Originally published March 30, 2026. Updated September 2026 with the confirmed breach scale, intrusion timeline, and legal developments.
No organization is immune to a cyberattack. Here is what the 2025 Kettering Health ransomware attack looked like, what has come to light since, and what your business should do right now.
Events surrounding the Kettering Health cyberattack in 2025 reignited a critical conversation in the current threat landscape: no organization, regardless of size or industry, is immune to a serious cyber incident.
What is clear from how this incident unfolded, and from what has been disclosed in the year since, is that cyberattacks don't just take down systems. They disrupt people, halt critical workflows, and erode the trust you have worked hard to build. Attackers were inside the network for 41 days before anyone knew. Nearly 1.7 million people were affected. A year later, dozens of lawsuits are still moving through the courts.
For businesses across sectors, including manufacturing, professional services, healthcare, and logistics, this is a direct reminder that resiliency is a core business requirement. This post covers what happened, what we know now that was not known then, the lessons that apply to every organization, and how to prepare.
Key Takeaways
- Attackers had access to Kettering Health's network for 41 days before ransomware was deployed on May 20, 2025. Early detection, not just prevention, decides how large an incident becomes.
- Nearly 1.7 million individuals were confirmed affected in April 2026, and 44 lawsuits alleging delayed or denied care have been consolidated in Montgomery County court. The consequences of an attack can continue long after systems are restored.
- Declining to pay a ransom does not prevent stolen data from being published. Immutable, tested backups are what make that decision survivable.
- Downtime has measurable business impact. Kettering Health was operating on paper workflows for roughly three weeks.
- Resiliency is a combination of layered cybersecurity controls, 24/7/365 monitoring, a tested disaster recovery plan, and a written incident response plan. None of the four can be skipped.
What Happened During the Kettering Health Cyberattack?
On May 20, 2025, Kettering Health, a nonprofit healthcare network operating 14 medical centers and more than 120 outpatient facilities across western Ohio and employing over 15,000 people, experienced a ransomware attack that caused a system-wide technology outage (BleepingComputer).
The attack was carried out by the Interlock ransomware group, which encrypted critical systems including phone lines, the MyChart patient portal, and core patient care applications. The group claimed to have stolen over 941 GB of data across more than 732,000 files and threatened to publish it if Kettering did not respond within 72 hours (HIPAA Journal).
Kettering Health responded by shutting down approximately 600 digital applications to contain the threat. Elective procedures were canceled, emergency departments temporarily diverted ambulances, and clinical staff shifted to manual, pen-and-paper workflows (TechCrunch). Kettering Health has been widely reported as declining to pay the ransom, and Interlock subsequently published the stolen data on its leak site. Kettering Health has not publicly confirmed the details of any ransom decision.
Core systems returned in stages, and Kettering Health reported a return to normal operations on June 10, 2025, roughly three weeks after the attack began.
The table below summarizes the timeline as it is now understood, including details that were only disclosed months later.
| Date | What Happened |
|---|---|
| April 9, 2025 | Interlock first gains access to Kettering Health's network. The intrusion goes undetected. |
| May 20, 2025 | Ransomware is deployed. System-wide outage begins; ~600 applications taken offline to contain the attack. |
| Late May 2025 | Scam calls targeting patients reported; billing calls paused. Interlock begins leaking stolen data after the ransom deadline passes. |
| June 2, 2025 | Core Epic electronic health record system restored, letting clinicians begin entering patient information directly again and working through the paper backlog. |
| June 9, 2025 | MyChart patient portal returns in limited form. |
| June 10, 2025 | Kettering Health reports a full return to normal operations for surgery, imaging, retail pharmacy, and physician office visits. |
| July 2025 | Kettering Health confirms an unauthorized party viewed or took files between April 9 and May 20. |
| January 29, 2026 | Individual notification letters begin going out; credit monitoring and identity restoration services offered. |
| March 2026 | 44 individual lawsuits are consolidated in Montgomery County Common Pleas Court, 37 alleging delayed treatment and 8 alleging denial of care. |
| April 2026 | The HHS Office for Civil Rights breach portal is updated to show 1,695,382 individuals affected. |
Kettering Health is far from alone in facing this type of threat. It joins a growing list of healthcare organizations targeted by ransomware in recent years, including Change Healthcare, Ascension Health, and DaVita.
What We Know Now That We Didn't Know Then
When this incident first made news, the story was about a three-week outage. A year later, the picture is different in three ways that matter for any business planning its own defenses.
The Attackers Were Inside for 41 Days
Kettering Health's own notice confirmed that unauthorized access began on April 9, 2025 and continued until the ransomware was discovered on May 20 (Becker's Hospital Review). That is 41 days of an attacker moving through the environment, identifying systems, and copying files before anything visible happened. This is a common pattern. Ransomware deployment is usually the last step of an intrusion, not the first, and the weeks before it are where monitoring and detection can change the outcome.
