Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatoperational-disruptionransomware-group-operationbreach-disclosure-notification

Healthcare Cyber Incidents: Kettering Health Ransomware Litigation, Insightin Health GoAnywhere Breach, and Polish Hospital Disruption

Updated 3mo agoFirst seen Mar 12, 20263 sources

Multiple healthcare-sector cyber incidents were reported, including ongoing fallout from a major U.S. provider ransomware event. Kettering Health continues to face escalating legal exposure from a 2025 ransomware attack attributed to Interlock, which allegedly stole 941 GB of data and encrypted systems; the disruption forced shutdown of roughly 600 applications, a temporary shift to paper workflows, and delays to care while systems (including Epic EHR) were restored. Dozens of patient lawsuits have been filed and consolidated in Ohio, with claims focused not only on data theft but also alleged delayed or denied medical care during the outage.

Separately, healthcare vendor Insightin Health disclosed a 2025 security incident involving its use of the GoAnywhere managed file transfer tool, reporting that an unauthorized party accessed GoAnywhere by exploiting an “unknown design flaw” and potentially accessed files on a subset of servers between Sept 17–23, 2025; impacted data may have included names, provider names, insurance information, and member IDs (no SSNs or financial data reported). In Europe, the Independent Public Regional Hospital in Szczecin, Poland reported a March 2026 cyberattack that encrypted parts of hospital data, disrupted digital operations, and forced a temporary return to paper-based processes, while the hospital stated urgent care continued despite slower administration.

Share:
Healthcare Cyber Incidents: Kettering Health Ransomware Litigation, Insightin Health GoAnywhere Breach, and Polish Hospital Disruption
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Mar 11, 20263mo ago

Dozens of lawsuits filed over Kettering Health attack

By March 2026, dozens of lawsuits had been filed in response to the Kettering Health ransomware attack, including a consolidated complaint in Ohio state court. The suits allege data theft, negligence, and delays or denial of medical care, and seek damages and security improvements.

Mar 7, 20264mo ago

Cyberattack disrupts Polish hospital and forces paper operations

Over the weekend of March 7–8, 2026, the Independent Public Regional Hospital in Szczecin, Poland, suffered a cyberattack that encrypted part of its data and disrupted IT systems. The hospital temporarily reverted to paper-based workflows while continuing urgent treatment and admissions during restoration efforts.

Mar 4, 20264mo ago

Insightin Health submits breach notice to California AG

Insightin Health submitted a breach notification to the California Attorney General on March 4, 2026, disclosing the September 2025 unauthorized access incident. A Washington State report update cited 11,740 affected Washington residents, while the incident had not yet appeared on the HHS breach portal at the time of reporting.

Feb 12, 20264mo ago

Health plan confirms affected individuals in Insightin files

On February 12, 2026, a health plan confirmed to Insightin Health that some individuals' data was included in the affected files from the September 2025 incident. This appears to have clarified that personal data was exposed in the compromise.

Sep 30, 20259mo ago

Medusa claims Insightin Health incident on leak site

Reporting noted that the Medusa ransomware/extortion group claimed the Insightin Health incident on its leak site in September 2025. The company's later notification did not mention this public extortion claim.

Sep 17, 20259mo ago

Attacker exploits GoAnywhere flaw at Insightin Health

Insightin Health said an attacker exploited an 'unknown design flaw' in the GoAnywhere file-transfer tool and may have accessed data on a subset of servers between September 17 and September 23, 2025. The potentially exposed information included personal and health-plan-related data such as names and insurance identifiers.

Jul 21, 202511mo ago

Kettering Health reports breach to HHS OCR

Kettering Health reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights with a placeholder count of 501 affected individuals. About 10 months after the attack, the total number of affected people was still unconfirmed.

Jun 10, 20251y ago

Kettering Health says normal operations resumed

Kettering Health stated that normal operations had resumed by June 10, 2025, after weeks of disruption caused by the ransomware attack. Plaintiffs later alleged some care disruptions lasted beyond the roughly three-week systems outage.

Jun 2, 20251y ago

Epic EHR core components restored at Kettering Health

Kettering Health restored core components of its Epic electronic health record system as part of recovery from the ransomware attack. This marked a major step toward resuming normal clinical and administrative operations.

May 20, 20251y ago

Kettering Health hit by ransomware attack and major outage begins

In May 2025, Kettering Health in Ohio suffered a ransomware attack attributed to Interlock. The health system shut down roughly 600 digital applications, reverted to paper processes, and canceled appointments during response and recovery.

Apr 9, 20251y ago

Interlock gains access to Kettering Health's network

A later investigation found the Interlock ransomware group had access to Kettering Health's network beginning on April 9, 2025. During this access window, the attackers were able to access or copy files containing patient, medical, insurance, and financial data.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Healthcare Cyber Incidents: Kettering Health Ransomware Litigation, Insightin Health GoAnywhere Breach, and Polish Hospital Disruption | Mallory