Kettering Health Cyberattack: Interlock Ransomware Confirmed
- Kettering Health, an Ohio-based healthcare provider with 14 medical centers, acknowledged that the Interlock ransomware group successfully breached its network in may, resulting in a notable data theft.
- The healthcare network stated that it has secured its network devices and is focused on re-establishing communication with patients affected by the technology outage.
- The initial cyberattack, disclosed May 20, caused widespread disruption, forcing medical staff to revert to manual charting.
Kettering Health confirms the Interlock ransomware group executed a significant cyberattack, resulting in data theft and widespread disruption. The breach compromised electronic health records, patient care systems, and crucial data including patient information, financial documents, and employee records. This incident, causing system outages and canceled procedures, has prompted the healthcare provider to reinforce network security, restore systems, and actively work on bringing applications back online. News Directory 3 reports on the Interlock ransomware’s emergence, its focus on healthcare, and the group’s claims of exfiltrating a ample amount of sensitive data. Discover what’s next as the inquiry unfolds and kettering Health works to prevent future attacks.
Kettering Health Confirms Ransomware Attack, Data Breach
Updated June 06, 2025
Kettering Health, an Ohio-based healthcare provider with 14 medical centers, acknowledged that the Interlock ransomware group successfully breached its network in may, resulting in a notable data theft. The health system, which employs over 15,000 individuals, including more than 1,800 physicians across 120 outpatient facilities, is working to restore systems.
The healthcare network stated that it has secured its network devices and is focused on re-establishing communication with patients affected by the technology outage. According to Kettering Health,the tools used by the attackers have been eliminated,and affected systems are now secure. External partners and the internal team conducted a thorough review, implementing enhanced monitoring, network segmentation, and updated access controls.
The initial cyberattack, disclosed May 20, caused widespread disruption, forcing medical staff to revert to manual charting. While emergency rooms and clinics remained operational, the attack impacted call centers and some patient care systems, leading to canceled elective procedures.
Kettering health reported that access to its electronic health record (EHR) system has been restored. The organization is actively working to bring the MyChart medical record application and call centers back online.
Interlock ransomware group claimed duty for the attack, releasing samples of the stolen data. The group alleges it exfiltrated 941 GB of files, encompassing over 732,000 documents within 20,000 folders, containing sensitive information.

The compromised data reportedly includes patient records, pharmacy and blood bank documents, bank reports, payroll details, Kettering Health police personnel files, and scanned identity documents like passports.
Interlock, a relatively new ransomware operation, emerged in September and has claimed responsibility for numerous attacks globally, with a focus on healthcare organizations. The group has also been linked to ClickFix attacks,using fake IT tools to infiltrate networks,and has deployed a remote access trojan (RAT) called NodeSnake in attacks against U.K. universities.
Recently, Interlock claimed responsibility for the breach of davita, a major kidney care provider, leaking 1.5 terabytes of stolen data.
What’s next
Kettering Health continues to restore its systems and reinforce its network security to prevent future incidents. The investigation into the full scope of the data breach is ongoing.
