ZeroHour

interlock

ransomware group · aka Interlock, Interlock ransomware · unknown · active since 2024-09

Victims · 7d
2▲1 vs prev. week
Victims · 30d
5active targets
Victims · 90d
16
All-time (tracked)
126since 2024-10-14
Last post
09-15 20:33UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Interlock is a ransomware and data-extortion group first documented by vendors in September 2024 (Trend Micro, 2024). It is notable for fielding encryptors for Windows, Linux, and FreeBSD, including use against NAS appliances, and for being among the first ransomware operations to adopt the 'ClickFix' fake CAPTCHA/browser-update social-engineering chain (Sucuri, 2024). Vendor research in 2025 documented a Rust-based Interlock RAT used alongside the encryptor, with later versions hiding configuration in images. No public attribution to a country or named leadership is available. Public victim reporting is limited; the group has been linked to the City of West Plains, Texas DOT, and, per this dashboard's tracking, NFM Lending (posted 2026-09-07).

Tactics & tooling
  • ClickFix social engineering: fake 'verify you are human'/CAPTCHA or fake browser-update prompts on compromised websites trick users into running PowerShell commands that fetch the payload (Sucuri, 2024).
  • PowerShell-based delivery chains using Invoke-Expression and attacker-controlled download URLs.
  • Multi-platform encryptors for Windows, Linux, and FreeBSD; deployed against NAS devices such as QNAP and Synology (Trend Micro, 2024).
  • Rust-based Interlock RAT deployed for post-access operations alongside ransomware; 2025 versions reportedly hide configuration in images via steganography (vendor research, 2025).
  • Double extortion: steals data pre-encryption and threatens publication on a Tor leak site.
  • Targets internet-exposed servers and appliances; no widely reported reliance on specific CVE exploitation for initial access.
  • Reconnaissance and data staging on compromised servers before encryption and leak-site posting.
Targeted sectors
government (municipal and state agencies)healthcarefinancial servicestechnology/IT services
Notable public victims

Devon International Group (US conglomerate; listed on Interlock leak site, October 2024), City of West Plains, Missouri (confirmed ransomware attack, November 2024), Texas Department of Transportation (incident confirmed by TxDOT; Interlock claimed ~35 GB of stolen data, May 2025), NFM Lending (listed on Interlock leak site, per this dashboard's tracking, 2026-09-07)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Springfield Public Schools · 54m agohttps://www.springfieldpublicschools.com/ Springfield Public Schools in Springfield, Massachusetts, is the third-largest school district in the state, with over 23,500 students and over 4,200 full-time employees. The school budget accounts for more than two-thirds of the city's total budget, which is approximately $700 million. Yet, they fail to ensure student safety and do nothing to address this problem. As a result, their negligence has led to a major breach of student and employee data. Extensive student databases are now available, containing last name, first name, student number, enrollment status, grade level, home address, home phone number, and ethnicity. You also have access to more than 10,000 company contacts, incident databases, phone records, and medical information. This raises the question: where are the allocated funds going? Why aren't they keeping their students safe?
City of Fort Smith Arkansas · 3h agohttps://www.fortsmithar.gov/ The City of Fort Smith is committed to providing high-quality, resident-focused services to foster a thriving community. This is how they try to position themselves, but in reality, they are very negligent towards their residents and organizations within the city due to their negligent attitude towards security and lack of desire to solve problems, were compromised resulting in a major leak of confidential data over 5.6 TB of data, which includes key infrastructure facilities of Fort Smith (Public Safety System: Police Station, Fire Department, Communications Center (responsible for the 911 emergency dispatch service), Water System: including numerous water and sewer treatment plants, Information Systems: computer systems and networks that support the operation of various departments of the city). As a result of a major leak of the city, you are provided with databases and documents of all their structures (Police and Crime Information: The Arkansas Crime Information Center and the FBI Criminal Justice Information Service system are available information on license plates and driver's licenses, Confidential law enforcement data, such as personally identifiable information (PII), such as Names, addresses, and phone numbers of residents.) More than 100,000 SSNs, reports and police station files with photos from the reports, as well as software used by cyberpolice to work with phone data, as well as reports and dumps of people's phones, and most importantly, their data on the water supply system and a complete database of 911 calls and incidents.
