrupt the encryption keys, making recovery impossible.
- Reboots or shutdowns: System restarts may cause key damage. Proceed at your own risk.
HOW DID THIS HAPPEN?
We identified vulnerabilities within your network and gained access to critical parts of your infrastructure. The following data categories have been extracted and are now at risk:
- Personal records and client information
- Financial statements, contracts, and legal documents
- Internal communications
- Backups and business-critical files
We hold full copies of these files, and their future is in your hands.
YOUR OPTIONS
#1. Ignore This Warning:
- In 96 hours, we will release or sell your sensitive data.
- Media outlets, regulators, and competitors will be notified.
- Your decryption keys will be destroyed, making recovery impossible.
- The financial and reputational damage could be catastrophic.
#2. Cooperate With Us:
- You will receive the only working decryption tool for your files.
- We will guarantee the secure deletion of all exfiltrated data.
- All traces of this incident will be erased from public and private records.
- A full security audit will be provided to prevent future breaches.
FINAL REMINDER
Failure to act promptly will result in:
- Permanent loss of all encrypted data.
- Leakage of confidential information to the public, competitors, and authorities.
- Irreversible financial harm to your organization.
CONTACT US SECURELY
1. Install the TOR browser via https://torproject.org
2. Visit our anonymous contact form at http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/support/step.php
3. Use your unique Company ID: [snip]
4. Review a sample of your compromised data for verification.
5. Use a VPN if TOR is restricted in your area.
!!!OPEN_ME!!!.txt
Action Required: Data Breach Notification Your Data Is Now Beyond Your Control We have taken control of your systems, encrypted your critical files, and extracted sensitive data. This is a pivotal moment for your organization—your actions now will determine the outcome. --- What You Need to Understand Your data security was compromised because of insufficient protection. As a result: 1. All access to important files has been restricted through encryption. 2. We possess confidential business records, personal data, and other critical information. 3. If you do not respond within 72 hours, we will initiate the public release of your data, creating irreversible damage. --- The Risks You Face: Failure to act swiftly puts your organization at risk of: - Legal violations under GDPR, GLBA, CCPA, HIPAA, NYDFS Cybersecurity Regulation, and DPA 2018. - Financial penalties for failing to protect Non-Public Information (NPI). - Reputational harm as clients, partners, and the public lose trust in your ability to safeguard their data. --- What You Must Do Immediately: 1. Initiate Communication: - Access our recovery portal using TOR Browser. - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Visit http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php, using your Organization ID [snip] to start the negotiation process. 2. Alternative Browser Access: - Use Chrome, Edge, or Firefox to open http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] to receive detailed recovery instructions. --- What Happens Next: - If we do not hear from you within 72 hours, your data will be exposed to the public and sold to interested parties. - The ensuing violations of laws such as GDPR and HIPAA will lead to significant penalties, lawsuits, and regulatory scrutiny. --- Your Responsibility: Your organization is fully accountable for protecting the data it collects. By neglecting this responsibility, you have allowed this situation to unfold. Your chance to regain control is limited—act decisively to avoid catastrophic outcomes.
FIRST_READ_ME.txt
Final Warning: Your Data Is at Risk To the Leadership of Your Organization We have encrypted your systems and extracted sensitive information from your network. Your organization's failure to prioritize cybersecurity has left critical data vulnerable, and now, the consequences are at hand. --- What You Need to Know: 1. We have seized key documents, customer information, and confidential business data. 2. Access to these files has been locked with advanced encryption. 3. Responsibility for this breach lies with your organization, as you are obligated by law to protect Non-Public Information (NPI). --- Legal and Financial Risks: If you fail to act within 72 hours, we will begin publishing your data on our leak platforms. The consequences will include: - Violations of laws such as GDPR, HIPAA, CCPA, GLBA, and NYDFS Cybersecurity Regulation. - Severe fines for non-compliance and lawsuits from affected parties. - Long-term reputational damage to your business, leading to client and partner losses. --- Your Actions: To prevent escalation, you must cooperate immediately. 1. Access our Recovery Platform via TOR Browser: - Download TOR from [https://www.torproject.org](https://www.torproject.org). - Open: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php - Use your Organization ID [snip] to create a private negotiation chat. 2. Alternative Access for Regular Browsers: - Open Chrome, Edge, or Firefox. - Navigate to: http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php - Enter your Organization ID [snip] for instructions. --- Important Warning: - Do not attempt self-recovery; it will fail and lead to data corruption. - Avoid engaging third-party negotiators or law enforcement; this will void any possibility of resolution. - Remember, the data we hold could be used by regulators, competitors, or even the media, causing irreparable harm to your business. Time is of the essence. Every hour of inaction increases the likelihood of devastating consequences. Make the right decision secure your future by cooperating with us now.
READ_THIS_ONE_FIRST.txt
We have successfully breached your network, encrypted your files, and obtained highly sensitive data. This is the result of weak cybersecurity on your part. As of now, your access to critical business information has been revoked. The only way to regain control is through cooperation. If you fail to contact us within 72 hours, we will proceed to publish your data to the public, ensuring severe consequences for your organization. By not addressing this matter, you risk violating major laws such as GDPR, GLBA, HIPAA, CCPA, NYDFS Cybersecurity Regulation, and DPA 2018. Such violations can result in massive fines, lawsuits, and irreparable harm to your reputation. It is your organization`s responsibility to protect Non-Public Information (NPI); neglecting this duty has led to this situation. To resolve this issue, visit our secure negotiation portal using the TOR Browser. Download TOR from [https://www.torproject.org](https://www.torproject.org), and access http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion/chat.php. Use your Organization ID [snip] to initiate communication. If you prefer, you can also use standard browsers like Chrome, Edge, or Firefox and go to http://ebhmkoohccl45qesdbvrjqtyro2hmhkmh6vkyfyjjzfllm3ix72aqaid.onion.ly/chat.php, where your ID will allow you to proceed. Do not attempt to recover files on your own or involve third parties, as these actions will void the opportunity to resolve this matter and could lead to permanent data loss. Failure to act will escalate the situation, exposing your data to competitors, regulators, and the media. Your future depends on your decision now-act responsibly before the deadline passes.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (24841)
Search, filter and paginate the victim timeline for Interlock. Showing 5601–5700 of 24841.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Elliott-Lewis id32832 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a business entity operating within the Services sector, based in the United States. The domain represents an organization cataloged in a threat-intelligence index under its designation as a ransomware victim. This listing associates the entity with the threat actor interlock, contributing structured intelligence for security analysts tracking adversary activity and impacted organizations. The description intentionally avoids speculative details regarding data exposure, operational impact, or confirmed breach specifics, adhering to factual and neutral reporting standards. It serves as a reference point within cybersecurity catalogs for understanding threat actor reach and victim landscape patterns. |
||||||
| Ransomware | Elliott-Lewis id32832 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a United States-based entity operating within the Services sector, documented in the threat-intelligence index as a ransomware victim. Its profile reflects exposure within cybersecurity threat ecosystems, with attribution linked to the interlock threat actor group. The listing type identifies the entity's relationship to ransomware activity without disclosing unverified technical details, breach specifics, or unconfirmed claims. This catalog entry provides neutral context for analysts monitoring service-sector security events and associated threat actor activity. It neutrally states that https://elliottlewis.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a United States-based company operating within the Services sector, providing professional and commercial services. It has been cataloged within this threat-intelligence index under the designation of ransomware victim, with the associated threat actor or source identified as interlock. The listing reflects the entity's inclusion in cybersecurity threat data, highlighting its connection to this specific threat actor profile without disclosing unverified incident details. This entry supports threat analysts and security teams monitoring ransomware activity across service-oriented organizations in the United States. The record serves as a reference point for understanding interlock's operational footprint and the vulnerability landscape within this sector. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a services-sector organization based in the United States, operating within professional services contexts. The entity is cataloged within the threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This classification reflects observed cybersecurity intelligence linking the organization to ransomware activity attributed to interlock. The description avoids speculation regarding specific incident details, data impacts, or operational outcomes. It neutrally documents the entity's presence in the ransomware victim listing associated with interlock for catalog and intelligence purposes. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a company operating within the Services sector based in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, specifically associated with the threat actor interlock. This designation reflects the cybersecurity event linking elliottlewis.com to interlock's activity, without disclosing unverified technical or operational details. The entry serves to document the relationship for security professionals monitoring ransomware incidents across sectors and geographies. It provides neutral context for threat researchers and defenders assessing associated risks. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
