Interlock is a ransomware group targeting critical infrastructure with double-extortion tactics.
Analyst brief
Interlock is a ransomware group first observed in September 2024, employing double-extortion tactics against critical infrastructure. They primarily target Healthcare, Government & Defense, Manufacturing, and Education sectors in the United States, Canada, and Australia. The group is known for operating a data-leak site and has claimed over 57 victims, with one incident exposing over two million patient records. Defenders should focus on network segmentation, immutable offline backups, and monitoring for anomalous data exfiltration to detect pre-ransomware staging.
interlock
activecrime
Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.