NFM Lending · 8d agohttps://nfmlending.com/ NFM Lending is a national mortgage lender with over 1,000 employees that originated approximately $7.15 billion in mortgages in the past 12 months. The data breach exposed over 2.5 TB of sensitive personal customer information (names, Social Security numbers, bank accounts, credit information, loan terms, addresses, phone numbers, email addresses, borrower and loan identifiers, loan pricing, and itemized loan expense reports), as well as proprietary pricing/profit formulas, in violation of federal GLBA/FCRA, state privacy laws, and the CFPB's data breach reporting rules. You also have access to data from the Encompass database, which contains information on more than 1 million clients, as well as internal databases, an extensive database of tax forms, and employees' personal information.
Super Systems Inc · 15d agohttps://supersystems.com/ Super Systems, Inc. develops and manufactures products for the heating industry. However, it is extremely negligent in its own security and that of its customers, resulting in data breaches. You can view documents revealing confidential control schemes and vulnerabilities in customer systems, SSi's entire client portfolio, and confidential financial information about outstanding customer accounts, which undermines trust and damages the company's reputation. You are also provided with a list of over 500 customers with their contact information and price lists for products and services. You are also provided with SSi's intellectual property, a full suite of software for process control, data collection, analysis, and product tracking.
Southeastern Oklahoma State University · 27d agohttps://www.se.edu/ Southeastern Oklahoma State University is a public, four-year university located in Durant, Oklahoma. A data breach exposed student educational records (including names, contact information, Social Security numbers, grades, enrollment data, financial aid information, disciplinary records, and medical information contained in educational records). This breach violates the Family Educational Rights and Privacy Act (FERPA), the HIPAA Privacy Rule, and students' common-law privacy rights. The breach affected employee personal data and injury information, including employee name, date of birth, date of injury, as well as Social Security number, Medicare card, and child custody/consent status. More than 90,000 student names, Social Security numbers, and student identification numbers, as well as Forms 1095-C and more than 490 documents.
Connell Enterprises LLC · Aug 14, 2026He performs system administration for domain networks but is unable to ensure his own security. As a result, his data was compromised, and he was caught distributing pornographic content, storing over 200 terabytes of pornographic data on his network-attached storage (NAS). He administers pornographic websites and publishes content there, creates content featuring real people and sells it for money, and engages in blackmail by generating pornographic content using artificial intelligence. He finds victims and demands money from them. Various victims, including minors, as well as prominent public figures and political figures, including President Donald Trump, have been discovered in his computer files. Law enforcement is advised to pay attention to this individual as he is a sexual predator and distributor of pornography. You can view his directory structure, browser profiles, and saved HTML pages, where you can read his 4chan correspondence and much more.
AngMar Companies · Aug 11, 2026https://www.angmarcompanies.com/ AngMar is a private organization comprised of numerous corporate holdings, LLCs, and companies, operating a network of home health care facilities. They disregard the safety of their clients and the people they care for. As a result, 710 GB of confidential information about the companies they serve has been exposed. Most importantly, patient data has been leaked, including their medical records, medical histories, personal information such as Social Security numbers, home addresses and phone numbers, and much more.
Gardiner Family Chiropractic · Jul 31, 2026https://www.gardinerfamilychiropractic.com/ Gardiner Family Chiropractic has been providing medical services to residents of Gardiner and the surrounding area since 1989. However, it is not responsible for its patients and makes no attempt to ensure the security of its stored information. Therefore, patient data, client records, medical histories, and internal company financial information have been compromised and are being made available to you.
Centre for Newcomers · Jul 17, 2026https://www.centrefornewcomers.ca/ The Newcomers Center provides immigration services aimed at supporting newcomers and creating a welcoming community. They maintain complete information about their clients in their databases, but they fail to ensure the security of this data. Due to their negligence toward their clients and employees, this data has been compromised. We offer you 380 GB of personal client data, company financial information, its current status and reporting, and human resources planning and policies.