elliottlewis.com operates within the Services sector based in the United States, providing digital services and maintaining an online presence at https:elliottlewis.com. The entity is cataloged as a ransomware victim within a threat-intelligence index, with its association to the threat actor interlock documented for analytical reference. This listing type indicates a cybersecurity incident classification rather than confirmed operational details of the attack. The description remains neutral and avoids speculating on data exposure, ransom activity, or specific technical compromise vectors. It serves to contextualize the entity within cyber-threat intelligence frameworks for monitoring and risk assessment purposes. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents a company operating within the Services sector based in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor and source identified as interlock. The description focuses on the entity's classification and contextual cybersecurity relevance rather than inventing unverified incident details such as data stolen, records compromised, ransom demands, or confirmed breach specifics. This entry supports professionals seeking structured intelligence on ransomware incidents tied to specific organizations, threat actors, sectors, and geographic locations. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity within the Services sector based in the United States. The domain is cataloged as a ransomware victim within the threat-intelligence index, with interlock identified as the associated threat actor or source. This listing provides structured context regarding the entity's exposure profile and its linkage to documented cyber threat activity. The description remains factual and neutral, focusing on the entity's classification, geographic context, sector, and the specific association with interlock without elaborating on unverified technical or operational details. It serves as reference material for threat analysts assessing ransomware-related intelligence. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity within the Services sector based in the United States. The domain is cataloged as a ransomware victim within the threat-intelligence index, with the associated threat actor identified as interlock. This listing type indicates documented exposure to ransomware activity linked to interlock's operations. The description remains factual and neutral, focusing on the entity's classification, geographic context, sector alignment, and verified attribution without speculating on unconfirmed technical details or incident specifics. Such profiles support threat analysts in tracking adversary activity and understanding victim landscape patterns across critical service industries. |
||||||
| Ransomware | Elliott-Lewis id32833 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity within the Services sector based in the United States. The domain is cataloged as a ransomware victim within a threat-intelligence index. Its association with the threat actor interlock is documented neutrally in the listing. No specific incident details, such as data stolen, records accessed, ransom demands, or confirmed breach evidence, are provided in this description. This entry serves as a factual reference for cybersecurity professionals monitoring ransomware activity and threat actor footprints across service-oriented organizations. |
||||||
| Ransomware | Elliott-Lewis id32834 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity within the Services sector based in the United States. The domain is cataloged as a ransomware victim within a threat-intelligence index, with its associated threat actor identified as interlock. This listing type indicates the entity's inclusion due to documented threat activity linked to this actor, without disclosing specific incident details such as data stolen, records affected, ransom demands, or confirmed breach specifics. The description adheres to neutral, encyclopedic standards for catalog copy, focusing solely on verified index attributes including sector, geographic location, listing classification, and source attribution. No invented facts, claims, or operational details are included beyond the verified association. |
||||||
| Ransomware | Elliott-Lewis id32839 View details | United States | Services | leaked | ||
|
elliottlewis.com operates within the Services sector and is located in the United States. The entity provides professional services, though specific service offerings are not detailed in available intelligence sources. It is cataloged within a threat-intelligence index under the listing type ransomware victim, linked to the threat actor interlock. This designation reflects its inclusion in records documenting cybersecurity incidents involving this actor. The description remains neutral and avoids speculation regarding breach details, data handling, or operational impact. It serves as factual catalog context for researchers and defenders monitoring threat actor activity. |
||||||
| Ransomware | Elliott-Lewis id32852 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity within the Services sector based in the United States. Its profile in the threat-intelligence index identifies it specifically as a ransomware victim associated with the threat actor interlock. The listing type contextualizes the entity's exposure within cybersecurity incident databases, providing analysts with verified linkage data for threat assessment and defense planning. This description adheres strictly to documented catalog information without extrapolating unconfirmed technical details or incident specifics. The inclusion reflects verified intelligence correlating this organization with interlock's activity profile. |
||||||
| Ransomware | Elliott-Lewis id32852 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents a company operating within the Services sector based in the United States. The entity is cataloged within this threat-intelligence index as a ransomware victim, specifically associated with the threat actor interlock. This listing type indicates that the organization was impacted by ransomware activity linked to interlock's operations. The catalog entry provides neutral context regarding the entity's status within cybersecurity threat databases and incident tracking frameworks. No specific technical details, data breach specifics, or confirmed incident metrics are included in this description to maintain factual accuracy and avoid speculation. |
||||||
| Ransomware | Elliott-Lewis id32853 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is an entity operating within the Services sector located in the United States. The domain represents a business whose security posture was assessed as part of threat-intelligence cataloging efforts focused on ransomware activity. As a ransomware victim listing associated with the threat actor interlock, this entry documents the entity's involvement within a cyber threat intelligence framework. The description remains neutral regarding specific technical details, data impacts, or remediation specifics. This catalog entry serves to inform stakeholders about the entity's status within the indexed threat landscape and its connection to identified malicious actor behavior. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
