SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
█ Ransomware ANGMAR-COMPANIES-I 2026-08-12

AngMar Companies: Interlock Ransomware Data Extortion Claim

"The Interlock ransomware operation has claimed an attack on healthcare provider AngMar Companies, alleging the theft of roughly 710 GB of medical and patient data and posting the victim to its leak site. The claim…"

The Interlock ransomware operation has claimed an attack on healthcare provider AngMar Companies, alleging the theft of roughly 710 GB of medical and patient data and posting the victim to its leak site. The claim surfaced on August 12, 2026, and was reported by Undercode News, which attributed it to a report circulating on X from the account Cybersecurity News Everyday. Undercode News states plainly that the 710 GB figure and the contents of the dataset have not been independently verified, and at the time of writing no statement from AngMar Companies, no regulatory filing, and no established security outlet has corroborated the claim. What can be corroborated is the actor: Sophos, whose incident response teams have worked Interlock intrusions directly, confirms the group is an active double extortion operator with a documented appetite for healthcare targets.

What Happened

The public record on this specific incident is thin and rests on a single OTHER-tier source. According to Undercode News, Interlock added AngMar Companies to its extortion infrastructure and claimed approximately 710 GB of exfiltrated data, described as including patient medical records, medical histories, Social Security numbers, home addresses, and telephone numbers. That outlet's own reporting is explicit that it is relaying a third-party social media report rather than confirming the breach.

Treat the 710 GB number as an attacker assertion, not an audited figure. Leak site volumes are marketing copy written by extortionists to pressure a victim into paying, and they routinely include duplicated files, system artefacts, and backup images that inflate the headline total. The pattern is consistent with how Interlock has behaved elsewhere: HIPAA Journal reports the group claimed 260 GB from Park Dental Research Corporation in Oklahoma following an April 29, 2026 incident, and both HIPAA Journal and Paubox report a 540 GB claim against the Texas Hearing Institute in Houston, added to Interlock's dark web leak site in early April 2026. Claimdepot, tracking the same Texas case for class action purposes, dates the Interlock posting to April 2, 2026.

Those earlier cases are instructive on timing. Texas Hearing Institute discovered suspicious activity on March 20, 2026, concluded its forensic investigation on April 22, finalised its data review on June 19, and published notice on June 26, according to Paubox and Claimdepot. Interlock had already posted the victim publicly on April 2, roughly three months before the organisation notified anyone. If AngMar Companies follows the same arc, formal notification and a real affected-individual count are likely months away.

What Was Taken

For AngMar Companies, the only description available is Interlock's own: about 710 GB spanning patient medical records and histories alongside direct identifiers including Social Security numbers, residential addresses, and phone numbers. No source has published a count of affected individuals, and none has confirmed the data is genuine.

The comparable Interlock healthcare cases give a sense of what actually gets confirmed once the forensics land. At Texas Hearing Institute, the verified exposure covered names, Social Security numbers, financial account information including credit and debit card numbers, and medical records, affecting 29,498 Texas residents per the notification to the Texas Attorney General. HIPAA Journal notes it remains unclear how many individuals were affected in total, since that figure counts only one state. At Park Dental Research, the confirmed set was employee-focused: names, dates of birth, addresses, Social Security numbers, driver's license numbers, bank account information, passports, and I-9 forms.

The sensitivity point Undercode News makes is the correct one. A compromised password is rotated in seconds and a card is reissued in days. A Social Security number tied to a diagnosis history is a permanent record that fuels medical identity theft, insurance fraud, and targeted social engineering for the rest of a patient's life, and for pediatric patients, which is who a provider like Texas Hearing Institute serves, that exposure window can run for decades before the victim ever applies for credit.

Why It Matters

Interlock is not an opportunistic nuisance. Ransomnews notes the group earned a joint CISA, FBI, HHS and MS-ISAC #StopRansomware advisory, AA25-203A, in July 2025, less than a year after it surfaced in September 2024. HHS co-signing an advisory is a direct signal about which sector the group is hunting in.

The sources disagree on Interlock's business model, and the disagreement matters for defenders. Paubox describes Interlock as a ransomware-as-a-service platform that sells tooling to affiliates for a cut of up to 20 percent of profits. Sophos, which tracks the group as GOLD EMBRACE and has investigated its intrusions first-hand, states the opposite: Interlock appears not to operate as RaaS but as a small, dedicated team that develops its own malware and runs its own attacks. On weight of evidence the Sophos assessment should be preferred. The practical implication is that Interlock intrusions will look consistent from victim to victim rather than varying wildly by affiliate skill, which makes their tradecraft worth hardening against specifically.

Scale is also worth calibrating. The Ransomnews tracker logged 10 confirmed Interlock victims in 2026, which is modest volume for a group with this profile. Interlock is running a low-count, high-value campaign, not a spray. Sophos places its current focus on North American and European critical infrastructure, healthcare, and education, and Paubox notes prior US victims including Kettering Health and DaVita.

The Attack Technique

No initial access vector has been reported for the AngMar Companies incident. The group's established playbook, however, is well documented across the primary and outlet reporting.

Interlock's signature entry method is ClickFix, described by Ransomnews as social engineering that turns the user into the delivery mechanism. A victim lands on a compromised or malicious website, is shown a fake CAPTCHA or error message, and is instructed to "fix" it by pasting a supplied command into the Windows Run box or a terminal. That command pulls the payload. A later variant, FileFix, changes the lure but keeps the principle of masking a malicious action behind legitimate-looking activity, sidestepping many endpoint and network controls. By mid-2025 the FBI tied Interlock to a PHP-based variant riding the wider KongTuke FileFix campaign. Paubox notes the FBI has characterised the group's tactics as "uncommon," citing drive-by download delivery.

Post-compromise, Sophos documents a custom remote access trojan tracked as NodeSnake or Interlock RAT, a PHP-based backdoor for cross-platform persistence, and targeting of both Windows and FreeBSD systems. Ransomnews adds that Interlock has built Windows and Linux encryptors including variants that specifically target virtual machines, putting it in the same bracket as the ESXi-hunting crews.

Two developments deserve particular attention. First, Sophos reports that in a March 2026 engagement its Emergency Incident Response team observed Interlock running Volatility3, a legitimate memory forensics tool, on the Patient Zero device before Sophos was engaged. Reporting by Kobaran frames the same behaviour as hijacking forensic tooling to pull Windows credentials out of memory. Turning a defender's own analysis tool into a credential harvester is deliberate living-off-the-land tradecraft designed to blend into administrative noise. Second, Sophos states that Interlock has been actively exploiting CVE-2026-20131, a critical-severity zero-day in Cisco Secure Firewall Management Center software. A group that pairs mass-market social engineering with edge-device zero-day exploitation is operating well above commodity criminal capability.

Sophos also flags a detail worth internalising: in the March 2026 case, the customer environment mixed Sophos-managed servers with Defender-managed endpoints, and not all endpoints were in fact running the expected agent. Coverage gaps, not tool quality, decided where the attacker got to work undisturbed.

What Organizations Should Do

Sources: Interlock Ransomware Strikes AngMar Companies: 710 GB of Medical Da... | Interlock ransomware gang creates volatile situation SOPHOS | Data Security Incidents Announced by Park Dental Research Corp; Wab... | Almost 30,000 Texas Residents Affected by Data Breach at The Texas... | Interlock Ransomware Hijacks Forensic Tools to Steal Windows Creden... | Texas Hearing Institute notifies public of 30k breach claimed by In... | Texas Hearing Institute Data Breach Investigation | Interlock: the drive-by ransomware crew CISA flagged Ransomnews