Paragon Store Fixtures · Jul 17, 2026https://paragonstorefixtures.com/ Paragon Store Fixtures specializes in custom display cases, retail fixtures, and interior design elements for luxury stores, beauty salons, offices, restaurants, and entertainment venues. A security breach resulted in the breach of partnership agreements, resulting in the intellectual property of both the company and its clients. Internal design files were exposed, including work completed for clients in the high-end retail sector and luxury brands. Due to the company's negligence, contracts, architectural plans, and confidential design documentation became public. The identities of clients and projects have now been revealed.
District of Columbia Housing Authority · Jul 17, 2026https://www.dchousing.org/ DC Housing, the organization entrusted with the powers of the District of Columbia Housing Authority, was completely compromised due to its negligence and greed in security, and all confidential information, databases, passports, and personal data of clients were stolen. We offer you 1.6 TB of confidential information, including all data of District residents and large databases.
Converting Equipment International · Jul 16, 2026https://www.slitandrewind.com/ CEI's mission is to produce high-quality equipment for the manufacturing industry through innovation, collaboration, and integrity. However, the company has a history of neglecting its own security, putting its customers and employees at risk. This negligence has resulted in the leakage of confidential information and personal data. We provide confidential information regarding equipment development, contracts, and customer relationships. We also have information about their subsidiaries and their entire financial structure.
Borger ISD · Jul 10, 2026https://www.borgerisd.net/ Borger Independent School District serves approximately 2,500 students on six campuses in Hutchinson County, Texas. The district fails to foster a collaborative environment for students, parents, and the community. They are not responsible or committed to ensuring the security of your data. This is not the first time they have neglected their students, with confidential information about staff, students, and their parents, as well as all incidents, the district's financial situation, and other information they concealed, leaking online. We offer you 330 GB of this information.
YMCA of Western North Carolina · Jul 7, 2026https://www.ymcawnc.org/ The YMCA of Western North Carolina operates seven fitness centers, a summer camp, dozens of food trucks, youth sports programs, and many other initiatives. They are also the state's largest provider of licensed school-age childcare. However, they don't ensure security and aren't responsible for it, and you can gain access to confidential client information (complete sets of documents, even fingerprints), contracts, and incidents (of which they have many!), as well as to employee personal data and financial documents.
Clearview Eye Centre · Jun 25, 2026https://www.clearvieweyecentre.com Clearview Eye Centre is a state-of-the-art ophthalmology clinic run by doctors Faisal Adatia and Ryan Yau in Calgary, Alberta. They disregard security regulations and medical confidentiality, show no respect for their clients' privacy, and make no attempt to protect the information stored in their databases. Their practices are extremely lax, resulting in client information including medical records, personal data, incident reports, and financial and tax information being exposed to you.
Reynella East College · Jun 23, 2026https://www.reynellaec.sa.edu.au/ Reynella East College is an innovative educational institution offering a comprehensive curriculum for students from preschool to 12th grade. However, the school failed to adequately protect the privacy of its students and staff and made no attempt to do so, resulting in the leak of their sensitive personal data online. We are providing you with 600 GB of interesting files and documents, including contracts, financial reports, personal data, student and staff identification numbers, seating charts, and much more.
Cold Front Distribution · Jun 2, 2026https://coldfrontdist.com/ Cold Front Distribution is a leading DSD supplier specializing in grocery and foodservice supply chain solutions across a fifteen-state region. Due to their negligence in the area of security, we are providing you with a complete set of confidential documents, specifically the pricing grids of major partners sold through the Cold Front system, discount agreements, information on new product launches, and other confidential partner documents, as well as personal information about employees and the companys financial status...
Kent District Library · May 12, 2026https://kdl.org/ Kent District Library (KDL) is a public library system that owns and operates libraries throughout Michigan. However, it does not manage its own security, which is damaging its reputation. We are providing you with confidential financial documents, contact information for organizations, personal data on customers and employees, building plans and blueprints, as well as information about various incidents that they are concealing.