elliottlewis.com operates within the Services sector and is associated with the United States. The entity is documented within this threat-intelligence index under the listing type ransomware victim, with the associated threat actor identified as interlock. This entry provides contextual information regarding the organization's involvement in a cyber incident and its linkage to the specified threat actor for monitoring and analysis purposes. The description remains factual and neutral, focusing on the verified associations without speculating on unconfirmed details such as data exfiltration or financial impact. This catalog entry supports threat-intelligence workflows by clearly identifying the entity, its sector, geographic context, listing classification, and associated actor. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a United States-based Services sector entity documented within this threat-intelligence index under the ransomware victim listing type. The entity represents an organization whose security posture was impacted by activity linked to the interlock threat actor. Catalog entries of this nature provide structured intelligence for defenders assessing exposure, threat actor footprints, and sector-specific risk patterns across the Services industry. This description adheres to neutral, encyclopedic standards without disclosing unverified incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com identifies an entity operating within the Services sector based in the United States. The domain represents a business entity whose infrastructure was impacted by a ransomware incident, as documented within this threat-intelligence index. The listing type specifically categorizes this entity as a ransomware victim linked to the threat actor interlock. This entry provides neutral context for monitoring cyber threats, supporting threat-intelligence analysis, and enhancing defensive awareness related to identified attack patterns in the Services sector. The description avoids speculation regarding data specifics while accurately reflecting the indexed classification. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity operating within the Services sector located in the United States. The domain is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor or source identified as interlock. Catalog descriptions for such entities focus on verified attribution and sector context rather than speculative incident details. This entry reflects the index's classification without confirming specific breach elements, data compromises, or operational impacts. The entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a United States-based entity operating within the Services sector. The domain represents a business entity whose security posture was impacted by a ransomware incident, as documented within the threat-intelligence index. This listing type identifies the entity as a ransomware victim associated with the threat actor interlock. The record provides contextual intelligence for threat analysts tracking attack patterns, victim profiles, and actor-specific indicators across the Services industry. The description remains factual and neutral, focusing solely on the indexed classification without elaborating on unconfirmed technical details or incident specifics. This entry supports comprehensive cyber threat monitoring and intelligence aggregation efforts. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a US-based entity operating within the Services sector, providing digital and professional services. It has been cataloged within a threat-intelligence index under the listing type ransomware victim, specifically linked to the threat actor interlock. This designation reflects the entity's documented association with this cyber threat actor within threat intelligence records. The entry serves as a reference point for security analysts monitoring ransomware activity across the Services sector in the United States. No specific incident details, such as data stolen or ransom amounts, are included per strict factual reporting guidelines. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity within the Services sector based in the United States. The domain is cataloged as a ransomware victim within a threat-intelligence index. This listing type identifies the entity as having experienced ransomware-related activity. The association with the threat actor interlock provides context for its inclusion in cybersecurity threat databases. The description avoids speculative claims regarding compromised data, financial impact, or technical details, maintaining factual neutrality consistent with threat-intelligence reporting standards. |
||||||
| Ransomware | Elliott-Lewis id32855 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a Services sector organization based in the United States, cataloged within this threat-intelligence index as a ransomware victim. The entity name and sector provide context for its operational domain while maintaining factual restraint regarding unconfirmed incident details. This listing type indicates its inclusion in intelligence records tied to the interlock threat actor, reflecting observed threat-related activity or attribution context. The description avoids speculation about stolen data, ransom terms, breach scope, or confirmed impact, adhering to neutral and authoritative reporting standards. It serves as a structured reference point for researchers and defenders monitoring ransomware incidents within the Services sector in the United States and associated with interlock. |
||||||
| Ransomware | Elliott-Lewis id32871 View details | United States | Services | leaked | ||
|
https://elliottlewis.com identifies an entity operating within the Services sector located in the United States. The domain serves as a reference point within a threat-intelligence index documenting cybersecurity incidents, specifically categorized as a ransomware victim listing linked to the interlock threat actor. This entry contributes contextual intelligence regarding attacker targeting patterns, sector exposure, and geographic risk indicators for security professionals and defenders. The description remains neutral and factual, focusing solely on the entity's classification within the index without elaborating on unverified incident details such as data exfiltration scope, ransom demands, or specific breach mechanics. |
||||||
| Ransomware | Elliott-Lewis id33063 View details | United States | Services | leaked | ||
|
https://elliottlewis.com operates within the Services sector based in the United States, providing professional and commercial services. The entity is cataloged in the threat-intelligence index under the listing type ransomware victim, with interlock identified as the associated threat actor or source. This designation reflects observed threat-intelligence linkages without confirming specific incident details such as data accessed, scope, or resolution. The entry serves as a reference point for monitoring security implications within the Services sector and understanding connections to the interlock threat actor profile. It remains a documented case for cybersecurity researchers and defenders assessing ransomware exposure. |
||||||
| Ransomware | Elliott-Lewis id33064 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents a company operating within the Services sector based in the United States. The entity is cataloged in the threat-intelligence index with the listing type ransomware victim, associated with the threat actor interlock. Catalog entries provide structured context regarding organizational exposure profiles and threat-actor linkages for security professionals and analysts monitoring cyber incidents. This description maintains factual neutrality regarding the entity's operational profile and its documented association with interlock within the ransomware victim classification. |
||||||
| Ransomware | Elliott-Lewis id33065 View details | United States | Services | leaked | ||
|
https://elliottlewis.com operates within the Services sector and is based in the United States. The entity provides services aligned with professional service offerings and is documented within this threat-intelligence index under the classification of ransomware victim. The listing associates this organization with the threat actor interlock, reflecting its inclusion in cybersecurity intelligence records related to malicious activity targeting service-sector entities. This description maintains neutrality regarding specific incident details while accurately conveying the entity's categorization, geographic context, sector focus, and threat association. The entry serves as a reference point for threat analysts monitoring ransomware incidents across service-oriented organizations. |
||||||
| Ransomware | Elliott-Lewis id33065 View details | United States | Services | leaked | ||
|
https://elliottlewis.com operates within the Services sector based in the United States, providing digital services and maintaining an online presence. This entity is cataloged within the threat-intelligence index under the listing type ransomware victim. Its association with the threat actor interlock indicates its inclusion in intelligence datasets focused on ransomware activity and targeted organizations. The description adheres to neutral, encyclopedic standards without disclosing unverified incident details such as data exfiltration specifics, ransom terms, or confirmed breach metrics. This entry supports cybersecurity professionals in monitoring threat actor behavior and assessing potential risks across service-sector environments. |
||||||
| Ransomware | Elliott-Lewis id33065 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a United States-based Services sector organization cataloged within this threat-intelligence index. The entity represents a ransomware victim listing, explicitly linked to the threat actor interlock. This designation reflects the cybersecurity context in which the organization was identified within threat monitoring frameworks. The listing type underscores its role as a reported victim of ransomware activity, providing stakeholders with verified threat-actor association data for risk assessment and defensive planning. The description remains neutral and factual, focusing solely on the entity's categorization and its association with interlock. |
||||||
| Ransomware | Elliott-Lewis id33065 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents an entity operating within the Services sector based in the United States. The domain is cataloged as a ransomware victim within a threat-intelligence index. This listing type indicates documented association with the threat actor interlock, reflecting cybersecurity intelligence observations. The entity's offerings and operational profile are contextualized within its sector and geographic location for analytical reference. The entry neutrally records that https://elliottlewis.com was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Elliott-Lewis id33065 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents a company operating within the Services sector based in the United States. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as interlock. This designation reflects the entity's inclusion in records documenting cybersecurity incidents involving this specific threat actor. The description remains neutral and factual, focusing on the entity's classification, operational context, and threat-intelligence linkage without asserting unverified incident details. Such listings support threat analysts and defenders in tracking adversary activity across sectors and geographies. |
