ResourcesTexas Breach Tracker › Texas Tech University Health Sciences Center
Healthcare Ransomware Actor: Interlock Remediated

Texas Tech University Health Sciences Center
Breach Analysis

Texas Tech University Health Sciences Center disclosed a ransomware attack in late 2024 attributed to the Interlock ransomware group. Approximately 1.4 million patient records were affected across its Lubbock and El Paso campuses.

Incident Date
2024-11-20
Records Exposed
1,400,000
Attack Type
Ransomware
Threat Actor
Interlock

How they got in

Interlock ransomware group gained initial access via phishing targeting clinical research staff. Double-extortion: data exfiltrated to Interlock leak site prior to encryption. Both Lubbock and El Paso campuses affected, suggesting shared network infrastructure.

Sentinel / Fortress / Command coverage

Sentinel 24/7 SOC with healthcare-specific threat intel: Interlock TTPs mapped to SIEM rules; C2 callback detected pre-detonation
Fortress Exfiltration detection: large outbound transfer to unknown external IP triggers DLP block and SOC alert — data theft prevented before ransomware detonation
Command HIPAA risk assessment identifies campus network architecture as high-risk single failure domain; segmentation recommended and tracked to completion

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
HIPAA 45 CFR §164.308(a)(1) Risk analysis — multi-campus network architecture not assessed for ransomware propagation risk
HIPAA 45 CFR §164.312(a)(1) Access control — research staff credentials gave access to clinical systems beyond job function
TDPA Tex. B&C Code §521.053 1.4M TX patient notification obligations triggered

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.