Kettering Health A.I CyberSecurity Scoring
Kettering Health
Company Information
Website:http://www.ketteringhealth.org
Employees number:8,058
Number of followers:37,866
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:ketteringhealth.org
Kettering Health Risk Score (AI oriented)
Between 0 and 549
Kettering HealthHospitals and Health Care
Updated:
23/06/2026
23/06/2026
450/1000
Critical
C
Kettering Health Global Score (TPRM)
xxxx
Kettering HealthHospitals and Health Care
Score locked

Kettering HealthCritical
Current Score
450C (CRITICAL)
01000
5 incidents
-162 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
463
JULY 2026
452
JUNE 2026
449
MAY 2026
440
APRIL 2026
434
MARCH 2026
425
FEBRUARY 2026
412
JANUARY 2026
402
DECEMBER 2025
390
NOVEMBER 2025
387
OCTOBER 2025
535
Ransomware
20 Oct 2025 • Kettering Health
Kettering Health
ClickFix (Fake CAPTCHA) Social Engineering Attacks
373
CRITICAL-162
KET5232452102025
Kettering Health, a major healthcare provider, fell victim to a ClickFix attack linked to the Interlock ransomware group, resulting in a significant data breach. The attack exploited social engineering tactics, tricking employees into executing malicious scripts via browser-based lures (e.g., fake CAPTCHAs or error-fixing prompts). The malicious payload was copied to the clipboard via obfuscated JavaScript and executed locally, bypassing traditional email security and endpoint detection. The breach compromised sensitive patient and employee data, including medical records, financial details, and personally identifiable information (PII). The attack leveraged SEO poisoning and malvertising via Google Search, evading conventional phishing defenses. Despite EDR (Endpoint Detection and Response) being the last line of defense, the obfuscated, user-initiated commands delayed detection, allowing the ransomware to encrypt critical systems. The incident disrupted healthcare operations, risked patient safety due to delayed treatments, and exposed Kettering Health to reputational damage, financial penalties, and potential legal liabilities. The breach underscored vulnerabilities in both technical controls and user awareness, particularly against browser-based, fileless attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
532
MAY 2025
522
Cyber Attack
21 May 2025 • Kettering Health
Kettering Health: Kettering Health hit by cyberattack
Kettering Health Cyberattack
505
CRITICAL-17
KET1768401229
Kettering Health Hit by Cyberattack in Latest Healthcare Sector Breach
Kettering Health, a major healthcare provider serving the Greater Cincinnati and Northern Kentucky region, has confirmed a cyberattack disrupting its operations. While details remain limited, the incident highlights the ongoing vulnerability of healthcare systems to digital threats.
The attack was disclosed amid a broader wave of cyber incidents targeting medical institutions, where sensitive patient data and critical infrastructure are prime targets. Kettering Health has not released specifics on the nature of the breach, the extent of compromised data, or the attackers’ motives. However, such incidents often involve ransomware, data theft, or operational disruptions.
Healthcare cyberattacks can delay patient care, expose confidential records, and incur significant financial and reputational costs. Kettering Health joins a growing list of providers forced to navigate recovery efforts while maintaining essential services. The incident underscores the persistent risks faced by the sector, even as organizations invest in cybersecurity defenses.
No timeline for full restoration has been provided, and investigations are ongoing. Further updates are expected as the situation develops.
INCIDENT DETAILS -
TYPE
REFERENCES
MAY 2025
644
Ransomware
20 May 2025 • Kettering Health
Kettering Health
Ransomware Attack on Kettering Health Disrupts Patient Care Systems
504
CRITICAL-140
KET5372653112625
Kettering Health, a major Ohio-based hospital network with 14 medical centers and over 1,800 medical professionals, suffered a ransomware attack on May 20, 2025, executed by the Interlock ransomware group (RaaS model). The attack triggered a comprehensive IT failure, forcing the cancellation of all elective procedures, disrupting patient care systems, and placing emergency departments on diversion status—redirecting ambulances to other facilities. The incident involved lateral movement via RDP, potential use of malicious DLLs (rundll32.exe), and double extortion (data encryption + theft). Scam calls targeting patients for credit card details were reported, suggesting data exfiltration. Neighboring hospitals, like Premier Health, declared a ‘code yellow’ due to increased patient influx. The attack severely impacted operational continuity, patient safety, and regional healthcare resilience, with recovery efforts ongoing alongside cybersecurity teams. The long-term risks include follow-up financial fraud, reputational damage, and potential regulatory penalties for compromised patient data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2025
695
Breach
09 Apr 2025 • Kettering Health
Kettering Health: KH Credit Union Data Breach Lawsuit Investigation
KH Credit Union Data Breach Exposes Sensitive Member Information
641
CRITICAL-54
KET1782239933
KH Credit Union Data Breach Exposes Sensitive Member Information
A data breach at KH Credit Union, a Dayton, Ohio-based financial institution, has exposed sensitive personal and financial information of its members. The incident stemmed from unauthorized access to systems managed by Kettering Health, which handles certain operations for the credit union.
The breach was detected on May 20, 2025, after suspicious activity was identified on Kettering Health’s network. An investigation revealed that unauthorized access occurred between April 9 and May 20, 2025, during which files containing member data may have been viewed or exfiltrated. The breach was confined to Kettering Health’s systems and did not directly involve KH Credit Union’s own network.
Exposed data includes:
- Full names
- Bank and financial account numbers
- Medical billing and claims information
- Patient account numbers
- Social Security numbers
- Driver’s license and state ID numbers
KH Credit Union, founded in 1964, serves members with a range of financial services, emphasizing privacy and security. The breach has prompted legal action, with Shamis & Gentile P.A., a class action law firm, investigating potential compensation for affected individuals.
No further details on the scope of impacted members or the attackers’ identity have been disclosed. The incident underscores the risks of third-party system vulnerabilities in financial data security.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2024
775
Ransomware
16 Jun 2024 • Kettering Health
Kettering Health
Ransomware Attack on Kettering Health Disrupts Operations for Two Weeks
679
CRITICAL-96
KET1270312100325
Kettering Health, a major Ohio-based healthcare network with multiple medical and emergency centers, suffered a severe ransomware attack leading to a system-wide technology outage lasting over two weeks. The attack disrupted electronic health records (Epic system), forcing staff to revert to manual (pen-and-paper) operations. Critical services were severely impacted: emergency rooms closed, medication refills delayed (risking patient seizures), ambulances diverted due to prolonged wait times, and life-saving procedures canceled—including MRIs, cancer follow-ups, open-heart surgery prep, and chemotherapy. Phone lines and digital communications failed, leaving patients unable to contact doctors. While Kettering restored core EHR functions, the Interlock ransomware gang claimed responsibility, stating they had compromised and secured vital files. The attack mirrors a broader 2024 trend of devastating healthcare breaches, though Kettering has not confirmed data exfiltration or the scope of stolen records. The operational chaos threatened patient safety, with some facing potentially fatal delays in critical treatments.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Kettering Health ??
What was Kettering Health's A.I Rankiteo Cyber Score in July 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in June 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in May 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in April 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in March 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in February 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in January 2026 ??
What was Kettering Health's A.I Rankiteo Cyber Score in December 2025 ??
What was Kettering Health's A.I Rankiteo Cyber Score in November 2025 ??
What was Kettering Health's A.I Rankiteo Cyber Score in October 2025 ??
What was Kettering Health's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Kettering Health's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Kettering Health ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Kettering Health's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?