By |Last Updated: July 21st, 2026|9 min read|Categories: Healthcare, Data Exfiltration, Ransomware|

Contents

On May 20, 2025, staff at Kettering Health arrived to find a system-wide technology outage that had taken the Ohio health system’s hospitals offline.

The nonprofit runs 14 medical centers and more than 120 outpatient facilities across the Dayton area, and within hours it had canceled every elective procedure, diverted ambulances, and sent clinicians back to pen and paper. 

A ransomware group called Interlock was behind it. 

The Kettering Health ransomware attack turned a network breach into a patient-care emergency, putting hard numbers on a fear that has shadowed hospitals for years. When technology goes down, patient care goes down with it. A healthcare ransomware attack is now a patient-safety event, not only an IT outage.

Inside the Kettering Health Ransomware Attack

Kettering Health Time Line

Kettering Health first spotted the intrusion on May 20, 2025, though investigators later traced initial access back to April 9. The attackers moved through the network for roughly six weeks before triggering the outage. 

To contain the damage, Kettering shut down around 600 applications, including its Epic electronic health record system, the MyChart patient portal, and its phone lines. 

The Kettering Health cyberattack forced clinicians onto paper charts and knocked out scheduling for the entire system.

On June 6, Kettering confirmed that the Interlock ransomware group was responsible, after CNN obtained the ransom note. Interlock claimed it had stolen 941 GB of data across more than 732,000 files. The health system declined to pay, and core systems returned in stages through early June. The timeline below tracks the attack from initial access to recovery:

  • Attack discovered: Kettering detects the outage on May 20, 2025, weeks after the initial breach on April 9.
  • Systems disrupted: Around 600 applications go offline, including the Epic EHR, the MyChart portal, and phone lines.
  • Patient services affected: Elective procedures are canceled and ambulances diverted for about a week.
  • Recovery initiated: Systems return in phases, with Epic restored on June 2 and most operations back by June 10.

How the Cyberattack Impacted Patient Services

The damage landed on patients first. Every elective inpatient and outpatient procedure was canceled on the day of the attack, and ambulances were diverted for about a week. Emergency rooms and clinics stayed open, but staff worked without the tools they rely on every day. Some of the services impacted included:

  • Appointments: Patients could not book or check visits during the outage.
  • Patient portal: MyChart went offline, cutting access to records and results.
  • Phones: The call center went dark, so families could not reach staff.
  • Paper workflows: Clinicians charted by hand, slowing care and raising error risk.
  • Scam calls: Kettering warned of fraudsters posing as staff to demand payments.

This kind of healthcare system downtime does more than delay paperwork. It postpones surgeries, interrupts treatment, and chips away at patient trust at the exact moment people need care.

Was Patient Data Compromised?

Yes. Because Kettering declined to pay, Interlock began leaking the stolen files in early June 2025. The Kettering Health data breach was later confirmed to affect 1,695,382 people, with several types of sensitive information exposed:

  • Identity data: Names, SSNs, driver’s license and passport numbers.
  • Medical records: Diagnoses, treatment details, and health insurance information.
  • Financial data: Bank account details, billing records, and claims information.
  • Credentials: Some usernames and passwords.

This was medical data theft at scale and a textbook example of the double-extortion model most ransomware groups now employ.

Attackers copy the files out through data exfiltration before they encrypt anything, then threaten to publish unless they are paid. Healthcare records sell well on the dark web because they bundle identity, insurance, and financial details into one file, which makes them ideal for fraud. 

Unlike a stolen card number, a medical record cannot be canceled and reissued, so the exposure follows patients for years.

Why Hospitals Continue to Be Ransomware Targets

A ransomware attack on a hospital rarely remains an IT problem because the same systems that support administrative functions often underpin patient care. That overlap is what keeps attackers coming back. A few things make the sector an easy mark:

  • High-value data: Records combine identity, insurance, and payment details.
  • Legacy technology: Old systems and medical devices are hard to patch.
  • Operational urgency: With care at risk, pressure to pay climbs fast.
  • Large attack surface: Thousands of staff, devices, and vendors to defend.
  • Thin security teams: Most providers run lean, understaffed security functions.

Recent incidents underscore the scale of the problem.

