Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kettering Health

Kettering Health Vendor Cyber Rating & Cyber Score

ketteringhealth.org

As a faith-based, nonprofit healthcare system, Kettering Health's mission is to live God's love by promoting and restoring health. We're made up of 14 medical centers and more than 120 outpatient locations throughout western Ohio, as well as Kettering Health Medical Group. With more than 700 board-certified providers, we're dedicated to elevating the health, healing, and hope of our community.


Kettering Health A.I CyberSecurity Scoring

Kettering Health
Company Information
Website:http://www.ketteringhealth.org
Employees number:8,058
Number of followers:37,866
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:ketteringhealth.org
Kettering Health Risk Score (AI oriented)
Between 0 and 549
logo
Kettering HealthHospitals and Health Care
Updated:
23/06/2026
450/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kettering Health Global Score (TPRM)
xxxx
logo
Kettering HealthHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kettering Health
Kettering HealthCritical
Current Score
450C (CRITICAL)
01000
5 incidents
-162 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
463Before Incident
JULY 2026
452Before Incident
JUNE 2026
449Before Incident
MAY 2026
440Before Incident
APRIL 2026
434Before Incident
MARCH 2026
425Before Incident
FEBRUARY 2026
412Before Incident
JANUARY 2026
402Before Incident
DECEMBER 2025
390Before Incident
NOVEMBER 2025
387Before Incident
OCTOBER 2025
535Before Incident
Ransomware
20 Oct 2025Kettering Health
Kettering Health

ClickFix (Fake CAPTCHA) Social Engineering Attacks

373After Incident
CRITICAL-162
KET5232452102025
Kettering Health, a major healthcare provider, fell victim to a ClickFix attack linked to the Interlock ransomware group, resulting in a significant data breach. The attack exploited social engineering tactics, tricking employees into executing malicious scripts via browser-based lures (e.g., fake CAPTCHAs or error-fixing prompts). The malicious payload was copied to the clipboard via obfuscated JavaScript and executed locally, bypassing traditional email security and endpoint detection. The breach compromised sensitive patient and employee data, including medical records, financial details, and personally identifiable information (PII). The attack leveraged SEO poisoning and malvertising via Google Search, evading conventional phishing defenses. Despite EDR (Endpoint Detection and Response) being the last line of defense, the obfuscated, user-initiated commands delayed detection, allowing the ransomware to encrypt critical systems. The incident disrupted healthcare operations, risked patient safety due to delayed treatments, and exposed Kettering Health to reputational damage, financial penalties, and potential legal liabilities. The breach underscored vulnerabilities in both technical controls and user awareness, particularly against browser-based, fileless attacks.
INCIDENT DETAILS -
TYPE
Social EngineeringMalvertisingSEO PoisoningClipboard HijackingFake CAPTCHAWatering Hole Attack
MOTIVATION
Financial Gain (Ransomware, Data Theft)Credential HarvestingLateral Movement for Targeted AttacksEspionage (APT-Linked)Session Hijacking
IMPACT
Credentials (Stored in Browsers)Cookies (Session Tokens)Potentially PII (Depending on Follow-on Exploitation)Endpoints (User Devices)Browsers (Chrome, Edge, Firefox, etc.)Potential Network Lateral MovementDisruption from Ransomware (Linked Cases)Incident Response OverheadProductivity Loss (User Remediation)Erosion of Trust (Phishing/Social Engineering)Associated with High-Profile Breaches (e.g., Healthcare, Education)High (If Credentials/Cookies Stolen)Potential (If Browser-Stored Payment Data Accessed)
DATA BREACH
CredentialsSession CookiesPotentially PII (Context-Dependent)High (If Credentials/Cookies Lead to Further Compromise)Likely (For Ransomware/APT Groups)Possible (If Follow-on Attacks Occur)
SEPTEMBER 2025
532Before Incident
MAY 2025
522Before Incident
Cyber Attack
21 May 2025Kettering Health
Kettering Health: Kettering Health hit by cyberattack

Kettering Health Cyberattack

505After Incident
CRITICAL-17
KET1768401229
Kettering Health Hit by Cyberattack in Latest Healthcare Sector Breach Kettering Health, a major healthcare provider serving the Greater Cincinnati and Northern Kentucky region, has confirmed a cyberattack disrupting its operations. While details remain limited, the incident highlights the ongoing vulnerability of healthcare systems to digital threats. The attack was disclosed amid a broader wave of cyber incidents targeting medical institutions, where sensitive patient data and critical infrastructure are prime targets. Kettering Health has not released specifics on the nature of the breach, the extent of compromised data, or the attackers’ motives. However, such incidents often involve ransomware, data theft, or operational disruptions. Healthcare cyberattacks can delay patient care, expose confidential records, and incur significant financial and reputational costs. Kettering Health joins a growing list of providers forced to navigate recovery efforts while maintaining essential services. The incident underscores the persistent risks faced by the sector, even as organizations invest in cybersecurity defenses. No timeline for full restoration has been provided, and investigations are ongoing. Further updates are expected as the situation develops.
INCIDENT DETAILS -
TYPE
Cyberattack
MAY 2025
644Before Incident
Ransomware
20 May 2025Kettering Health
Kettering Health