||||||
| Ransomware | Elliott-Lewis id33065 View details | United States | Services | leaked | ||
|
https://elliottlewis.com represents a company operating within the Services sector based in the United States. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, with an associated threat actor identified as interlock. This designation reflects the entity's inclusion in records documenting cybersecurity incidents involving this specific threat actor. The description remains neutral and factual, focusing on the entity's classification, operational context, and threat-intelligence linkage without asserting unverified incident details. Such listings support threat analysts and defenders in tracking adversary activity across sectors and geographies. |
||||||
| Ransomware | Elliott-Lewis id32862 View details | United States | Services | leaked | ||
|
https://elliottlewis.com is a website representing an organization operating within the Services sector, based in the United States. The entity is cataloged within this threat-intelligence index under the listing type ransomware victim, explicitly linked to the threat actor interlock. This designation reflects the entity's inclusion in cybersecurity intelligence records documenting its association with this particular threat actor and its classification regarding ransomware activity. The description provides neutral, factual context regarding the entity's sector, geographic location, and its role within the ransomware victim index associated with interlock, without disclosing unverified incident details. |
||||||
| Ransomware | Elliott-Lewis id32862 View details | United States | Services | leaked | ||
|
Since 1905, Elliott-Lewis Corporate has provided comprehensive solutions for maintenance, repair and operations, engineering, design, installation, and energy consumption. In addition, Elliott-Lewis' Facilities Management team provides individual on-site operations management but does not provide security to its customers, resulting in a large database of confidential contracts and projects, as well as personal customer and employee data. |
||||||
| Ransomware | Wagon Mound Public Schools id27218 View details | United States | Education | leaked | ||
|
Wagon Mound Public Schools provides education to students in the Wagon Mound area, providing resources and support for both elementary and middle schools. However, they neglected to address the security of their materials, resulting in the compromise of all their personal data, including the school's blueprints. We present to your attention a 80 GB of data, which includes staff and student information, their phone numbers, residence addresses, and passport numbers. |
||||||
| Ransomware | Wagon Mound Public Schools id32532 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim operating within the US Education sector. The entity identifier suggests involvement in a K12 educational context based on its naming convention, with location signals pointing to the United States. This listing type captures the relationship between the entity and the interlock threat actor within a threat-intelligence index, highlighting sector exposure and geographic relevance for defenders monitoring education-focused cyber incidents. The entry provides neutral context for security teams assessing ransomware activity patterns across educational institutions. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32532 View details | United States | Education | — | ||
|
Wagon Mound Public Schools provides education to students in the Wagon Mound area, providing resources and support for both elementary and middle schools. However, they neglected to address the security of their materials, resulting in the compromise of all their personal data, including the school's blueprints. We present to your attention a 80 GB of data, which includes staff and student information, their phone numbers, residence addresses, and passport numbers. |
||||||
| Ransomware | Wagon Mound Public Schools id32638 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity within the threat-intelligence index designated as a ransomware victim operating within the Education sector and located in the United States. The domain name references the K-12 (elementary and secondary education) context and the state of New Mexico, indicating its operational footprint within U.S. educational institutions. As part of this ransomware victim listing, the entity is associated with the threat actor interlock, providing critical context for cybersecurity analysts monitoring educational infrastructure threats. This entry serves as a reference point for understanding ransomware activity targeting U.S. education sectors and the specific threat actor interlock responsible. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32639 View details | United States | Education | — | ||
|
wm.k12.nm.us is a threat-intelligence index listing categorized as a ransomware victim within the United States Education sector. The entity name indicates a K12 (primary and secondary education) context in New Mexico, suggesting institutional infrastructure relevant to student and administrative systems. Its inclusion reflects observed threat activity or attributed incidents where interlock, the associated threat actor or source, is linked to this victim profile. The listing provides neutral catalog context for security professionals monitoring education-sector ransomware risks in the US. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32639 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity identified within the United States Education sector. The entity name suggests a North American public school or educational institution context, and the listing type indicates it has been cataloged as an affected organization in the threat-intelligence index. Associated with the threat actor interlock, this entry documents the relationship between the victim entity and the identified source or actor profile. The description remains neutral and avoids inventing breach details, data claims, or operational specifics. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32640 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity cataloged within a threat-intelligence index under the ransomware victim listing type. Its designation aligns with the Education sector and indicates operational context within the United States, specifically referencing New Mexico through the domain suffix nm. The entity represents an institution or organization assessed for cybersecurity relevance, reflecting exposure patterns associated with ransomware activity in educational environments. The association with threat actor interlock identifies a specific adversary or source connected to this classification in the index. This entry documents the relationship neutrally as a ransomware victim linked to interlock, contributing to broader threat awareness without disclosing unverified incident details. |
||||||
| Ransomware | Wagon Mound Public Schools id32644 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the United States Education sector. The domain name and context indicate involvement in a threat-intelligence index where the entity is categorized as a ransomware victim associated with the threat actor interlock. This listing type identifies the entity's role within cybersecurity threat reporting, linking a specific organization or infrastructure component to an active threat actor profile. The description remains factual and neutral, focusing on sector classification, geographic location, and the established association without speculating on unverified incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32644 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within a threat-intelligence index as a ransomware victim operating within the Education sector and based in the United States. The domain name suggests involvement in a K12 (elementary and secondary education) context within Nevada, indicating the organization's sector and geographic location. This listing type categorizes the entity as a victim of ransomware activity, associated with the threat actor interlock. The entry provides contextual intelligence for security analysts tracking ransomware incidents across educational institutions in the US. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32652 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity within the Education sector located in the United States, cataloged as a ransomware victim in the threat-intelligence index. Its designation reflects involvement in an incident associated with the threat actor interlock, providing context for security teams monitoring educational infrastructure threats. The entity name suggests a school or educational institution context, with sector and geographic data aligning with the US Education environment. This listing serves to document the relationship between the victim entity, the ransomware context, and the identified threat actor interlock without disclosing unverified incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32654 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the Education sector, located in the United States. The entity name indicates a K12 educational context, suggesting institutional or school-related infrastructure associated with the threat-intelligence index. Its listing reflects observed threat-actor linkage rather than confirmed technical incident details, maintaining neutrality regarding specific compromise elements. The associated threat actor and source identified is interlock, providing attribution context for the catalog entry. This description serves as authoritative index copy for threat-intelligence professionals evaluating ransomware exposure patterns across education environments in the US. |
||||||
