A cyberattack has hit Kettering Health, one of Ohio's largest healthcare , which operates 14 medical centers and more than 120 outpatient facilities in the region. The incident has led to widespread disruption of the organization's technology infrastructure, causing some processes to be suspended.

In an official statement posted on the organization's website, Kettering Health management confirms that the ongoing outage was caused by a cyberattack, affecting critical systems, such as the call center and management tools patient care.
"All non-urgent scheduled procedures, both inpatient and outpatient, have been canceled for today, Tuesday, May 20," the statement said. "These procedures will be rescheduled, and more information will be provided as updates become available. Additionally, our call center is experiencing an outage and may not be accessible."
See also: VanHelsing ransomware-as-a-service: Source code leaked
At the same time, the administration emphasizes that emergencies and clinics continue to operate normally.
At the same time, the organization is warning the public about suspicious phone calls from scammers employees Kettering Health, requesting credit card payments for alleged medical expenses. While a direct connection to this cyberattack has not been confirmed, the organization is urging patients to report such scam attempts to local authorities.
Kettering Health: The service outages are related to the Interlock ransomware;
Although Kettering Health has yet to officially confirm the nature of the cyberattack that led to the severe outage of its infrastructure, all signs point to a ransomware scenario. Cybersecurity experts believe the attack bears the hallmarks of Interlock .
Cyber threat firm PRODAFT revealed to BleepingComputer that the cyberattack is allegedly being carried out by the Nefarious Mantis – a unit of the wider Interlock. The group has a history of targeting healthcare and biotech organizations in the US, using the Interlock RAT to infiltrate, monitor, and maintain access to victims’ internal networks.
"In several cases, this action led to the deployment of the Interlock ransomware, causing operational disruptions and potential data loss," a PRODAFT spokesperson noted.
See also: KeePass: Fake version leads to ransomware infection
CNN confirms similar information, reporting that cybercriminals have already threatened to leak sensitive data they have allegedly extracted from Kettering Health's systems.
No official claim of responsibility for the cyberattack on Kettering Health
To date, the group behind the Interlock ransomware has not published any report of a breach of Kettering Health on the leak site it maintains on the dark web. Meanwhile, no other known ransomware gang has taken responsibility for the attack, leaving the landscape open regarding the identity of the perpetrators.
Interlock, however, is one of the most emerging threats in the cybercrime space. Its activity has been detected since September, and since then it has claimed more than 30 data breaches.

One of its most recent “hits” involves DaVita, a kidney care giant with over 2,600 dialysis centers in the U.S. Interlock published approximately 1.5 terabytes of data – nearly 700,000 records – that it allegedly extracted from the organization’s systems, raising serious concerns about the security of healthcare infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Ransomware gangs use Skitnet malware
Despite indications of Interlock involvement and third‑party reports, a Kettering Health spokesperson avoided commenting further or officially confirming whether the incident is linked to ransomware.
Ransomware protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to the network
- Encryption of sensitive data
- Updating devices and systems with the latest security patches
- Conducting regular security audits and penetration testing
- Using strong, unique passwords
- Limiting user access to only necessary systems and information
- Use solutions email security for additional protection against phishing attacks
- Recovery plan for quick recovery
Source: www.bleepingcomputer.com
