While known for healthcare breaches, the gang primarily launches opportunistic attacks using sophisticated social engineering.

On July 22, 2025, the FBI and other U.S. federal agencies issued a public alert regarding Interlock, a ransomware group that has been active since September 2024. The cybercriminal organization has targeted entities across North America and Europe, including DaVita, a major U.S. dialysis provider, and a large healthcare network in Ohio.

Despite several high-profile attacks on the healthcare sector, the FBI assesses that Interlock does not prioritize any specific industry. Instead, it focuses on opportunistic campaigns and is known for its unconventional intrusion methods, including drive-by downloads and advanced social engineering tactics. The group has also been observed distributing malicious browser update pop-ups to infect systems.

Cybersecurity analysts have identified possible ties between Interlock and Rhysida, another ransomware group active in similar regions.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.