
On May 20, 2025, staff at Kettering Health arrived to find a system-wide technology outage that had taken the Ohio health system’s hospitals offline.
The nonprofit runs 14 medical centers and more than 120 outpatient facilities across the Dayton area, and within hours it had canceled every elective procedure, diverted ambulances, and sent clinicians back to pen and paper.Â
A ransomware group called Interlock was behind it.Â
The Kettering Health ransomware attack turned a network breach into a patient-care emergency, putting hard numbers on a fear that has shadowed hospitals for years. When technology goes down, patient care goes down with it. A healthcare ransomware attack is now a patient-safety event, not only an IT outage.
Inside the Kettering Health Ransomware Attack

Kettering Health first spotted the intrusion on May 20, 2025, though investigators later traced initial access back to April 9. The attackers moved through the network for roughly six weeks before triggering the outage.Â
To contain the damage, Kettering shut down around 600 applications, including its Epic electronic health record system, the MyChart patient portal, and its phone lines.Â
The Kettering Health cyberattack forced clinicians onto paper charts and knocked out scheduling for the entire system.
On June 6, Kettering confirmed that the Interlock ransomware group was responsible, after CNN obtained the ransom note. Interlock claimed it had stolen 941 GB of data across more than 732,000 files. The health system declined to pay, and core systems returned in stages through early June. The timeline below tracks the attack from initial access to recovery:
- Attack discovered: Kettering detects the outage on May 20, 2025, weeks after the initial breach on April 9.
- Systems disrupted: Around 600 applications go offline, including the Epic EHR, the MyChart portal, and phone lines.
- Patient services affected: Elective procedures are canceled and ambulances diverted for about a week.
- Recovery initiated: Systems return in phases, with Epic restored on June 2 and most operations back by June 10.
How the Cyberattack Impacted Patient Services
The damage landed on patients first. Every elective inpatient and outpatient procedure was canceled on the day of the attack, and ambulances were diverted for about a week. Emergency rooms and clinics stayed open, but staff worked without the tools they rely on every day. Some of the services impacted included:
- Appointments: Patients could not book or check visits during the outage.
- Patient portal: MyChart went offline, cutting access to records and results.
- Phones: The call center went dark, so families could not reach staff.
- Paper workflows: Clinicians charted by hand, slowing care and raising error risk.
- Scam calls: Kettering warned of fraudsters posing as staff to demand payments.
This kind of healthcare system downtime does more than delay paperwork. It postpones surgeries, interrupts treatment, and chips away at patient trust at the exact moment people need care.
Was Patient Data Compromised?
Yes. Because Kettering declined to pay, Interlock began leaking the stolen files in early June 2025. The Kettering Health data breach was later confirmed to affect 1,695,382 people, with several types of sensitive information exposed:
- Identity data: Names, SSNs, driver’s license and passport numbers.
- Medical records: Diagnoses, treatment details, and health insurance information.
- Financial data: Bank account details, billing records, and claims information.
- Credentials: Some usernames and passwords.
This was medical data theft at scale and a textbook example of the double-extortion model most ransomware groups now employ.
Attackers copy the files out through data exfiltration before they encrypt anything, then threaten to publish unless they are paid. Healthcare records sell well on the dark web because they bundle identity, insurance, and financial details into one file, which makes them ideal for fraud.Â
Unlike a stolen card number, a medical record cannot be canceled and reissued, so the exposure follows patients for years.
Why Hospitals Continue to Be Ransomware Targets
A ransomware attack on a hospital rarely remains an IT problem because the same systems that support administrative functions often underpin patient care. That overlap is what keeps attackers coming back. A few things make the sector an easy mark:
- High-value data: Records combine identity, insurance, and payment details.
- Legacy technology: Old systems and medical devices are hard to patch.
- Operational urgency: With care at risk, pressure to pay climbs fast.
- Large attack surface: Thousands of staff, devices, and vendors to defend.
- Thin security teams: Most providers run lean, understaffed security functions.
Recent incidents underscore the scale of the problem.
