The institute, formally known as the Center for Hearing and Speech, reported the breach, which has since been claimed by the notorious ransomware gang, Interlock.

 

What happened

According to the institute’s notice, which was published and released on June 26th, 2026, although not reported to the Department of Health and Human Services until later, the breach was initially discovered on March 20th, 2026. At that time, the Institute discovered suspicious activity and determined they had been compromised by an unauthorized actor.

Through an investigation, the institute determined they had been breached on April 22nd, 2026. Accessed information varied by individual but generally included names, Social Security numbers, financial information, and medical records. The institute reported the incident to the Texas Attorney General, stating 29,498 individuals were impacted.

 

Going deeper

While the Texas Hearing Institute has not made a statement confirming, Interlock has claimed the attack and added the institution to its dark web leak site. They claim to have 540 gigabytes of data.

Interlock has become an infamous group in recent years, regularly targeting companies in the US like Kettering Health and DaVita. They have also targeted other organizations in Texas.

The group emerged in September 2024, according to Paubox, and operates as a ransomware-as-a-service (RaaS) platform, meaning they sell tools and software for less tech-savvy individuals or groups to still successfully complete ransomware attacks. In return, Interlock receives a percentage of the profits, sometimes up to 20%. Their tactics have been described as “uncommon” by the FBI, because they use strategies like drive-by-download, meaning sending malicious files in ordinary-appearing downloads or in unauthorized downloads.

 

In the know

Suspicious activity can present itself in a lot of ways, depending on the type of attack that is being carried out. According to the Federal Trade Commission, it can look like unusual access, which might include someone logging in from a strange location, an unknown device, or at unusual hours. Other signs may include strange transactions or unauthorized withdrawals, sudden spikes in data traffic or a slow network performance. For employees, they may notice unexpected password resets or locked profiles for users.

 

The big picture

Ransomware groups like Interlock show no signs of stopping, continually adding data breach to their leak site and sending ransomware notes to victims. It’s unclear how successful these ransomware groups are, as many organizations don’t publicize if they pay a ransom or not. It’s usually not advised to pay a ransom, as it doesn’t guarantee if the data will be deleted; many ransomware organizations don’t operate in good faith and will publish or sell the data regardless of the ransom payment. In fact, according to one study, 80% of ransomware victims who paid the ransom were hit by an additional attack, since malicious groups consider the attack successful.

 

What’s next

For the Texas Hearing Institute, data breach notices have been sent out and now the organization will simply have to wait to see if any class action suits will be filed or if any additional investigations, like from the Texas Attorney General, will be initiated. Currently, several law firms are hoping to build a suit, but it will take some time to determine if a suit emerges and what the final outcome will be.

 

FAQs

Why do malicious groups sell programs like RaaS instead of using them for themselves?

Most ransomware group are financially motivated, and selling services becomes a new revenue source. Many ransomware groups actually have working relationships with each other, and it’s common for groups to split and create new groups, creating an interconnected world of crime.

 

Was this breach preventable?

It’s hard to say for certain if a breach is preventable without knowing exactly how it occurred. However, most breaches can be prevented with strong practices and software. Even as attackers get more strategic and sophisticated, nearly every breach can still be stopped before it’s too late.