# Interlock ransomware breaches Southeastern Oklahoma State

Published: 2026-08-19 · Severity: elevated · Sectors: education
Canonical: https://vorant.io/reports/d53782d2-6ebb-558b-bcb1-a0962c8d8c92/interlock-ransomware-breaches-southeastern-oklahoma-state

> Interlock ransomware group claims a breach of Southeastern Oklahoma State University, exposing SSNs, medical, and financial data for over 90,000 students and staff.

Southeastern Oklahoma State University (Durant, Oklahoma) has been listed as a victim by the Interlock ransomware group on their leak site, with an estimated attack date of August 19, 2026. The exposed data reportedly includes highly sensitive student educational records covered under FERPA (names, Social Security numbers, grades, enrollment, financial aid, disciplinary, and medical information), as well as employee personal data including Social Security numbers, Medicare details, dates of birth, injury records, and child custody/consent status protected under HIPAA. The breach reportedly affects more than 90,000 individuals and includes over 490 leaked documents along with IRS Form 1095-C records.

HudsonRock infostealer telemetry associated with the university's domain shows a moderate footprint of compromised credentials — 32 compromised employees, 39 compromised users, and 38 third-party employee credential exposures — suggesting stolen-credential activity may have contributed to or coincided with initial access. The university's external attack surface includes Microsoft 365, Adobe, Amazon SES/WorkMail, SendGrid, and Zoom integrations, any of which could represent potential access vectors, though the specific intrusion method is not detailed in the source.

Given the scale of sensitive PII/PHI exposure (SSNs, medical and financial data of tens of thousands of students and employees) and confirmed claim by a named, active ransomware operation, this incident carries substantial regulatory and identity-theft risk for the affected population. Educational institutions handling large volumes of regulated student and employee data remain a recurring target for ransomware groups seeking high-value extortion leverage.

## Mentioned in this report

- Threat actors: interlock
- Malware: Interlock

Source reporting: https://www.ransomware.live/id/U291dGhlYXN0ZXJuIE9rbGFob21hIFN0YXRlIFVuaXZlcnNpdHlAaW50ZXJsb2Nr

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d53782d2-6ebb-558b-bcb1-a0962c8d8c92/interlock-ransomware-breaches-southeastern-oklahoma-state.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
