Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kettering Health

Kettering Health Vendor Cyber Rating & Cyber Score

ketteringhealth.org

As a faith-based, nonprofit healthcare system, Kettering Health's mission is to live God's love by promoting and restoring health. We're made up of 14 medical centers and more than 120 outpatient locations throughout western Ohio, as well as Kettering Health Medical Group. With more than 700 board-certified providers, we're dedicated to elevating the health, healing, and hope of our community.


Kettering Health A.I CyberSecurity Scoring

Kettering Health
Company Information
Website:http://www.ketteringhealth.org
Employees number:8,058
Number of followers:37,866
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:ketteringhealth.org
Kettering Health Risk Score (AI oriented)
Between 0 and 549
logo
Kettering HealthHospitals and Health Care
Updated:
29/03/2026
468/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kettering Health Global Score (TPRM)
xxxx
logo
Kettering HealthHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kettering Health
Kettering HealthCritical
Current Score
468C (CRITICAL)
01000
4 incidents
-163 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
490Before Incident
MAY 2026
482Before Incident
APRIL 2026
476Before Incident
MARCH 2026
468Before Incident
FEBRUARY 2026
456Before Incident
JANUARY 2026
446Before Incident
DECEMBER 2025
436Before Incident
NOVEMBER 2025
433Before Incident
OCTOBER 2025
598Before Incident
Ransomware
20 Oct 2025Kettering Health
Kettering Health

ClickFix (Fake CAPTCHA) Social Engineering Attacks

435After Incident
CRITICAL-163
KET5232452102025
Kettering Health, a major healthcare provider, fell victim to a ClickFix attack linked to the Interlock ransomware group, resulting in a significant data breach. The attack exploited social engineering tactics, tricking employees into executing malicious scripts via browser-based lures (e.g., fake CAPTCHAs or error-fixing prompts). The malicious payload was copied to the clipboard via obfuscated JavaScript and executed locally, bypassing traditional email security and endpoint detection. The breach compromised sensitive patient and employee data, including medical records, financial details, and personally identifiable information (PII). The attack leveraged SEO poisoning and malvertising via Google Search, evading conventional phishing defenses. Despite EDR (Endpoint Detection and Response) being the last line of defense, the obfuscated, user-initiated commands delayed detection, allowing the ransomware to encrypt critical systems. The incident disrupted healthcare operations, risked patient safety due to delayed treatments, and exposed Kettering Health to reputational damage, financial penalties, and potential legal liabilities. The breach underscored vulnerabilities in both technical controls and user awareness, particularly against browser-based, fileless attacks.
INCIDENT DETAILS -
TYPE
Social EngineeringMalvertisingSEO PoisoningClipboard HijackingFake CAPTCHAWatering Hole Attack
MOTIVATION
Financial Gain (Ransomware, Data Theft)Credential HarvestingLateral Movement for Targeted AttacksEspionage (APT-Linked)Session Hijacking
IMPACT
Credentials (Stored in Browsers)Cookies (Session Tokens)Potentially PII (Depending on Follow-on Exploitation)Endpoints (User Devices)Browsers (Chrome, Edge, Firefox, etc.)Potential Network Lateral MovementDisruption from Ransomware (Linked Cases)Incident Response OverheadProductivity Loss (User Remediation)Erosion of Trust (Phishing/Social Engineering)Associated with High-Profile Breaches (e.g., Healthcare, Education)High (If Credentials/Cookies Stolen)Potential (If Browser-Stored Payment Data Accessed)
DATA BREACH
CredentialsSession CookiesPotentially PII (Context-Dependent)High (If Credentials/Cookies Lead to Further Compromise)Likely (For Ransomware/APT Groups)Possible (If Follow-on Attacks Occur)
SEPTEMBER 2025
580Before Incident
AUGUST 2025
575Before Incident
JULY 2025
569Before Incident
MAY 2025
574Before Incident
Cyber Attack
21 May 2025Kettering Health
Kettering Health: Kettering Health hit by cyberattack

