Here is the complete article.
title: "Kettering Health: Interlock Ransomware Attack" date: 2026-07-21 slug: kettering-health-interlock-ransomware
Kettering Health: Interlock Ransomware Attack
On May 20, 2025, staff at Kettering Health, a nonprofit Ohio health system running 14 medical centers and more than 120 outpatient facilities across the Dayton area, arrived to a system-wide technology outage that had knocked its hospitals offline. The Interlock ransomware group claimed responsibility, boasting the theft of 941 GB of data across more than 732,000 files. Kettering confirmed Interlock's involvement on June 6 after CNN obtained the ransom note. The health system declined to pay.
What Happened
Kettering Health detected the intrusion on May 20, 2025, but investigators later traced initial access back to April 9. Attackers dwelled inside the network for roughly six weeks before triggering the outage. To contain the damage, Kettering shut down around 600 applications, including its Epic electronic health record system, the MyChart patient portal, and its phone lines. Clinicians were forced back to paper charts, and scheduling collapsed across the entire system. Core systems returned in phases, with Epic restored on June 2 and most operations back online by June 10.
What Was Taken
Interlock claimed exfiltration of 941 GB of data spanning more than 732,000 files. While Kettering has not published a full inventory of the stolen records, a healthcare system of this scale holds highly sensitive protected health information: patient medical histories, insurance and billing details, and personally identifiable information. Data exfiltration prior to encryption is a hallmark of double-extortion campaigns, giving the attackers leverage to threaten publication even when the victim refuses to pay.
Why It Matters
The Kettering Health attack turned a network breach into a patient-care emergency. Every elective inpatient and outpatient procedure was canceled on the day of the attack, ambulances were diverted for about a week, and families lost the ability to reach staff when the call center went dark. This incident puts hard numbers on a fear that has shadowed hospitals for years: when technology goes down, patient care goes down with it. A healthcare ransomware attack is now a patient-safety event, not merely an IT outage.
The Attack Technique
Interlock gained initial access on April 9, 2025, then moved laterally through the network undetected for roughly six weeks before detonating the payload on May 20. This extended dwell time allowed the group to map the environment and stage the 941 GB of data for exfiltration ahead of encryption. The pattern reflects a classic double-extortion playbook: quiet persistence, broad reconnaissance, bulk data theft, and finally system-wide encryption timed to maximize operational disruption.
What Organizations Should Do
- Deploy anti-data-exfiltration controls that block unauthorized outbound transfers, since encryption is only half of a double-extortion attack.
- Shrink dwell time with continuous monitoring and endpoint detection tuned to catch lateral movement in the weeks between access and detonation.
- Segment clinical networks so a single intrusion cannot cascade across every application and facility at once.
- Maintain and regularly test offline, immutable backups so recovery does not depend on paying a ransom.
- Rehearse downtime procedures, including paper workflows and ambulance diversion plans, so patient safety is preserved when systems fail.
- Enforce phishing-resistant multi-factor authentication and least-privilege access to raise the cost of initial access and lateral movement.
Sources: How the Kettering Health Ransomware Attack Disrupted Patient Services