YMCA of Western North Carolina
Attack Intelligence
YMCA of Western North Carolina was compromised in a ransomware attack attributed to interlock in July 2026. The organization, operating in the Consumer Services sector in United States, was added to the group's data leak site as part of an extortion campaign.
interlock operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
The YMCA of Western North Carolina operates seven fitness centers, a summer camp, dozens of food trucks, youth sports programs, and many other initiatives. They are also the state's largest provider of licensed school-age childcare. However, they don't ensure security and aren't responsible for it, and you can gain access to confidential client information (complete sets of documents, even fingerprints), contracts, and incidents (of which they have many!), as well as to employee personal data and financial documents.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-20131, which may have been leveraged as initial access vectors or for lateral movement.