Ransomware
Kettering Health Interlock Ransomware Attack
Primary Source βIncident Details
Kettering Health, an Ohio health system running 14 medical centers and dozens of clinics primarily in the Dayton area, was hit by Interlock ransomware on May 20, 2025. Approximately 600 digital applications were shut down; scheduled inpatient and outpatient procedures cancelled; staff reverted to pen and paper. Interlock claimed 941 GB of data stolen (732,490 files). Ransom not paid; data published on dark web. Full number of affected patients not yet confirmed (HHS portal shows placeholder of 500). Recovery took approximately three weeks. 200+ lawsuits filed. Notable for use of ClickFix initial access technique.
Technical Details
- Initial Attack Vector
- Drive-by download from compromised legitimate website; ClickFix technique (fake CAPTCHA prompting users to run malicious code via Windows Run dialog)
- Malware Family
- Interlock ransomware
Timeline
- 2025-05-20 Breach occurred
- 2025-05-20 Publicly disclosed
- 2025-06-01 Customers notified