Park Dental Research · May 12, 2026https://shop.pdrus.com/ Park Dental Research is a supplier of technologies and materials for dental laboratories and orthodontic clinics; however, when it comes to security, it has proven to be an unreliable partner. As a result of its negligence, partner and customer data, financial documents, and login credentials for various web resources were compromised and made publicly available on the Internet.
Waterford Hotel Group · May 12, 2026https://waterfordhotelgroup.com/ Waterford Hotel Groupa company that manages hotels and conference centersfailed to implement adequate security measures, resulting in a data breach. We are providing you with a dataset containing information about the hotel chain and its other divisions, including personal and confidential data, partner contact information, and financial information.
First United Methodist Church Boerne · May 12, 2026https://fumc-boerne.org/ The First United Methodist Church in Bern offers a variety of programs for all age groups, including preschool, childrens, youth, and adult ministries. However, it does not ensure the protection of your personal data and does not seek to protect it; due to its negligence, there has been a leak of personal data including phone numbers, email addresses, and home addresses of staff, parishioners, and children attending the church, as well as financial and other confidential documents.
Lonestar Truck Group & Tag Truck Center · May 4, 2026https://www.tntxtruck.com Lonestar Truck Group consists of multiple dealerships that sell new and used trucks and trailers, as well as providing service and parts. They work with a vast number of customers and businesses, yet they have failed to prioritize security. As a result, personal data of employees, contact information for the companies they work with, and a significant number of customer records have been leaked online. We are also presenting their confidential and financial documents for your review.
Winona County · Apr 29, 2026https://www.winonacounty.gov/ Winona County is located in the Mississippi River blufflands of southeastern Minnesota. They have been negligent regarding security and the data they store, which has resulted in a breach and the public disclosure of all the confidential data they held. As a result, we are now able to offer you a large database containing resident records, tax and budget documents, police records, and data from other institutions.
Uniwersytet Warszawski · Apr 15, 2026https://www.uw.edu.pl The Faculty of Management at the University of Warsaw is a leading institution in the field of business education, offering a wide range of undergraduate and graduate programs that combine theory with practical experience. However, it is not known for its high level of security and data storage reliability, resulting in the leak of data on students, instructors, and leading professors, as well as student projects and papers.
Community College of Beaver County · Apr 3, 2026https://ccbc.edu The college serves a diverse student body, including recent high school graduates, adult learners, and those seeking career advancement. By focusing heavily on workforce development but neglecting its security, the college compromised hundreds of records containing personal and confidential information, as well as financial documents, projects, and contracts, which were subsequently leaked to the public.
The Center for Hearing & Speech · Apr 2, 2026https://thecenterforhearingandspeech.localsearch.com The Hearing and Speech Center provides comprehensive services in hearing diagnostics, speech therapy, and screening for people of all ages. However, it is not responsible for the security of your personal data; as a result of their negligence, a large amount of personal data belonging to clients and employees, as well as their confidential information, projects, and incident reports, was leaked online.
Goodwill · Mar 26, 2026https://goodwillinc.org Goodwill Industries of North Central Pennsylvania is dedicated to turning donations into jobs, providing employment for more than 700 people across 15 counties in Pennsylvania and one county in New York. However, they have been extremely negligent and irresponsible regarding security, resulting in the compromise and online leak of hundreds of pieces of personal data belonging to employees and partners, as well as financial documents.
Delta Manufacturing · Mar 18, 2026https://www.deltamfg.com Delta Manufacturing specializes in custom electric heating elements. They serve a variety of industries, including aerospace, medical, food, and chemical, ensuring fast turnaround of custom orders. However, they failed to prioritize security, resulting in the compromise of customer and employee data and contracts, as well as the exposure of all accounting records and invoices.
