Healthcare provider · Hospital and clinical care services · Integrated health system · USA
Faith-based healthcare system operating hospitals and outpatient facilities.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Interlock gained access to Kettering Health on April 9, 2025 and, after 41 days, deployed ransomware on May 20, 2025, triggering a system-wide outage that forced paper charting and some ambulance diversions. Interlock claimed exfiltration of about 941 GB (roughly 732,000 files) and published stolen data after Kettering declined to pay. Leaked samples reviewed by researchers included patient names, medical record numbers, clinical summaries, medication lists, mental-health notes, insurance and pharmacy documents, and scans of identity documents and payroll files for employees; reported PII also includes DOB, SSN, and payment-card/banking data. Kettering confirmed 1,695,382 individuals affected on the HHS OCR portal and began notifications in early 2026, noting a file-by-file review and that only a subset of patients had the most sensitive data exposed.
Full threat analysis, exploitation vectors, and principal guidance below.
11 additional sections · verified field analysis · defensive doctrine
1.7M records analyzed
Kettering Health is a not-for-profit, faith-based (Adventist) integrated health system in western Ohio, operating roughly 14 hospitals and more than 120 outpatient sites. It provides emergency, surgical, imaging, pharmacy, and outpatient care using the Epic electronic health record, maintaining extensive patient clinical, insurance, and billing records as well as employee HR and payroll data.
Integrated health systems collect patient identity, contact, insurance, billing, appointment, and clinical records across hospitals, specialty care, and administrative operations.
A May 20, 2025 ransomware attack caused a system-wide outage; Kettering restored core Epic functions by early June and declared normal operations on June 13, 2025. It initially reported a placeholder of 501 affected individuals to HHS in July 2025, then confirmed the total at 1,695,382 and began mailing patient notifications in early 2026. A class-action lawsuit was filed in Montgomery County in June 2025.
The breach compromised a broad set of clinical, identity, and financial data (medical records, mental-health notes, medication lists, Social Security numbers, insurance, and payment/banking data) for roughly 1.7 million patients, plus HR/payroll and ID-document data for employees. The scale and sensitivity create severe medical-fraud, identity-theft, financial-fraud, and extortion risk, compounded operational disruption to patient care, and generated significant litigation and reputational exposure.
• Medical identity fraud and insurance abuse using clinical, medication, and insurance data | • Identity theft and synthetic identity construction using SSN, DOB, and ID documents | • Financial fraud using exposed payment-card/banking data | • Extortion using mental-health notes and sensitive diagnoses | • Employee-directed HR/payroll fraud and social engineering | • Targeted phishing/vishing and fraudulent medical-bill scams | • Doxxing and physical targeting from exposed home addresses
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A ransomware and data-extortion operation active since around September 2024, impacting businesses and critical infrastructure across North America and Europe via a double-extortion model (encrypt plus steal).
Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.
We will only reveal whether a specific person appears in this breach to that person.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation