Interlock ransomware breaches Southeastern Oklahoma State
Interlock ransomware group claims a breach of Southeastern Oklahoma State University, exposing SSNs, medical, and financial data for over 90,000 students and staff.
Southeastern Oklahoma State University (Durant, Oklahoma) has been listed as a victim by the Interlock ransomware group on their leak site, with an estimated attack date of August 19, 2026. The exposed data reportedly includes highly sensitive student educational records covered under FERPA (names, Social Security numbers, grades, enrollment, financial aid, disciplinary, and medical information), as well as employee personal data including Social Security numbers, Medicare details, dates of birth, injury records, and child custody/consent status protected under HIPAA. The breach reportedly affects more than 90,000 individuals and includes over 490 leaked documents along with IRS Form 1095-C records.
HudsonRock infostealer telemetry associated with the university's domain shows a moderate footprint of compromised credentials — 32 compromised employees, 39 compromised users, and 38 third-party employee credential exposures — suggesting stolen-credential activity may have contributed to or coincided with initial access. The university's external attack surface includes Microsoft 365, Adobe, Amazon SES/WorkMail, SendGrid, and Zoom integrations, any of which could represent potential access vectors, though the specific intrusion method is not detailed in the source.
Given the scale of sensitive PII/PHI exposure (SSNs, medical and financial data of tens of thousands of students and employees) and confirmed claim by a named, active ransomware operation, this incident carries substantial regulatory and identity-theft risk for the affected population. Educational institutions handling large volumes of regulated student and employee data remain a recurring target for ransomware groups seeking high-value extortion leverage.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/U291dGhlYXN0ZXJuIE9rbGFob21hIFN0YXRlIFVuaXZlcnNpdHlAaW50ZXJsb2Nr
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free