Norton Healthcare agreed to pay $11 million to settle a class-action lawsuit tied to a 2023 ALPHV/BlackCat ransomware-related data theft that reportedly involved 4.7 TB of stolen data and impacted nearly 2.5 million people. The preliminary settlement provides for reimbursement claims (up to $2,500 for unreimbursed expenses), compensation for time spent responding to the incident (up to $80), and three years of medical identity monitoring, pending final court approval.
Separately, Ohio-based Kettering Health began notifying current and former patients and affiliates about a May 2025 ransomware and data theft incident claimed by the Interlock cybercrime group. Reporting indicates Interlock publicly listed Kettering Health on its leak site and claimed roughly 941–950 GB of data, and Kettering previously warned patients about scam calls from fraudsters impersonating medical bill collectors seeking credit card payments—activity consistent with post-breach social engineering and fraud attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A final court approval hearing for Norton Healthcare's preliminary $11 million settlement was scheduled for May 15 in Kentucky state court. The settlement reportedly does not require Norton to implement specific security improvements.
Norton Healthcare agreed to pay $11 million to settle a class action lawsuit over the 2023 BlackCat-related data theft. The preliminary settlement includes reimbursement for certain losses, compensation for time spent responding, and three years of medical identity monitoring, while Norton denied wrongdoing.
By February 2026, Kettering Health was notifying an unspecified number of current and former patients and affiliates about the 2025 Interlock-linked breach. The organization said it worked with federal law enforcement and was reviewing its cybersecurity policies and practices.
In July 2025, Kettering Health reported the incident to federal regulators as a hacking breach affecting 501 individuals, using that figure as a placeholder. The organization did not provide an updated total in the referenced reporting.
In June 2025, the Interlock group publicly listed Kettering Health on its leak site and claimed to have stolen roughly 941 GB of data. As of February 2026, the leak site still listed Kettering with about 950 GB allegedly available.
Kettering Health said unauthorized access to its environment lasted until May 20, 2025. The incident disrupted its IT environment for weeks, affecting patient care, canceling elective procedures, and causing emergency room diversions.
Kettering Health said unauthorized actors first accessed its environment on April 9, 2025, in an intrusion later tied to the Interlock cybercrime group. The attackers potentially viewed and acquired files containing personal, health, and financial data.
The May 2023 Norton Healthcare incident was attributed to the ALPHV/BlackCat ransomware group and ultimately affected nearly 2.5 million people. BlackCat claimed to have stolen about 4.7 TB of data, including sensitive personal, health, insurance, and financial information.
Norton Healthcare said attackers accessed certain network storage devices between May 7 and May 9, 2023, in a ransomware-related data theft incident later attributed to ALPHV/BlackCat. Norton said its medical record system and MyChart portal were not accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.