The Change Healthcare attack in February 2024 hit about 190 million people and involved a $22 million ransom. Ascension lost data on 5.6 million patients a few months later, reportedly to Black Basta. In London, the Synnovis attack forced the NHS to cancel thousands of operations and issue a national blood appeal, and the DaVita ransomware attack added 2.7 million more victims. 

Cybercriminal attacks on hospitals are now a recurring feature of the healthcare calendar, and they rank among the most serious healthcare cybersecurity threats any provider faces.

Common Ransomware Tactics in Healthcare

Most healthcare breaches start with a handful of well-worn techniques. Interlock and groups like it rarely need anything exotic to get in:

  • Phishing: A healthcare phishing attack tricks staff into opening a malicious link.
  • Credential theft: Stolen or reused logins open a quiet way in.
  • Fake update lures: Interlock uses ClickFix, a fake browser fix users run themselves.
  • Remote access abuse: Exposed RDP and VPN are common entry points.
  • Unpatched systems: Known vulnerabilities stay open for months.
  • Lateral movement: Attackers spread across the network unnoticed.
  • Data exfiltration: Files are copied out before encryption for extortion.

The 8 Main Lessons for Healthcare Providers

The Kettering Health incident is a blueprint for what to fix. Interlock sat inside the network for six weeks and stole 941 GB before it locked anything, so the measures that matter most are the ones that shorten dwell time and stop data from leaving.

  1. Rehearse the Downtime
    Drill a full week with the EHR and call center dark, so clinicians can chart on paper and verify medications without the systems they lean on.
  2. Segment Clinical Systems
    Wall off the EHR, billing, imaging, pharmacy, and blood-bank networks so one foothold cannot reach them all.
  3. Alert on Dwell-Time Signals
    Flag new admin accounts, credential dumping, and off-hours access, the quiet markers of an intruder weeks before encryption.
  4. Keep Offline, Immutable Backups
    Store backups beyond the attacker’s reach and rehearse a full restore, the foundation of fast ransomware recovery.
  5. Train Staff to Spot ClickFix
    Teach people that a prompt telling them to paste a command or run a browser fix is the attack that Interlock favors.
  6. Require Phishing-Resistant MFA
    Put hardware keys or passkeys on email, VPN, and remote access, because attackers relay one-time codes in real time.
  7. Vet Vendor Access
    Inventory every third party with a network link or patient data and confirm each can detect and disclose a breach fast.
  8. Block Bulk Data Transfers
    Baseline normal traffic and stop large transfers to unfamiliar destinations, this is the step that would have denied Interlock its 941 GB.

Final Thoughts

For Kettering Health, the steepest cost was measured in patients. It showed up as weeks of canceled surgeries, families who could not reach a nurse by phone, and 1.7 million people whose records ended up in criminal hands. That damage lands on people long after the systems come back online. 

Healthcare cyber resilience now depends on assuming an intrusion will happen and shrinking what an attacker can reach and carry out. That last part is where BlackFog ADX helps, blocking unauthorized data from leaving the endpoint so a hospital breach stays contained instead of turning into a patient-data leak.

The Most Frequently Asked Questions

Here are quick answers to the most common questions about the Kettering Health attack.

Interlock is a ransomware group that emerged in late 2024 and leans heavily on healthcare targets. It runs double-extortion attacks and often uses a fake-update lure called ClickFix. Kettering Health confirmed Interlock was responsible on June 6, 2025.

Interlock claimed 941 GB across more than 732,000 files. The healthcare cybersecurity incident exposed names, Social Security numbers, driver’s license and passport numbers, medical and insurance details, and billing data for roughly 1.69 million people.

No. Kettering declined to pay, so Interlock published the stolen files on its leak site in early June 2025. Even a payment rarely stops a leak, and the data surfaced regardless.

Systems returned in stages. Kettering restored its Epic health record system on June 2, 2025, and had most operations, phones, and pharmacy running again by June 10, about three weeks after the outage began.

Bring in incident-response and legal experts before weighing any payment, preserve systems for forensics instead of wiping them, and tell patients and regulators early. Assume stolen data will surface even if the ransom is paid.

Share This Story, Choose Your Platform!

Related Posts