Elliott-Lewis · Mar 11, 2026https://elliottlewis.com Since 1905, Elliott-Lewis Corporate has provided comprehensive solutions for maintenance, repair and operations, engineering, design, installation, and energy consumption. In addition, Elliott-Lewis' Facilities Management team provides individual on-site operations management but does not provide security to its customers, resulting in a large database of confidential contracts and projects, as well as personal customer and employee data.
Wagon Mound Public Schools · Mar 9, 2026https://www.wm.k12.nm.us Wagon Mound Public Schools provides education to students in the Wagon Mound area, providing resources and support for both elementary and middle schools. However, they neglected to address the security of their materials, resulting in the compromise of all their personal data, including the school's blueprints. We present to your attention a 80 GB of data, which includes staff and student information, their phone numbers, residence addresses, and passport numbers.
Abbott Media Productions · Feb 16, 2026https://abbottanimation.com Abbott Media Productions, based in Tucson, Arizona, specializes in 3D animation, technical animation, and a full range of video production services. They provide animation services and interactive applications, incident reenactments, product animation, and motion graphics. Their primary clients include government agencies, defense contractors, and commercial organizations.
Yew Tree Dairy · Feb 16, 2026https://yewtreedairy.co.uk Yew Tree Dairy is a family-owned business that has been supplying dairy products since 1904. The product range includes fresh milk, cream, and milk powder, primarily targeting wholesalers and retailers.
Archaeological Institute of America · Feb 13, 2026https://www.archaeological.org Founded in 1879, the Archaeological Institute of America (AIA) is the oldest and largest archaeological organization in North America. Today, the AIA has over 200,000 members and 110 local societies in the United States, Canada, and abroad.
Odyssey Academy · Feb 1, 2026https://www.odyssey-academy.com Odyssey Academy is a free public charter school. This school educates and prepares children for adulthood, but a large amount of data has become publicly available due to the disrespectful and negligent attitude of its staff and administration. As a result, student and staff data and the school's records, including full financial reports and other confidential documentation, have been compromised.
Urban Edge Architecture · Jan 29, 2026https://www.urbanedgearchitecture.co.uk Urban Edge Architecture is a Stamford-based architectural firm specializing in the development of sustainable, resilient, and feasible projects across a diverse portfolio. Their services span a variety of sectors, including retail, residential development, landscape design, and residential fit-out.
RGD Consulting Engineers · Jan 7, 2026https://www.rgdengineers.com RGD Consulting Engineers is a full-service engineering firm specializing in mechanical, electrical, plumbing, and structural design, based in Florida. RGD is focused on providing engineering solutions, exceptional customer service, and cost-effective systems. Serving a variety of markets throughout Florida, the United States, and the Caribbean, RGD collaborates closely with its clients.
Westlake Christian Academy · Jan 7, 2026https://www.westlakechristianacademy.org Westlake Christian Academy is a private Christian school located in Grayslake. Due to security issues, its database, including its entire student list and staff information, was made publicly available. The staff at this institution exhibits extreme indifference and inappropriate behavior toward its students and staff.
Aero Fabrications · Jan 6, 2026https://www.aerofabrications.co.uk Aero Fabrications Ltd specializes in the manufacture of aerospace components, with over 30 years of experience. They partner with leading aerospace companies such as Airbus and BAE Systems. However, due to poor security and employee negligence, all data and databases were compromised and leaked publicly. This included customer, employee, and company data, as well as contracts and, most importantly, confidential drawings.
Apex Spine and Neurosurgery · Jan 6, 2026https://www.apexspineandneuro.com Apex Spine and Neurosurgery specializes in the comprehensive neurosurgical treatment of spinal and cranial disorders. The team consists of neurosurgeons who offer treatment options, including minimally invasive spine surgery, tailored to the needs of their patients. They serve patients from across Georgia, particularly Atlanta, and emphasize a patient-centered approach. Their services cover a wide range of conditions, including back pain, brain tumors, and trauma.
Hunneman · Dec 31, 2025htpps://www.hunnemanre.com/ Hunneman, founded in Boston in 1929, is a real estate firm that offers a full range of real estate brokerage, leasing investment sales, and management services.