| Ransomware | Wagon Mound Public Schools id32654 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity operating within the US Education sector. The domain prefix indicates a K12 context and references the state of New Mexico, situating the entity within a public or institutional education environment. As part of a threat-intelligence index, this listing type documents cybersecurity exposure associated with the threat actor interlock. The description focuses on entity classification, geographic and sectoral context, and the verified association with interlock without asserting unconfirmed breach details, data exfiltration specifics, or financial impact. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32655 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index as a ransomware victim operating within the Education sector and located in the United States. The name suggests involvement with a K12 (primary and secondary education) context in New Mexico, reflecting its sector classification and geographic focus. It is cataloged specifically as a ransomware victim associated with the threat actor interlock, indicating its inclusion in intelligence records documenting such incidents. This listing provides neutral, factual context for researchers and defenders analyzing ransomware activity within educational institutions across the US. The entry serves to inform stakeholders about threats targeting this specific entity and its sector profile. |
||||||
| Ransomware | Wagon Mound Public Schools id32658 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the Education sector, located in the United States. The entity name suggests a North American public or institutional education context, though specific operational details, infrastructure scope, or service offerings are not disclosed in the listing. This entry is associated with the threat actor interlock, indicating its inclusion in a threat-intelligence index to document ransomware-related exposure and actor linkage. The listing provides neutral intelligence context for researchers, defenders, and catalog maintainers monitoring Education-sector incidents tied to identified threat actors. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32658 View details | United States | Education | — | ||
|
wm.k12.nm.us represents an entity within the United States Education sector cataloged as a ransomware victim in the threat-intelligence index. The domain name indicates a focus on K12 (primary and secondary education) infrastructure in New Mexico, reflecting operational context and service offerings relevant to educational institutions. This listing type identifies the entity as having been affected by ransomware activity, with the associated threat actor designated as interlock. The entry provides structured intelligence context for security professionals monitoring education-sector threats and ransomware campaigns in the US. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32658 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index under the ransomware victim listing type. The name and context indicate involvement within the United States education sector, where K12 environments commonly face targeted cyber threats and operational disruption risks. Associated with the threat actor interlock, this entry documents the entity's classification and contextual profile for catalog and intelligence purposes. The description remains neutral regarding specific incident details, avoiding assumptions about data exposure, ransom activity, or confirmed breach specifics. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32658 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity within the threat-intelligence index categorized as a ransomware victim operating within the Education sector and located in the United States. The domain prefix wm.k12.nm.us indicates a North American school or educational institution context, aligning with its sector classification and geographic origin. This listing type identifies the entity as having been affected by ransomware activity, with interlock cited as the associated threat actor or source in the intelligence record. The description remains factual and neutral, focusing on the entity's classification, operational context, and linkage to the specified threat actor without asserting unconfirmed incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32658 View details | United States | Education | — | ||
|
wm.k12.nm.us is identified within the threat-intelligence index as a ransomware victim operating in the United States education sector. The entity name references K12 and the state of New Mexico, indicating its context within a school or educational institution environment. Threat-intelligence records associate this listing with the threat actor interlock, providing context for the entity's classification and the actor's activity profile. This entry serves as catalog documentation for monitoring ransomware incidents across education infrastructure in the US. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32658 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity cataloged within the threat-intelligence index under the ransomware victim listing type. Its naming convention and sector context indicate a US-based education organization or institution operating within the K12 domain of the nation state NM. The entity represents infrastructure or services relevant to education cybersecurity monitoring, where ransomware incidents carry significant operational, regulatory, and community impact. It is formally associated with the threat actor interlock in this index. This listing neutrally states that wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32659 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the Education sector, located in the United States. The entity name references a K12 and New Mexico context, indicating its operational environment is associated with school or educational infrastructure. As part of the threat-intelligence index, this listing type identifies the entity's involvement in a ransomware-related incident linked to the threat actor or source named interlock. The description remains factual and neutral, focusing on sector classification, geographic scope, and the association with the specified threat actor without asserting unverified details such as data stolen, ransom demands, or confirmed breach scope. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32659 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and associated with the United States, specifically New Mexico. The designation wm.k12.nm.us reflects its classification within cybersecurity monitoring contexts, linking the organization to a sector-specific threat event and its associated threat actor profile. This listing provides neutral catalog context for defenders assessing ransomware exposure in educational institutions across the US. The entity was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32662 View details | United States | Education | — | ||
|
wm.k12.nm.us is associated with the US Education sector and is cataloged as a ransomware victim within a threat-intelligence index. The entity name suggests a K12 educational context in New Mexico, reflecting its sector and geographic location. Its inclusion in the index links it to the threat actor interlock, providing threat-intelligence context for analysts tracking ransomware activity in educational institutions. This listing type identifies the entity as a victim of ransomware operations without disclosing unverified incident details. The entry contributes to monitoring cybersecurity risks across US education environments. |
||||||
| Ransomware | Wagon Mound Public Schools id32662 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the United States Education sector. The entity name references a K12 and New Mexico context, indicating its operational footprint is associated with school or educational infrastructure in the US. Its inclusion in the threat-intelligence index reflects observed or attributed ransomware activity linked to the interlock threat actor profile. The listing type identifies it specifically as a ransomware victim rather than a threat actor or infrastructure component. This entry provides neutral catalog context for analysts tracking education-sector security incidents and interlock-associated ransomware exposure. |
||||||
| Ransomware | Wagon Mound Public Schools id32663 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the United States Education sector. The entity name indicates a K12 educational context in New Mexico, suggesting institutional infrastructure serving students and educators. As part of a threat-intelligence index listing, wm.k12.nm.us is linked to the threat actor interlock, reflecting cybersecurity risk intelligence tied to this sector and geographic footprint. The description avoids speculative claims regarding data exfiltration, ransom demands, or confirmed breach details, maintaining factual neutrality. This entry documents the entity's classification and its association with interlock for threat-monitoring and catalog purposes. |
||||||
