logo

FBI urges vigilance against Interlock ransomware group behind recent healthcare attacks

ID: f33c8e37-f761-54a1-9cb6-97c472ea33d2

STIX ID: report--f33c8e37-f761-54a1-9cb6-97c472ea33d2

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-07-22

Date Updated: 2026-05-01

...
...

The Interlock ransomware group, active since late September 2024, is targeting critical infrastructure and businesses across North America and Europe — notably causing outages at a dialysis provider and a major Ohio healthcare system. Federal agencies (FBI, CISA, HHS) warn Interlock uses drive-by downloads, fake browser updates, and ClickFix social engineering to gain access, employs info stealers (Lumma, Berserk) to harvest credentials, operates Windows and Linux encryptors, and demands Bitcoin with contact-only ransom notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.