The Salvation Army · Dec 24, 2025https://www.salvationarmy.org The Salvation Army, established in 1865, has been offering an array of social services that range from providing food for the hungry, relief for disaster victims, assistance for the disabled, outreach to the elderly and ill, clothing and shelter to the homeless and opportunities for underprivileged children.
Swartz Campbell · Dec 22, 2025https;//www.swartzcampbell.com Swartz Campbell LLC is a law firm with multiple locations across the East Coast specializing in areas including class action, employment, medical malpractice, and divorce. The law firm was founded in 1921 and is headquartered in Philadelphia, Pennsylvania.
Clarksville ISD · Dec 19, 2025https://www.clarksvilleisd.net Once again, we see how a certain school organization, Clarksville ISD, was attacked and compromised due to the negligence and irresponsibility of employees with other people's data, that is, other people, as a result of which a large amount of confidential data was compromised, including the SNN of all students for the entire year, as well as all employee data, including SNN, banking transactions, and financial components.
Print-O-Tape · Dec 15, 2025https://www.printotape.com Print-O-Tape, Inc. is a manufacturer specializing in self-adhesive labels, offering a wide range of products including custom labels, stock labels, RFID labels, and roll materials. The company has established strong relationships with well-known end users, resellers, and OEMs, providing labeling solutions. Their commitment to innovation and technology allows them to remain an industry leader, serving markets such as transportation, warehousing, food and beverage, and consumer goods. Print-O-Tape, Inc. manufactures and supplies self-adhesive labels to customers worldwides.
Computing Dynamics · Dec 9, 2025https://www.cdisoftware.com Computing Dynamics Inc is a company that develops custom software and provides IT services. In other words, this company operates in the IT sector and yet manages to make stupid mistakes in its work. As a result, it fell victim to an attack and a large amount of confidential data was compromised! This included data about clients, employees, and the company itself. Names, phone numbers, addresses, and a lot of personal information were compromised!
Fargo Park District · Dec 5, 2025https://www.fargoparks.com Fargo Park District, with over 2,100 acres of land, is divided into Finance, Enterprise, Events, Operations, Programming and Facilities, Human Resources, Valley Senior Services and Courts, and Community Physical Activity. The Fargo Park District boasts over 150 parks, amenities, and over 170 kilometers of trails and paths.
Providence Academy · Dec 3, 2025https://www.providenceacademy.org Providence Academy was established as a private Christian school. The institution's staff demonstrated a disregard for their own security and that of all their students. As a result, all student databases were accessed, revealing all personal information, including SSNs. The most unsafe and unsafe job was the Chief IT Director! This is simply nonsense! Numerous financial documents and confidential employee data were also leaked.
Issaqueena Pediatric Dentistry · Nov 25, 2025https://www.issaqueenadental.com Isaquenna is a medical center where people get dental treatment and leave their confidential data. Due to its low security, Isaquenna suffered a data breach involving its patients' phone numbers, addresses, SSNs, and personal information such as images, medical histories, and the entire history of the clinic.
Westrian Group · Nov 24, 2025https://www.jrengineering.com JR Engineering provides services in land management, surveying, land transportation, water resources, and structural design! This company was compromised due to extremely poor security and a weak IT department. Client databases were lost, including confidential contracts with clients and more! All of the company's current sketches and models are now publicly available, which could ruin its reputation and financial position!
Aptura Group & Central Indiana Hardware · Nov 7, 2025https://www.apturagroup.com & https://www.cih-inc.com Central Indiana Hardware - Produces custom access systems, space management solutions, and high-performance hardware to optimize the security and functionality of commercial spaces. APTURA GROUP is a wholly employee-owned company specializing in innovative solutions and services in the door hardware and security systems industry. Working with several leading brands, including Central Indiana Hardware (CIH), APTEK, Security Builders Supply, and HG/Schultz Door, we have built our reputation on precision, efficiency, and exceptional customer service that consistently exceeds expectations. CIH helps the company work more productively.

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .