Ransomware

Kettering Health Interlock Ransomware Attack

πŸ“… 2025-05-20 🦠 Interlock ransomware
Primary Source β†—

Incident Details

Kettering Health, an Ohio health system running 14 medical centers and dozens of clinics primarily in the Dayton area, was hit by Interlock ransomware on May 20, 2025. Approximately 600 digital applications were shut down; scheduled inpatient and outpatient procedures cancelled; staff reverted to pen and paper. Interlock claimed 941 GB of data stolen (732,490 files). Ransom not paid; data published on dark web. Full number of affected patients not yet confirmed (HHS portal shows placeholder of 500). Recovery took approximately three weeks. 200+ lawsuits filed. Notable for use of ClickFix initial access technique.

Technical Details

Initial Attack Vector
Drive-by download from compromised legitimate website; ClickFix technique (fake CAPTCHA prompting users to run malicious code via Windows Run dialog)
Malware Family
Interlock ransomware

Timeline

  1. 2025-05-20 Breach occurred
  2. 2025-05-20 Publicly disclosed
  3. 2025-06-01 Customers notified