Ransomware Attack on Kettering Health Disrupts Patient Care Systems

504After Incident
CRITICAL-140
KET5372653112625
Kettering Health, a major Ohio-based hospital network with 14 medical centers and over 1,800 medical professionals, suffered a ransomware attack on May 20, 2025, executed by the Interlock ransomware group (RaaS model). The attack triggered a comprehensive IT failure, forcing the cancellation of all elective procedures, disrupting patient care systems, and placing emergency departments on diversion status—redirecting ambulances to other facilities. The incident involved lateral movement via RDP, potential use of malicious DLLs (rundll32.exe), and double extortion (data encryption + theft). Scam calls targeting patients for credit card details were reported, suggesting data exfiltration. Neighboring hospitals, like Premier Health, declared a ‘code yellow’ due to increased patient influx. The attack severely impacted operational continuity, patient safety, and regional healthcare resilience, with recovery efforts ongoing alongside cybersecurity teams. The long-term risks include follow-up financial fraud, reputational damage, and potential regulatory penalties for compromised patient data.
INCIDENT DETAILS -
TYPE
ransomwaredata breachcyberattack
MOTIVATION
financial gain (double extortion)data theft
IMPACT
electronic health records (EHR)patient care systemspayment systemscommunication systemscancellation of elective proceduresemergency department diversionsactivation of downtime proceduresdisruption of patient caresuspension of payment-related calls
DATA BREACH
patient data (potential)payment information (targeted in scam calls)Sensitivity Of Data: high (healthcare and financial data)
APRIL 2025
695Before Incident
Breach
09 Apr 2025Kettering Health
Kettering Health: KH Credit Union Data Breach Lawsuit Investigation

KH Credit Union Data Breach Exposes Sensitive Member Information

641After Incident
CRITICAL-54
KET1782239933
KH Credit Union Data Breach Exposes Sensitive Member Information A data breach at KH Credit Union, a Dayton, Ohio-based financial institution, has exposed sensitive personal and financial information of its members. The incident stemmed from unauthorized access to systems managed by Kettering Health, which handles certain operations for the credit union. The breach was detected on May 20, 2025, after suspicious activity was identified on Kettering Health’s network. An investigation revealed that unauthorized access occurred between April 9 and May 20, 2025, during which files containing member data may have been viewed or exfiltrated. The breach was confined to Kettering Health’s systems and did not directly involve KH Credit Union’s own network. Exposed data includes: - Full names - Bank and financial account numbers - Medical billing and claims information - Patient account numbers - Social Security numbers - Driver’s license and state ID numbers KH Credit Union, founded in 1964, serves members with a range of financial services, emphasizing privacy and security. The breach has prompted legal action, with Shamis & Gentile P.A., a class action law firm, investigating potential compensation for affected individuals. No further details on the scope of impacted members or the attackers’ identity have been disclosed. The incident underscores the risks of third-party system vulnerabilities in financial data security.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive personal and financial informationSystems Affected: Kettering Health’s systemsLegal Liabilities: Potential class action lawsuitIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Full namesBank and financial account numbersMedical billing and claims informationPatient account numbersSocial Security numbersDriver’s license and state ID numbersSensitivity Of Data: HighData Exfiltration: PossiblePersonally Identifiable Information: Yes
JUNE 2024
775Before Incident
Ransomware
16 Jun 2024Kettering Health
Kettering Health

Ransomware Attack on Kettering Health Disrupts Operations for Two Weeks

679After Incident
CRITICAL-96
KET1270312100325
Kettering Health, a major Ohio-based healthcare network with multiple medical and emergency centers, suffered a severe ransomware attack leading to a system-wide technology outage lasting over two weeks. The attack disrupted electronic health records (Epic system), forcing staff to revert to manual (pen-and-paper) operations. Critical services were severely impacted: emergency rooms closed, medication refills delayed (risking patient seizures), ambulances diverted due to prolonged wait times, and life-saving procedures canceled—including MRIs, cancer follow-ups, open-heart surgery prep, and chemotherapy. Phone lines and digital communications failed, leaving patients unable to contact doctors. While Kettering restored core EHR functions, the Interlock ransomware gang claimed responsibility, stating they had compromised and secured vital files. The attack mirrors a broader 2024 trend of devastating healthcare breaches, though Kettering has not confirmed data exfiltration or the scope of stolen records. The operational chaos threatened patient safety, with some facing potentially fatal delays in critical treatments.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial (ransom demand)
IMPACT
Electronic Health Record (EHR) system (Epic)Communication systemsPhone linesPatient care coordination toolsEmergency room operationsAppointment scheduling systemsDowntime: 2+ weeks (ongoing recovery as of last update)Manual (pen-and-paper) processes for patient recordsCanceled medical procedures (MRIs, chemotherapy, open-heart surgery prep, cancer follow-ups)Closed or limited emergency room servicesDelayed medication refillsAmbulance diversions due to prolonged patient processing timesSpotty phone serviceInability to contact doctors' officesMedication refill delays (risking withdrawal seizures)Canceled critical appointmentsLong wait times in emergency roomsRecommendations to avoid Kettering Health servicesBrand Reputation Impact: High (public advisories to avoid facilities, negative local subreddit discussions, media coverage of operational failures)
DATA BREACH
Data Exfiltration: Unconfirmed (hackers claimed to secure 'most vital files,' but Kettering Health did not disclose details)Data Encryption: Yes (ransomware encrypted systems)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kettering Health ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Kettering Health's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Kettering Health's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kettering Health ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kettering Health's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?