The Scale of the Breach Was Far Larger Than First Reported
The initial HHS filing used a placeholder of 501 individuals. In April 2026, the confirmed figure was updated to 1,695,382. The exposed information reportedly included names, Social Security numbers, financial account numbers, driver's license and passport numbers, medical and treatment information, health insurance details, and usernames and passwords. The breach notification, credit monitoring, and identity restoration obligations that follow a breach of this size apply regardless of whether a ransom was paid.
The Legal Consequences Are About Care, Not Just Data
Of the 44 consolidated lawsuits, 37 allege delayed treatment and 8 allege denial of care. Plaintiffs include patients receiving ongoing treatment whose appointments were rescheduled months later or not at all. The attorneys representing them have argued that there was no contingency plan for a ransomware attack. Whether or not that argument holds up in court, the lesson for any organization is the same: the plan for how operations continue while systems are down is a business continuity question, not only an IT question.
What Unfolds in a Cyberattack?
Understanding what unfolds during an incident is the first step toward preparing for one. Organizations typically face a rapid combination of challenges:
- System outages that halt operations.
- Data inaccessibility or encryption (ransomware).
- Security containment measures that restrict access.
- Manual workarounds that slow productivity.
Even well-managed IT environments aren't immune. The difference between a minor incident and a major crisis often comes down to how quickly your team can detect the attack, contain it, and recover from it.
Key Lessons From the Kettering Health Cyberattack
Rather than dissecting any single organization's response, here are the broader lessons that apply to virtually every business.
1. Downtime Has Real, Measurable Business Impact
When systems go down (even briefly), teams scramble to manual processes or halt work entirely. Customer-facing operations stall. Revenue slows. Reputational damage accumulates by the hour. The financial cost of unplanned downtime is often far higher than the cost of the preventive measures that could have reduced it.
2. Visibility and Monitoring Aren't Optional
Many cyberattacks go undetected for days or weeks. In this case, it was 41 days. Early detection is one of the highest-leverage investments an organization can make. The faster you spot an anomaly, the smaller the blast radius, and the less data an attacker has time to copy before the encryption step.
3. Recovery Speed Matters as Much as Prevention
There is no such thing as a 100% secure environment. The organizations that fare best aren't just the ones that block the attack. They are the ones that have a plan for what to do if something gets through.
4. The Ransom Decision Is Separate From the Recovery Plan
The FBI generally discourages paying ransoms, and many organizations decline for good reasons. But declining to pay only works as a strategy if you can restore operations without the attacker's cooperation. That depends entirely on having backups the attacker could not reach, and a tested process for restoring from them.
How to Prevent Cyberattacks
Prevention is about reducing your attack surface and making it harder for threats to succeed, not achieving an impossible standard of perfect security. Cyberattacks are constantly evolving, and no environment is completely immune. The following controls help create meaningful friction for attackers and can significantly reduce your risk of a successful breach.
A strong baseline for cyberattack prevention includes:
Layered Cybersecurity Architecture
- Next-generation firewalls.
- Endpoint detection and response (EDR).
- Network segmentation to contain lateral movement.
Proactive 24/7/365 Monitoring
- Real-time alerting on suspicious activity.
- Behavioral anomaly detection.
- Human-reviewed escalation, not just automated noise.
Identity and Access Controls
- Zero-trust policies and multi-factor authentication (MFA) across all systems.
- Least-privilege access policies so compromised credentials do limited damage.
Consistent Patch Management
- Regular operating system and application updates.
- Vulnerability scanning with structured remediation workflows.
End-User Cybersecurity Awareness Training
- Regular training so employees can recognize phishing and social engineering, which remain the most common entry points.
These controls create meaningful friction for attackers, but they must be paired with something equally important: a tested recovery plan. For a deeper look at how these controls overlap, and what each one cannot do on its own, see Layered Security: Why Patching Alone Is Not Enough.
What to Do If Your Business Is Hit
When an incident occurs, the first few minutes matter enormously. Here is a response framework that works.
Step 1: Contain the Threat
- Isolate affected systems from the rest of your network.
- Disable or rotate compromised credentials immediately.
- Block lateral movement before it spreads further.
Step 2: Activate Incident Response
- Engage your internal team and any external cybersecurity partners.
- Document every action taken. This is critical for post-incident analysis and potential legal requirements.
- Maintain clear, factual communication with leadership and key stakeholders.
Step 3: Shift to Business Continuity Mode
- Activate backup systems or failover environments.
- Prioritize your most critical applications and workflows.
- Set realistic timelines and communicate them clearly.
Step 4: Begin Structured Recovery
- Restore only from clean, verified backups.
- Validate full system integrity before bringing anything back online.
- Conduct a post-incident review to close the gaps that were exploited.
Disaster Recovery: The Difference Between Hours and Days
This is where organizations are either prepared or left with real gaps in their resiliency. A modern disaster recovery strategy isn't just about having backups. It is about having the right backups, regularly tested, in an architecture designed to recover fast.
A modern disaster recovery strategy should include:
Immutable, Tested Backups
- Immutable backups cannot be altered or encrypted by ransomware, a critical distinction when attackers have had weeks inside the network.
- Regular recovery testing (not just backup success logs).