| Ransomware | Wagon Mound Public Schools id32663 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index under the ransomware victim listing type. Its designation aligns with the Education sector and the United States, reflecting operational context relevant to institutional digital infrastructure. The entity is cataloged as associated with the threat actor interlock, contributing contextual intelligence for threat analysts monitoring ransomware activity across educational environments. This listing provides neutral reference points for assessing risk patterns, actor relationships, and sector-specific exposure without disclosing unverified incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32664 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the United States education sector. The domain name and context indicate involvement in a K-12 educational environment in New Mexico, with offerings or infrastructure associated with school systems. This listing type identifies the entity as a ransomware victim linked to the threat actor interlock in the threat-intelligence index. The description avoids inventing specific incident details such as stolen data, records compromised, ransom demands, or confirmed breach specifics. It neutrally records that wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32664 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity within the US Education sector identified as a ransomware victim in the threat-intelligence index. Its designation reflects its operational context in a K12 educational environment and its inclusion under threat-actor attribution analysis. The entity is associated with the threat actor interlock, which is cataloged for its activity targeting critical infrastructure and educational institutions. This listing type documents the relationship between the victim entity and the identified cyber threat actor without disclosing unverified incident specifics. The entry serves as a reference point for security teams monitoring ransomware campaigns in US education sectors. |
||||||
| Ransomware | Wagon Mound Public Schools id32669 View details | United States | Education | — | ||
|
wm.k12.nm.us is a threat-intelligence index entry categorized as a ransomware victim operating within the Education sector and associated with the United States, specifically New Mexico. The entity name reflects its context within a K12 educational environment, indicating relevance to school, institutional, or student-facing infrastructure where ransomware incidents can significantly disrupt operations and data continuity. This listing identifies the entity alongside threat actor interlock, providing cybersecurity analysts with contextual linkage between affected infrastructure, sector exposure, geographic scope, and associated adversary activity. The description remains factual and neutral, focusing on the entity's classification, sector, location, and threat actor association without speculating on confirmed breach details, data impacts, or operational outcomes. |
||||||
| Ransomware | Wagon Mound Public Schools id32669 View details | United States | Education | — | ||
|
wm.k12.nm.us is identified within the threat-intelligence index as a ransomware victim entity operating in the United States education sector. The entity name indicates its association with K12 and Nevada (NM) education contexts, suggesting institutional infrastructure relevant to student and administrative systems. As a ransomware victim listing, the entry documents the relationship between this entity and the threat actor interlock, providing catalog context for defenders assessing attack patterns and sector exposure. The description remains factual and neutral, focusing on sector, geographic scope, listing classification, and associated actor without extrapolating breach details or inventing incident specifics. This entry supports threat-intelligence workflows by linking victims to active actors for monitoring and risk analysis. |
||||||
| Ransomware | Wagon Mound Public Schools id32671 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The designation wm.k12.nm.us aligns with known indicators referencing New Mexico and K-12 educational infrastructure, reflecting its operational context within U.S. education environments. This listing type categorizes the entity based on threat-intelligence analysis associating it with the threat actor interlock, without disclosing unverified incident details. The catalog entry provides structured context for cybersecurity professionals monitoring ransomware activity across educational sectors. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32671 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the Education sector, located in the United States, with operational context associated with Nevada. The entity name indicates a K12 educational institution, reflecting its role in the student and academic technology environment. As cataloged in the threat-intelligence index, wm.k12.nm.us is classified as a ransomware victim associated with the threat actor interlock. This listing provides structured intelligence context for security professionals monitoring education sector infrastructure threats and correlating ransomware incidents with identified source actors. The description remains factual and neutral, focusing on sector, location, listing classification, and associated threat actor without speculating on unconfirmed incident details. |
||||||
| Ransomware | Wagon Mound Public Schools id32672 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim entity within the United States Education sector. The domain name suggests a North American school or educational institution context, with offerings and infrastructure aligned to K-12 systems. This listing type identifies the entity as having been affected by ransomware activity, with interlock cited as the associated threat actor or source. The description reflects the threat-intelligence index classification without disclosing unverified incident specifics such as data stolen, ransom demands, or confirmed breach details. It serves as a reference point for monitoring educational infrastructure security threats in the US. |
||||||
| Ransomware | Wagon Mound Public Schools id32672 View details | United States | Education | — | ||
|
wm.k12.nm.us represents an entity within the United States Education sector, cataloged as a ransomware victim in a threat-intelligence index. The designation wm.k12.nm.us aligns with K-12 educational institution contexts, indicating involvement in public or institutional schooling environments across the nation. This listing type identifies the entity as a victim of ransomware activity, with the associated threat actor and source attributed to interlock. The entry serves to inform security teams, regulators, and threat researchers about compromised infrastructure in critical education systems. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32673 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index under the ransomware victim listing type. Operating within the US Education sector, the designation references a school or educational institution context, with NM indicating New Mexico as the geographic scope. The entity is cataloged as part of an intelligence record linking ransomware activity to the interlock threat actor. This listing provides neutral context for cybersecurity professionals assessing educational infrastructure exposure and associated threat patterns. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32677 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the Education sector and associated with the United States. The designation wm.k12.nm.us reflects its role in threat-intelligence records, contextualized by its K12 education environment and regional classification. This listing type identifies the entity as having been affected by ransomware activity, with interlock cited as the associated threat actor or source. The description remains factual and neutral, focusing on sector, location, and the verified association without extrapolating incident details. It was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32677 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity within the threat-intelligence index classified as a ransomware victim operating within the Education sector and based in the United States. The designation wm.k12.nm.us reflects its role in cybersecurity threat tracking, where it is cataloged to identify affected infrastructure and contextualize attack patterns relevant to educational institutions. This listing type highlights the entity's association with the threat actor interlock, providing analysts with structured intelligence for risk assessment, sector-specific defense planning, and cross-referencing threat campaigns. The entry underscores the importance of monitoring ransomware incidents within US educational environments to support proactive mitigation and threat-response strategies. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32677 View details | United States | Education | — | ||
|
wm.k12.nm.us is a public school district serving students in the state of New Mexico, United States, offering comprehensive K‑12 education, curriculum development, and digital learning platforms. The district operates multiple elementary, middle, and high schools, delivering standard academic programs alongside extracurricular activities and community services. As part of the education sector, it maintains student information systems, staff portals, and networked classroom technologies. The organization was listed as a ransomware victim associated with the Interlock threat actor, highlighting the growing cyber threats targeting educational institutions. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the United States Education sector. The entity name indicates a K12 (primary and secondary education) context in New Mexico, suggesting institutional infrastructure serving students and administrators. It is cataloged as a ransomware victim associated with the threat actor interlock, reflecting its inclusion in threat-intelligence indexing for cybersecurity monitoring and sector-specific risk assessment. The listing type identifies its role within the ransomware incident dataset linked to interlock. This entry provides neutral context for analysts tracking education-sector security events and associated threat actor activity. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the United States Education sector. The entity name indicates a K12 (primary and secondary education) context in New Mexico, aligning with the provided country and sector classifications. As part of a threat-intelligence index, this listing type documents the association between the entity and the threat actor interlock, contributing structured intelligence for defenders monitoring education infrastructure threats. The description remains factual and neutral, focusing on sector placement, geographic context, and the verified ransomware victim linkage to interlock without extrapolating incident details. This entry supports security teams in tracking education-sector exposure and correlating victim data with identified threat actor activity. