Skip to main content

Feds Warn Health, Other Sectors of Interlock Threats

Errol Weiss, Chief Security Officer at Health-ISAC, quoted on actionable sector-specific threat intelligence.

Healthcare Providers Are Among Dozens of Entities Hit Since Gang Emerged in 2024

The Health Information Sharing and Analysis Center has observed 51 Interlock attacks against all sectors since the group appeared in the last quarter of 2024, with seven of those targeting healthcare, said Errol Weiss, chief security officer at Health-ISAC.

“Interlock is particularly concerning because, beyond ransomware encryption, they routinely engage in data theft and data extortion. This double-extortion model significantly increases the risk to patient privacy and regulatory compliance,” he said.

“With Interlock’s primary focus on the health sector, defense industrial base and other critical infrastructure sectors, their attacks have high potential for disrupting critical services and directly impacting patient safety and clinical continuity.”

Weiss strongly encourages organization to implement critical security best practices and controls, including multi-factor authentication for all critical accounts, privileged users, virtual private networks and email systems.

Stay up to date on patches, back up critical systems and test the backups, actively participate in information-sharing communities to stay informed about emerging threats, develop and regularly test an incident response plan; and provide ongoing cybersecurity awareness training to staff, he advised.

“This situation underscores the immense value of timely, peer-to-peer threat intelligence communities like Health-ISAC, where incident details from a victim were shared, which then provide crucial information for network defenders to proactively block and detect malicious activity,” he said.

“While government alerts are helpful for broad awareness, sector-specific ISACs often provide more granular, actionable intelligence sooner.” Health-ISAC and the American Hospital Association in May issued a joint advisory about Interlock for their members with known indicators of compromise, he said.

Read the article in Data Breach Today. Click Here