West Lothian Council Listed by interlock Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
West Lothian Council was listed by the interlock ransomware group on May 06, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of people. Individuals who may have had data held by the council should review official updates and follow any recommended steps.
West Lothian Council, the local authority responsible for public services across the West Lothian area of Scotland, has been listed by the ransomware group known as interlock. The listing, reported on 6 May 2025, indicates that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and further operational details have not been publicly confirmed.
For residents and staff who rely on the council for everyday services, the disclosure raises immediate questions about what information may have left its systems and what practical steps can reduce personal risk while official investigations continue.
What happened
According to the available record, West Lothian Council was named on a leak site associated with the interlock ransomware group. The group claims that internal files were taken as part of a ransomware attack. No public confirmation has been issued regarding the precise date of intrusion, the technical method used to gain access, the volume of data involved, or whether encryption of systems also occurred. The number of individuals whose information may have been included is listed as unknown. Public detail on the incident is therefore limited to the fact of the listing itself and the description of exfiltrated internal files.
Inside interlock
Interlock is a ransomware operation that became publicly visible in late 2024. Like many contemporary groups, it typically employs a double-extortion model: data is copied from the victim’s network before systems are encrypted, and the threat of public release is used to pressure payment. The group maintains a dark-web leak site on which it posts the names of organisations it claims to have compromised, sometimes accompanied by sample files. Interlock has previously listed victims across multiple sectors, including public administration and private enterprise. Its claims are not independently verified at the moment of publication; they serve as assertions by the actors themselves. In this case, the listing of West Lothian Council is therefore treated as an unverified claim by the group rather than as confirmed fact from the council or law-enforcement sources.
Who is West Lothian Council?
West Lothian Council is the local government body that oversees public services for the West Lothian area of Scotland. Its responsibilities include education, local planning and legislative functions, economic development programmes, social care, housing support, waste management and community services. As a unitary authority it holds records on residents, school pupils, staff, businesses and service users. Local councils of this type routinely process personal data required to deliver statutory services, making any unauthorised access potentially consequential for large numbers of people who have no choice but to interact with the organisation.
The information in question
The only data category named in the available record is “internal files” said to have been exfiltrated. No further breakdown—such as whether the material included personal identifiers, financial records, health-related notes, staff details or operational documents—has been disclosed. Organisations of this kind typically hold names, addresses, dates of birth, contact details, school enrolment information, social-care case notes, employment records and correspondence with residents. Because the exact contents remain unconfirmed, it is not possible to state with certainty which of these categories, if any, were among the files claimed by interlock.
The real-world impact
If personal data were among the internal files, affected individuals could face risks of phishing, identity fraud or unwanted contact. Even purely operational documents can reveal patterns of service delivery or internal processes that might be misused. For the council itself, the incident may disrupt day-to-day administration, require forensic investigation, notification of regulators and the provision of support to residents. Because the scale of exposure is unknown, the practical consequences for any single person cannot yet be quantified; the primary immediate effect is uncertainty and the need for heightened vigilance.
Were you affected?
Anyone who has dealt with West Lothian Council—residents, parents, staff or local businesses—should treat the listing as a prompt to review their own security posture. Monitor bank and credit accounts for unexpected activity, be cautious of unsolicited emails or calls that reference council services, and consider placing fraud alerts with relevant agencies if personal details are later confirmed as exposed. Change passwords on any accounts that reused credentials linked to council interactions. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach datasets; such a scan provides an additional data point while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Fargo Park District Listed by interlock Ransomware GroupShelbyville Police Department Listed by interlock Ransomware GroupAccident Injury Solicitors Listed by interlock Ransomware GroupBox Elder County Listed by interlock Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the West Lothian Council Listed by interlock Ransomware Group →
Publicly posted by interlock — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.