The notorious Interlock ransomware group appears to be behind the serious cyberattack that recently hit Kettering Health , a sprawling healthcare network in Ohio, USA. In fact, the attackers have released samples of sensitive data they claim was stolen in the attack.

The cyberattack was revealed on May 20, causing severe disruptions to the operation of digital systems. The call center was taken down, while key patient care systems were also affected. Staff were forced to resort back to paper and pencil, as access to electronic health records (EHR) was disrupted. The attack also resulted in the cancellation of scheduled medical procedures, both for inpatients and outpatients. Despite the problems, emergency departments and clinics remained open.
See also: Interlock ransomware behind DaVita attack
In a recent update, Kettering Health announced that access to the EHR system has been restored, while work continues to fully restore MyChart, the platform patients use to access their medical records, as well as to re-open phone lines at affected practices.
Pending the full restoration of the call center, the organization is providing a temporary hotline, staffed by nurses, to handle urgent medical inquiries.
Although Kettering Health has not yet named a specific perpetrator, the ransomware gang claimed responsibility for the cyberattack and leaked data purportedly belonging to the medical organization.
See also: FBI: Play ransomware has compromised 900 organizations
The group claimed to have stolen 941 gigabytes of data from Kettering Health systems . This included more than 20,000 folders containing nearly 750,000 documents containing sensitive personal and financial information : bank statements, payroll records, patient medical records, as well as internal documents from Kettering Health's pharmacies, blood banks, and police departments. In addition, scanned identification documents , such as passports and other official IDs, were leaked .
Interlock ransomware
Interlock is a relatively new presence in the cybercrime scene, having only appeared in September 2024. However, in less than a year it has been linked to dozens of attacks , mainly targeting healthcare organizations .
The group has also engaged in ClickFix- style social engineering campaigns and has used a Remote Access Trojan called NodeSnake .
See also: New Lyrix Ransomware Attacks Windows Users

Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
