Executive summary

On August 23, 2026 at 08:08 UTC, the Kazu ransomware group posted on its victim portal (leak-site) a claim of attack against the Dr. Akbar Niazi Teaching Hospital (ANTH), a 500-bed teaching hospital in Islamabad, Pakistan. Kazu is an emerging group (active since September 2025) specializing in double extortion (encrypt + exfiltrate) with a marked pattern toward healthcare, government and financial targets in Southeast Asia, the Middle East and Latin America. ANTH offers emergency care, surgery, cardiology, orthopedics, pediatrics, gynecology, oncology, diagnostic laboratory and specialized consultations; as a teaching hospital it is affiliated with medical training programs. HudsonRock has detected infostealer activity on credentials associated with the anth.pk domain, suggesting prior credential compromise that likely facilitated initial access. Event severity is CRITICAL due to the combination of an active teaching hospital, possible exfiltration of medical records and Kazu’s explicit motivation against the health sector.

Key points

  • Victim: Dr. Akbar Niazi Teaching Hospital (ANTH) — 500 beds, Islamabad, Pakistan.
  • Attacker group: Kazu — double extortion (encrypt + exfiltrate), active since Sept-2025, focus on healthcare/government/finance.
  • Claim date: 2026-08-23 08:08 UTC, on the leak-site monitored by ransomware.live.
  • Probable attack vector: credentials previously compromised by infostealer (HudsonRock detects malicious activity on anth.pk), suggesting an IAB (Initial Access Broker) pattern followed by ransomware — the same pattern observed in recent hospital campaigns.
  • Data at risk: medical records, patient demographic data, healthcare professional data, billing data, possible clinical research data (teaching hospital), internal credentials.
  • Affected hospital services: emergency, surgery, cardiology, orthopedics, pediatrics, gynecology, oncology, diagnostic laboratory, specialized consultations. As a teaching hospital, also medical training programs.
  • Kazu pattern in healthcare: three of its most recent claimed victims (23-Aug-2026) are all health sector: ANTH, Centro Médico Especializado OSI: Healthcare Solutions, and PappyJoe: Healthcare Management System — confirming Kazu as an active and healthcare-focused threat.
  • No public confirmation from ANTH at the time of the post. Investigation is ongoing and patient notification has not yet occurred.
  • Country: Pakistan — the competent authority is the Pakistan Information Protection Act (PIPA), GDPR-equivalent for breach notification.

Regulatory implications

FDA (US)

Not directly applicable — the hospital is not in the US. But if US patients had been treated at ANTH (medical tourism unlikely but possible in oncology), HIPAA Breach Notification Rule would apply to the referring entity.

MDR (EU)

Not directly applicable. However, any EU citizen treated at ANTH could activate the right to information under Art. 34 GDPR if the data controller (ANTH) does not notify within 72h.

GDPR

ANTH is not under direct European jurisdiction, but if it holds data of EU citizens it must notify the DPA and relevant supervisory authorities within 72h (Art. 33) if affected data includes special categories (Art. 9: health data).

NIS2 / ENS

Pakistan is not under NIS2. The Pakistan Information Protection Act (PIPA, 2024) requires notification to the national authority and to affected parties in case of breach with potential harm to fundamental rights.

HIPAA (sector reference standard)

We apply HIPAA as a good practice standard for the global healthcare sector. §164.404 — patient notification without unreasonable delay. §164.408 — notification to HHS (in this case, Pakistani equivalent). §164.402 — definition of breach includes “impermissible use or disclosure”. The potential magnitude of the incident (500 beds, teaching hospital with data of thousands of patients) suggests HIGH risk for patients.

Recommendation

Immediate actions within the next 72 hours: (1) if your hospital has Pakistani patients or partnerships with ANTH, contact the center to confirm the scope of the breach and apply protective measures to shared data; (2) verify credentials of any system that has exchanged information with ANTH in the last 12 months; (3) review VPN access and email logs looking for connections from suspicious IPs to anth.pk; (4) do not pay ransom — there is no guarantee of recovery and it funds the group; (5) monitor Kazu’s leak-site (ransomware.live) to detect ANTH data publications; (6) prepare notification kit in case your organization’s patient data was shared; (7) reinforce awareness on infostealers (RedLine, Raccoon, LummaC2) among healthcare staff — the attack vector observed at ANTH starts from credentials stolen by malware on endpoints; (8) activate MFA on all accounts that have any technical or administrative relation with Pakistani hospitals.

30-day actions: audit the security posture against the IAB → ransomware pattern, including endpoint infostealer detection (HudsonRock-style monitoring), HIS/EHR segmentation from the rest of the network, and incident response drills that assume a starting point of compromised legitimate credentials.


Source: Ransomware.live — Victim: Dr Akbar Niazi Teaching Hospital (Kazu)

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.