Failover Capacity Outside the Affected Environment
- The ability to shift workloads between on-premises and cloud environments reduces exposure to single points of failure.
- A well-designed architecture means a downed server does not have to mean a downed business.
Clearly Defined Recovery Objectives
Two metrics every organization should know:
- Recovery Time Objective (RTO): How quickly must your systems be back online?
- Recovery Point Objective (RPO): How much data can your business afford to lose?
If you do not have documented answers to both of those questions, your disaster recovery plan isn't complete.
In practice, the difference between a well-designed, regularly tested recovery strategy and an untested one often comes down to whether your business is down for hours or for days.
Infrastructure Designed for Resiliency, Not Just Uptime
At DataYard, we have seen firsthand how much infrastructure design can impact real-world outcomes. Supporting high-demand platforms like MegaMillions during billion-dollar lottery events requires environments built for extreme availability, where performance, redundancy, and rapid recovery are all taken into account.
That same philosophy applies directly to cybersecurity resiliency. Environments designed with recovery in mind can significantly reduce downtime, from days to hours, depending on how systems are architected and tested. Read the MegaMillions case study to see what that looks like in practice.
Building a More Resilient Organization After the Kettering Health Cyberattack
The most important takeaway from events like the Kettering Health cyberattack isn't fear. It is urgency around preparation.
Organizations that invest in proactive monitoring, well-architected infrastructure, tested disaster recovery, and experienced engineers are in a measurably stronger position to maintain operations when incidents occur. And they do occur.
The goal isn't just prevention. It is the ability to recover quickly, maintain operations, and move forward with confidence.
Frequently Asked Questions
What Happened in the Kettering Health Cyberattack?
On May 20, 2025, Kettering Health, a nonprofit healthcare network in western Ohio, was hit by a ransomware attack carried out by the Interlock ransomware group. The attack encrypted critical systems, took down phone lines and the MyChart patient portal, forced the cancellation of elective procedures, and disrupted operations across 14 medical centers. Kettering Health has been widely reported as declining to pay the ransom, and it reported a return to normal operations on June 10, 2025.
How Many People Were Affected by the Kettering Health Data Breach?
In April 2026, the HHS Office for Civil Rights breach portal was updated to show 1,695,382 individuals affected. Exposed information reportedly included names, Social Security numbers, financial account numbers, driver's license and passport numbers, medical information, and account credentials.
How Long Were Attackers Inside Kettering Health's Network?
According to Kettering Health's own notice, unauthorized access began on April 9, 2025 and continued until May 20, 2025, when the ransomware was deployed and discovered. That is roughly 41 days.
Did Kettering Health Pay the Ransom?
Multiple news outlets reported that Kettering Health declined to pay, and the Interlock group subsequently published the stolen data. Kettering Health has stated it would not comment on specific operational details of its response. Either way, the breach notification obligations were the same.
What Can Businesses Learn From the Kettering Health Cyberattack?
The biggest takeaway is that prevention alone isn't enough. Even well-resourced organizations can be targeted. What separates a manageable incident from a prolonged crisis is having strong cybersecurity controls, real-time monitoring, and a tested disaster recovery plan already in place before an attack occurs.
How Can Businesses Prevent a Cyberattack Like This?
No environment is completely immune, but layered cybersecurity measures can significantly reduce risk. This includes zero-trust policies, next-generation firewalls, endpoint detection and response (EDR), multi-factor authentication (MFA), network segmentation, end-user cybersecurity awareness training, and consistent patch management. Prevention should always be paired with a solid recovery strategy.
What Should You Do If Your Business Experiences a Cyberattack?
Act fast and follow a structured response: isolate affected systems to contain the threat, disable compromised credentials, activate your incident response plan, and communicate clearly with stakeholders. Once the threat is contained, restore operations from clean, verified backups and validate system integrity before bringing anything back online.
How Long Does It Take to Recover From a Cyberattack?
It depends on how prepared your environment is. Organizations with failover capacity and regularly tested recovery plans can often restore critical systems in hours. Those relying on untested backups or a single environment may face days or weeks of disruption. Kettering Health's outage lasted roughly three weeks.
What Is the Difference Between Backup and Disaster Recovery?
A backup is a copy of your data. Disaster recovery is the complete process of restoring your systems, applications, and operations after an incident. Backups are a critical part of that process, but on their own they aren't enough. A true disaster recovery strategy includes documented recovery procedures, defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs), and regular testing. Immutable backups, which cannot be altered or encrypted by ransomware, add an additional layer of protection.
How Often Should Disaster Recovery Plans Be Tested?
Disaster recovery plans should be tested regularly, at least annually, and ideally more often for critical systems. Testing confirms that backups are usable and that recovery processes work as expected under real-world conditions.
Is My Business Too Small to Be a Target for Cyberattacks?
No. Small and midsize businesses are frequently targeted because they often have fewer cybersecurity resources. The lessons from the Kettering Health cyberattack apply regardless of your organization's size or industry.
Related pages: Disaster Recovery Planning | Cybersecurity | Immutable Backups