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and located in the United States. The domain name signals a school or educational institution context, with offerings and infrastructure typically associated with student records, administrative systems, and digital learning platforms. This listing type categorizes the entity based on its association with a ransomware incident and the threat actor interlock, providing structured context for threat-researchers and defenders monitoring Education-sector exposure. The description remains factual and neutral, avoiding speculation regarding data stolen, system impact, ransom demands, or confirmed breach details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is identified as a ransomware victim entity operating within the Education sector and associated with the United States. The entity name suggests a K12 educational context in New Mexico, reflecting its sector, geographic scope, and operational environment. In the threat-intelligence index, wm.k12.nm.us is cataloged as a ransomware victim linked to the threat actor or source interlock. This listing type indicates its inclusion in intelligence records tied to ransomware activity and associated adversary attribution. The description remains neutral and avoids inventing incident details such as data stolen, records affected, ransom amounts, or confirmed breach specifics. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is associated with the Education sector within the United States, specifically categorized as a ransomware victim in the threat-intelligence index. The entity name suggests a connection to K-12 educational infrastructure, potentially representing a school, district, or educational institution operating in Nevada (NM). Its inclusion in this ransomware victim listing reflects observed threat activity targeting this sector, with interlock identified as the associated threat actor or source. This entry serves as a reference point within the threat-intelligence catalog for analysts tracking cyber incidents in educational environments across the US. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us represents an entity within the United States Education sector cataloged as a ransomware victim in the threat-intelligence index. The domain structure and sector designation indicate involvement in a K12 educational context within New Mexico, providing context for its classification and relevance to cybersecurity monitoring. This listing type identifies the entity's status as impacted by malicious activity, specifically associated with the threat actor interlock. The entry serves as a reference point for threat analysts tracking ransomware incidents across educational institutions. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is identified within the threat-intelligence index as a ransomware victim entity operating in the Education sector, located in the United States. The domain name and sector context indicate involvement within a K12 educational environment, where threat actors increasingly target institutional infrastructure for disruption and data compromise. This listing type categorizes the entity based on its association with the threat actor interlock, providing catalog users with a structured reference for risk assessment and monitoring. The description remains factual and neutral, focusing on sector, geographic context, listing classification, and the linked threat actor without asserting unverified incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector, with operational context tied to the United States and specifically New Mexico. The designation reflects involvement in an incident catalogued under the associated threat actor interlock, providing structured intelligence for security teams assessing ransomware exposure across educational institutions. The listing type emphasizes the entity's role as a victim rather than the attacker's infrastructure, ensuring clarity for analysts monitoring sector-specific cyber threats. This entry supports comprehensive threat-intelligence workflows by linking victim profiles, geographic context, sector classification, and actor attribution without disclosing unverified incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index as a ransomware victim operating in the Education sector and associated with the United States. The name indicates a K12 educational context in New Mexico, suggesting institutional or school-related infrastructure relevant to cybersecurity monitoring and threat indexing. As a ransomware victim listing, the entry documents the entity's association with threat actor interlock within the catalog, providing context for analysts tracking education-sector cyber incidents and attacker-source relationships. The description remains factual and neutral, avoiding unverified claims regarding stolen data, breach scope, ransom activity, or confirmed impact details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32679 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the Education sector, located in the United States. The entity name indicates a North American public or institutional education context, and the listing type identifies its relationship to a cyber incident involving ransomware activity. Associated threat actor and source attribution is interlock, a designated adversary reference in the threat-intelligence index. This entry provides neutral catalog context for monitoring ransomware exposure, sector-specific attack patterns, and adversary-entity linkage without disclosing unconfirmed incident details. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32680 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the United States Education sector, identified through threat-intelligence indexing. The entity name indicates a K12 educational context in New Mexico, reflecting its operational sector and geographic scope. As part of a ransomware victim listing associated with the threat actor interlock, this entry documents the relationship between the victim infrastructure and the identified cyber threat actor without disclosing unverified incident details. The catalog description maintains neutrality, focusing on sector classification, geographic attribution, listing type, and associated threat actor for analytical purposes. This information supports threat-intelligence researchers, defenders, and security teams in contextualizing ransomware activity within educational environments across the US. |
||||||
| Ransomware | Wagon Mound Public Schools id32680 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity operating within the Education sector and based in the United States. The entity name indicates a K12 (primary and secondary education) context in New Mexico, suggesting institutional infrastructure relevant to student, faculty, and administrative systems. As part of a threat-intelligence index, wm.k12.nm.us is cataloged for its ransomware-victim classification, reflecting exposure within a sector frequently targeted by cyberattacks. Its association with the interlock threat actor contextualizes the listing within broader cyber-threat intelligence reporting. This entry provides neutral catalog information for monitoring and analysis purposes. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32681 View details | United States | Education | — | ||
|
wm.k12.nm.us is associated with the US Education sector and represents a ransomware victim entity within a threat-intelligence index. The domain name indicates a K12 (primary and secondary education) context in Nevada, United States, reflecting institutional infrastructure typically targeted by cyber threats. This listing type identifies the entity as a victim of ransomware activity, with interlock cited as the associated threat actor or source in threat-intelligence records. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope or operational impact are not attributed to this entity in available intelligence. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32682 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the United States Education sector. The domain name indicates a K12 (primary and secondary education) context, with NM denoting New Mexico as the geographic region, reflecting the entity's operational footprint in U.S. educational infrastructure. As a ransomware victim, this entry documents the incident within a threat-intelligence index, highlighting exposure within critical education systems. The association with the interlock threat actor provides context regarding the threat landscape affecting this sector. This listing serves as a verified reference point for cybersecurity professionals monitoring ransomware activity in U.S. educational institutions. |
||||||
| Ransomware | Wagon Mound Public Schools id32683 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the United States Education sector. The entity name indicates a K12 educational context in New Mexico, with offerings and operational scope aligned to school or institutional education environments. As part of a threat-intelligence index, this listing type identifies affected organizations and links them to the interlock threat actor for monitoring and risk assessment. The description remains factual and neutral, avoiding invented details regarding breach specifics, data exposure, ransom activity, or confirmed incident outcomes. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32684 View details | United States | Education | — | ||
|
