SYS::ONLINE
Wasteland.
Briefs1269
Issues20
SinceFeb 2026
LIVE
█ Ransomware KETTERING-HEALTH-I 2026-07-21

Kettering Health: Interlock Ransomware Attack

"Here is the complete article."

Here is the complete article.


title: "Kettering Health: Interlock Ransomware Attack" date: 2026-07-21 slug: kettering-health-interlock-ransomware


Kettering Health: Interlock Ransomware Attack

On May 20, 2025, staff at Kettering Health, a nonprofit Ohio health system running 14 medical centers and more than 120 outpatient facilities across the Dayton area, arrived to a system-wide technology outage that had knocked its hospitals offline. The Interlock ransomware group claimed responsibility, boasting the theft of 941 GB of data across more than 732,000 files. Kettering confirmed Interlock's involvement on June 6 after CNN obtained the ransom note. The health system declined to pay.

What Happened

Kettering Health detected the intrusion on May 20, 2025, but investigators later traced initial access back to April 9. Attackers dwelled inside the network for roughly six weeks before triggering the outage. To contain the damage, Kettering shut down around 600 applications, including its Epic electronic health record system, the MyChart patient portal, and its phone lines. Clinicians were forced back to paper charts, and scheduling collapsed across the entire system. Core systems returned in phases, with Epic restored on June 2 and most operations back online by June 10.

What Was Taken

Interlock claimed exfiltration of 941 GB of data spanning more than 732,000 files. While Kettering has not published a full inventory of the stolen records, a healthcare system of this scale holds highly sensitive protected health information: patient medical histories, insurance and billing details, and personally identifiable information. Data exfiltration prior to encryption is a hallmark of double-extortion campaigns, giving the attackers leverage to threaten publication even when the victim refuses to pay.

Why It Matters

The Kettering Health attack turned a network breach into a patient-care emergency. Every elective inpatient and outpatient procedure was canceled on the day of the attack, ambulances were diverted for about a week, and families lost the ability to reach staff when the call center went dark. This incident puts hard numbers on a fear that has shadowed hospitals for years: when technology goes down, patient care goes down with it. A healthcare ransomware attack is now a patient-safety event, not merely an IT outage.

The Attack Technique

Interlock gained initial access on April 9, 2025, then moved laterally through the network undetected for roughly six weeks before detonating the payload on May 20. This extended dwell time allowed the group to map the environment and stage the 941 GB of data for exfiltration ahead of encryption. The pattern reflects a classic double-extortion playbook: quiet persistence, broad reconnaissance, bulk data theft, and finally system-wide encryption timed to maximize operational disruption.

What Organizations Should Do

Sources: How the Kettering Health Ransomware Attack Disrupted Patient Services