The Change Healthcare attack in February 2024 hit about 190 million people and involved a $22 million ransom. Ascension lost data on 5.6 million patients a few months later, reportedly to Black Basta. In London, the Synnovis attack forced the NHS to cancel thousands of operations and issue a national blood appeal, and the DaVita ransomware attack added 2.7 million more victims.Â
Cybercriminal attacks on hospitals are now a recurring feature of the healthcare calendar, and they rank among the most serious healthcare cybersecurity threats any provider faces.
Common Ransomware Tactics in Healthcare
Most healthcare breaches start with a handful of well-worn techniques. Interlock and groups like it rarely need anything exotic to get in:
- Phishing: A healthcare phishing attack tricks staff into opening a malicious link.
- Credential theft: Stolen or reused logins open a quiet way in.
- Fake update lures: Interlock uses ClickFix, a fake browser fix users run themselves.
- Remote access abuse: Exposed RDP and VPN are common entry points.
- Unpatched systems: Known vulnerabilities stay open for months.
- Lateral movement: Attackers spread across the network unnoticed.
- Data exfiltration: Files are copied out before encryption for extortion.
The 8 Main Lessons for Healthcare Providers
The Kettering Health incident is a blueprint for what to fix. Interlock sat inside the network for six weeks and stole 941 GB before it locked anything, so the measures that matter most are the ones that shorten dwell time and stop data from leaving.
- Rehearse the Downtime
Drill a full week with the EHR and call center dark, so clinicians can chart on paper and verify medications without the systems they lean on. - Segment Clinical Systems
Wall off the EHR, billing, imaging, pharmacy, and blood-bank networks so one foothold cannot reach them all. - Alert on Dwell-Time Signals
Flag new admin accounts, credential dumping, and off-hours access, the quiet markers of an intruder weeks before encryption. - Keep Offline, Immutable Backups
Store backups beyond the attacker’s reach and rehearse a full restore, the foundation of fast ransomware recovery. - Train Staff to Spot ClickFix
Teach people that a prompt telling them to paste a command or run a browser fix is the attack that Interlock favors. - Require Phishing-Resistant MFA
Put hardware keys or passkeys on email, VPN, and remote access, because attackers relay one-time codes in real time. - Vet Vendor Access
Inventory every third party with a network link or patient data and confirm each can detect and disclose a breach fast. - Block Bulk Data Transfers
Baseline normal traffic and stop large transfers to unfamiliar destinations, this is the step that would have denied Interlock its 941 GB.
Final Thoughts
For Kettering Health, the steepest cost was measured in patients. It showed up as weeks of canceled surgeries, families who could not reach a nurse by phone, and 1.7 million people whose records ended up in criminal hands. That damage lands on people long after the systems come back online.Â
Healthcare cyber resilience now depends on assuming an intrusion will happen and shrinking what an attacker can reach and carry out. That last part is where BlackFog ADX helps, blocking unauthorized data from leaving the endpoint so a hospital breach stays contained instead of turning into a patient-data leak.
The Most Frequently Asked Questions
Here are quick answers to the most common questions about the Kettering Health attack.
Share This Story, Choose Your Platform!
Related Posts
What Are Recommended Best Practices For Implementing AI Assurance In Organizations?
Discover best practices for implementing AI assurance to build secure, transparent and trustworthy AI usage across your organization.
What Are The Latest Trends In AI Assurance Standards And Regulations?
Explore the latest AI assurance standards, regulations and governance trends shaping transparent, compliant and trustworthy AI.
How Can AI Be Used to Improve Cybersecurity Measures?
Learn how AI improves cybersecurity through faster threat detection, incident response, AI monitoring, behavioral analysis and security automation.
What Should I Look For In An AI Security App To Ensure My Device Is Protected?
Learn what to look for in an AI security app, from real-time visibility and data protection to defense against AI-powered threats, to keep your device secure.
What Are The Main Safety Concerns Associated With AI Development?
Explore the Main Safety Concerns Associated With AI Development, from security and privacy to bias and oversight, and why responsible AI governance matters.
What Are The Best Practices For Ensuring AI Privacy?
Discover key best practices for ensuring AI privacy when adopting these tools, including data masking, monitoring and governance.






