Skip to main content

Company intelligence

Ketteringhealth cybersecurity incidents and threat signals

ketteringhealth.org

Ketteringhealth logo

This company page brings together public reporting currently associated with Ketteringhealth. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

2

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

0

High or critical

confidence classifications

June 26, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Ketteringhealth. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Ketteringhealth

Ketteringhealth logoRansomware
Medium

Kettering Health hit by Interlock ransomware, data leaked

Kettering Health, an Ohio-based healthcare network, confirmed a ransomware attack by the Interlock group that disrupted internal systems, phone lines, and electronic health records across its 14 hospitals. The attack, which began in late May, led to procedure cancellations and ambulance diversions. The Interlock ransomware group claimed responsibility on June 4, 2025, and allegedly stole 941 GB of data, including patient and employee information. Kettering Health publicly acknowledged the ransomware group's link on June 6, 2025, and confirmed eradication of the threat actors' tools by June 5, 2025.

Ketteringhealth
Ketteringhealth logoRansomware
Medium

Kettering Health Hit by System-Wide Outage After Ransomware Attack

Kettering Health, a healthcare network in Ohio, experienced a ransomware attack on May 20, 2025, causing a system-wide technology outage. The attack, attributed to the Interlock ransomware group, forced the cancellation of inpatient and outpatient procedures and disrupted phone lines and patient portals. While emergency rooms remained open, staff reverted to manual, pen-and-paper workflows. The Interlock group claimed to have exfiltrated 941 GB of data, including patient information, and leaked it when the ransom was not paid.

Ketteringhealth

FAQ

Questions about Ketteringhealth cybersecurity reporting

What does the Ketteringhealth page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Ketteringhealth.

Does every mention of Ketteringhealth appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.