Interlock ransomware attack shuts down systems across Ohio's Kettering Health

Organization
Kettering Health
Exploit
Ransomware
Industry
Healthcare

Kettering Health, a nonprofit system that runs 14 medical centres and more than 120 outpatient sites in western Ohio, reported a system-wide technology outage on 20 May 2025 after attackers reached its network. The disruption cut access to patient care applications, took the call centre offline and forced the cancellation of all elective inpatient and outpatient procedures. Emergency departments and clinics stayed open, although ambulances were diverted at several facilities.

The health system initially declined to confirm ransomware. CNN reported that staff had found a ransom note attributed to the Interlock group, and Kettering Health confirmed Interlock's involvement in early June after the gang claimed the attack and posted sample files, including financial records, on its leak site.

Recovery ran for roughly three weeks. More than 200 staff and Epic personnel worked to restore core electronic health record functions by 2 June, and the organization said it had removed the attackers' tooling and completed a review of affected systems by 6 June. Normal operations, including the MyChart portal and phone lines, resumed on 11 June.

Kettering Health also warned patients about callers impersonating its staff and demanding payment for medical expenses during the outage. It said it would notify anyone whose information was involved and offer identity theft or credit monitoring. The final tally, confirmed later in 2025, was 1,695,382 individuals.

Updates

  1. Kettering Health revised its report to the HHS Office for Civil Rights to 1,695,382 affected people, replacing the placeholder estimate of about 500 individuals it filed in July 2025 while its file review was still running.

Sources