Kettering Health Cyberattack

557After Incident
CRITICAL-17
KET1768401229
Kettering Health Hit by Cyberattack in Latest Healthcare Sector Breach Kettering Health, a major healthcare provider serving the Greater Cincinnati and Northern Kentucky region, has confirmed a cyberattack disrupting its operations. While details remain limited, the incident highlights the ongoing vulnerability of healthcare systems to digital threats. The attack was disclosed amid a broader wave of cyber incidents targeting medical institutions, where sensitive patient data and critical infrastructure are prime targets. Kettering Health has not released specifics on the nature of the breach, the extent of compromised data, or the attackers’ motives. However, such incidents often involve ransomware, data theft, or operational disruptions. Healthcare cyberattacks can delay patient care, expose confidential records, and incur significant financial and reputational costs. Kettering Health joins a growing list of providers forced to navigate recovery efforts while maintaining essential services. The incident underscores the persistent risks faced by the sector, even as organizations invest in cybersecurity defenses. No timeline for full restoration has been provided, and investigations are ongoing. Further updates are expected as the situation develops.
INCIDENT DETAILS -
TYPE
Cyberattack
MAY 2025
696Before Incident
Ransomware
20 May 2025Kettering Health
Kettering Health

Ransomware Attack on Kettering Health Disrupts Patient Care Systems

556After Incident
CRITICAL-140
KET5372653112625
Kettering Health, a major Ohio-based hospital network with 14 medical centers and over 1,800 medical professionals, suffered a ransomware attack on May 20, 2025, executed by the Interlock ransomware group (RaaS model). The attack triggered a comprehensive IT failure, forcing the cancellation of all elective procedures, disrupting patient care systems, and placing emergency departments on diversion status—redirecting ambulances to other facilities. The incident involved lateral movement via RDP, potential use of malicious DLLs (rundll32.exe), and double extortion (data encryption + theft). Scam calls targeting patients for credit card details were reported, suggesting data exfiltration. Neighboring hospitals, like Premier Health, declared a ‘code yellow’ due to increased patient influx. The attack severely impacted operational continuity, patient safety, and regional healthcare resilience, with recovery efforts ongoing alongside cybersecurity teams. The long-term risks include follow-up financial fraud, reputational damage, and potential regulatory penalties for compromised patient data.
INCIDENT DETAILS -
TYPE
ransomwaredata breachcyberattack
MOTIVATION
financial gain (double extortion)data theft
IMPACT
electronic health records (EHR)patient care systemspayment systemscommunication systemscancellation of elective proceduresemergency department diversionsactivation of downtime proceduresdisruption of patient caresuspension of payment-related calls
DATA BREACH
patient data (potential)payment information (targeted in scam calls)Sensitivity Of Data: high (healthcare and financial data)
JUNE 2024
775Before Incident
Ransomware
16 Jun 2024Kettering Health
Kettering Health

Ransomware Attack on Kettering Health Disrupts Operations for Two Weeks

679After Incident
CRITICAL-96
KET1270312100325
Kettering Health, a major Ohio-based healthcare network with multiple medical and emergency centers, suffered a severe ransomware attack leading to a system-wide technology outage lasting over two weeks. The attack disrupted electronic health records (Epic system), forcing staff to revert to manual (pen-and-paper) operations. Critical services were severely impacted: emergency rooms closed, medication refills delayed (risking patient seizures), ambulances diverted due to prolonged wait times, and life-saving procedures canceled—including MRIs, cancer follow-ups, open-heart surgery prep, and chemotherapy. Phone lines and digital communications failed, leaving patients unable to contact doctors. While Kettering restored core EHR functions, the Interlock ransomware gang claimed responsibility, stating they had compromised and secured vital files. The attack mirrors a broader 2024 trend of devastating healthcare breaches, though Kettering has not confirmed data exfiltration or the scope of stolen records. The operational chaos threatened patient safety, with some facing potentially fatal delays in critical treatments.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial (ransom demand)
IMPACT
Electronic Health Record (EHR) system (Epic)Communication systemsPhone linesPatient care coordination toolsEmergency room operationsAppointment scheduling systemsDowntime: 2+ weeks (ongoing recovery as of last update)Manual (pen-and-paper) processes for patient recordsCanceled medical procedures (MRIs, chemotherapy, open-heart surgery prep, cancer follow-ups)Closed or limited emergency room servicesDelayed medication refillsAmbulance diversions due to prolonged patient processing timesSpotty phone serviceInability to contact doctors' officesMedication refill delays (risking withdrawal seizures)Canceled critical appointmentsLong wait times in emergency roomsRecommendations to avoid Kettering Health servicesBrand Reputation Impact: High (public advisories to avoid facilities, negative local subreddit discussions, media coverage of operational failures)
DATA BREACH
Data Exfiltration: Unconfirmed (hackers claimed to secure 'most vital files,' but Kettering Health did not disclose details)Data Encryption: Yes (ransomware encrypted systems)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kettering Health ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Kettering Health's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kettering Health ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kettering Health's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?