The Kazu ransomware gang has posted eight healthcare organizations on its leak site in a single day, a coordinated burst spanning a 500-bed teaching hospital, a neurology clinic, and several telemedicine and medical imaging platforms.
The August 23 listings, tracked by ransomware.live, include Dr Akbar Niazi Teaching Hospital, a tertiary care hospital in Islamabad, Pakistan; Instituto Ferrero de Neurologia y Sueno, a specialized neurology and sleep center in Argentina; Brazil Mobilemed, a cloud PACS platform; Meducar and ConsultorioMovil, Brazilian telemedicine systems; Centro Medico Especializado OSI; PappyJoe, a healthcare management platform; and PawlyClinic, a veterinary care platform.
Most of the victims are small providers and software firms in Latin America, the kind of organizations that hold imaging studies, consultation records, and patient management data but rarely maintain dedicated security operations centers. GalaxyWarden’s breach index independently logged at least two of the listings, the Islamabad hospital and the Argentine institute, both rated high severity.
All of the claims are unconfirmed, and none of the victims have publicly commented. The volume of simultaneous listings suggests Kazu is running an affiliate program or working through a backlog of previously compromised networks.
The pattern is a reminder for smaller clinics and telehealth vendors that attackers treat them as low-effort targets. Offline backups, strict access controls on PACS and telemedicine portals, and vendor due diligence for cloud-hosted platforms are the controls most likely to limit damage.
Ransomware.live and GalaxyWarden’s breach index both carry the batch, giving researchers multiple independent records of the same-day listings.