wm.k12.nm.us is identified within the threat-intelligence index as a ransomware victim operating in the United States education sector. The entity name references a K12 context with a New Mexico geographic indicator, suggesting institutional infrastructure serving students and educational services in that region. Its listing type categorizes it specifically as a ransomware victim, providing context for threat-researchers analyzing attack patterns, victim profiles, and associated adversary activity. The entity is associated with the threat actor or source designated as interlock, which informs the intelligence catalog regarding potential attack campaigns or attribution links. This entry neutrally states that wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32684 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within a threat-intelligence index under the ransomware victim listing type. Its designation aligns with the K12 education sector and the United States, indicating operational context within U.S. educational institutions or related systems. The entity is associated with the threat actor interlock, providing intelligence linkage for monitoring ransomware activity across education infrastructure. No specific incident details, breach confirmations, data exfiltration claims, or financial impact are asserted in this catalog entry, preserving factual neutrality. This listing serves cybersecurity stakeholders by documenting the ransomware victim entity, its sector and geographic context, and its connection to interlock within the intelligence index. |
||||||
| Ransomware | Wagon Mound Public Schools id32686 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity within the US Education sector identified as a ransomware victim in the threat-intelligence index. The naming convention suggests a school or educational institution operating in New Mexico, serving K12 educational contexts. As a ransomware victim associated with the threat actor interlock, this listing documents the entity's involvement within a cyber threat landscape analysis. The entry provides context for monitoring educational infrastructure vulnerabilities and attacker targeting patterns. This catalog entry remains a factual record of the entity's classification without disclosing unverified incident specifics. |
||||||
| Ransomware | Wagon Mound Public Schools id32687 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim within the United States Education sector. The entity name indicates a school or educational institution context, with NM denoting New Mexico as its geographic area. As part of the threat-intelligence index, it is associated with the threat actor interlock, reflecting the ransomware-related exposure profile of this organization. The listing provides neutral, factual context for analysts tracking education-sector security incidents and adversary activity across US jurisdictions. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32688 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index under the ransomware victim listing type. Its designation aligns with the Education sector and the United States, reflecting operational context typical of educational institution infrastructure assessed in cyber threat analysis. The entity serves as a reference point for threat actor interlock activity within this catalog, providing structured context for security researchers and defenders monitoring ransomware-related incidents across US education environments. This entry neutrally states that wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us represents an entity within the United States Education sector cataloged as a ransomware victim in a threat-intelligence index. The domain name indicates a K12 (primary and secondary education) context, with NM suggesting New Mexico geographic relevance, aligning with the specified country and sector. This listing type identifies the entity as having experienced a ransomware incident associated with the interlock threat actor. The description remains neutral regarding specific incident details, as confirmed specifics such as data exfiltration scope or operational impact are not provided in available intelligence. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the Education sector and based in the United States. The domain notation indicates a school or educational institution context in New Mexico, reflecting its sector classification and geographic scope. This listing type identifies the entity as having been impacted by ransomware activity associated with the threat actor interlock. The description remains factual and neutral, focusing on the entity's classification, sector, location, and the verified association with the specified threat actor without disclosing unconfirmed incident details. It serves as a reference point in the threat-intelligence index for monitoring ransomware-related activity within educational infrastructure. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity cataloged within a threat-intelligence index as a ransomware victim operating within the US Education sector. The identifier reflects a North American public school or educational institution context, with offerings and infrastructure typical of K-12 systems managing student records, administrative data, and network services. This listing type classifies the entity based on observed threat activity associated with the interlock threat actor, highlighting its role within cybersecurity intelligence monitoring frameworks. The description remains neutral regarding specific incident details, as confirmed specifics are not publicly attributed to this entity in official records. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us is a catalog entity representing a ransomware victim within the United States Education sector. The domain name indicates a K12 (primary and secondary education) context associated with New Mexico, reflecting the geographic and sector classification used in threat-intelligence indexing. This listing type identifies the entity as having been affected by ransomware activity, with interlock cited as the associated threat actor or source in the intelligence index. The description remains neutral regarding specific incident details, as confirmed specifics such as data scope or operational impact are not attributed to this entity in the provided context. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity within the United States Education sector. The domain name and context indicate a school or educational institution located in New Mexico, serving K12 education environments and providing digital learning, administrative, and student services. As cataloged in the threat-intelligence index under the ransomware victim listing type, wm.k12.nm.us is associated with threat actor interlock. This entry contributes contextual intelligence regarding ransomware exposure patterns in education infrastructure across the US, supporting risk assessment and defensive monitoring. The description avoids inventing confirmed breach details, incident specifics, data losses, or financial impact while maintaining neutral, authoritative catalog language. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us is cataloged as a ransomware victim entity within the United States Education sector. The domain name indicates a school or educational institution context, commonly associated with K-12 environments in New Mexico, where cybersecurity incidents can significantly disrupt learning operations and institutional services. This listing type identifies the entity as having been affected by ransomware activity and is associated with the threat actor interlock. The entry serves as part of a threat-intelligence index to document victim profiles and attacker connections for risk assessment and defensive awareness. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32691 View details | United States | Education | — | ||
|
wm.k12.nm.us is a ransomware victim entity operating within the United States education sector. The domain name indicates a K12 educational context in New Mexico, with offerings or presence associated with school-based infrastructure and institutional services. This entity is cataloged in the threat-intelligence index as a ransomware victim linked to the threat actor interlock. The listing provides intelligence context regarding the affected organization's sector, geographic location, and the adversary association without disclosing unverified incident details. It serves as a reference point for monitoring ransomware activity within U.S. education environments. |
||||||
| Ransomware | Wagon Mound Public Schools id32692 View details | United States | Education | — | ||
|
wm.k12.nm.us is an entity identified within the threat-intelligence index under the ransomware victim listing type. Operating within the Education sector and associated with the United States, the entity represents a school or educational institution context where cybersecurity incidents may be cataloged. Its inclusion reflects threat-intelligence analysis correlating the entity with the interlock threat actor profile, providing context for defensive monitoring and sector-specific risk assessment. The description remains neutral regarding specific incident details, as confirmed specifics are not attributed here. wm.k12.nm.us was listed as a ransomware victim associated with interlock. |
||||||
| Ransomware | Wagon Mound Public Schools id32692 View details | United States | Education | — | ||
|
wm.k12.nm.us operates within the United States education sector, serving as a catalog entry representing a ransomware victim within the threat-intelligence index. The entity name indicates its classification within a K12 (primary and secondary education) context in Nevada, reflecting its sector and geographic relevance. As a ransomware victim listing, this entry documents the association with threat actor interlock for threat-aware analysis and infrastructure risk assessment. The description adheres to neutral, factual reporting standards without disclosing unverified incident details such as data exfiltration scope, ransom demands, or specific breach timelines. This entry supports cybersecurity teams in tracking education-sector vulnerabilities and correlating victim profiles with identified threat actors. |
||||||