Executive summary

On August 23, 2026 between 08:07 and 08:10 UTC, the Kazu ransomware group posted at least six simultaneous claims against health-sector entities on its victim portal: PappyJoe: Healthcare Management System (India, 413 GB and 6.8 million patients PII), Mobilemed: Cloud PACS Platform (Brazil, medical imaging platform), Instituto Ferrero de Neurología y Sueño (IFN) (Argentina, neurology center), Centro Médico Especializado OSI (Peru, rehabilitation and physiotherapy), ConsultorioMovil: Telemedicine and Healthcare System (LATAM telemedicine platform) and Meducar: Telemedicine and Patient Management System (Brazil, appointment and EHR management). This is the largest coordinated Kazu wave against healthtech infrastructure documented to date and confirms the group as an active and focused threat to the health sector in LATAM and South Asia. Severity is CRITICAL due to the combination of (a) multiple simultaneous victims with exfiltrated clinical data, (b) regional cloud infrastructure affected (PACS and telemedicine platforms with cascade effect on multiple client hospitals), and (c) evidence of prior infostealer activity detected by HudsonRock on the compromised domains, suggesting a reused IAB (Initial Access Broker) → ransomware pattern across multiple targets.

Key points

  • Actor: Kazu — emerging group active since September 2025, double extortion (encrypt + exfiltrate), focus on healthcare/government/finance in Southeast Asia, the Middle East and LATAM.
  • Simultaneous wave 23-Aug-2026: 6+ health-sector victims claimed within a 3-minute window (08:07–08:10 UTC), pattern incompatible with individual opportunistic attacks.
  • Highest-impact victim confirmed: PappyJoe: Healthcare Management System (India) — 413 GB exfiltrated, 6.8 million patients with PII, ransom demanded USD 250,000 (demand prior to leak, per darkwebsonar).
  • Cascade-impact victim on LATAM radiology: Mobilemed: Cloud PACS Platform (Brazil, mobilemed.com.br) — provides cloud PACS to radiologists, hospitals and diagnostic imaging centers. Compromise exposes DICOM studies of patients seen by multiple providers.
  • Spanish-speaking LATAM victims:
    • Instituto Ferrero de Neurología y Sueño (IFN) — Argentina, ifn.com.ar. Center specialized in neurology, sleep medicine and diagnostic studies.
    • Centro Médico Especializado OSI — Peru, centromedicoosi.com. Rehabilitation, physiotherapy, chiropractic and alternative medicine.
    • ConsultorioMovil (consultoriomovil.net) and Meducar (meducar.com) — Brazil/LATAM, telemedicine, appointment management and EHR platforms for doctors and clinics.
  • Probable attack vector: credentials previously compromised by infostealers (RedLine, Raccoon, LummaC2 and others). HudsonRock detects malicious activity on the victims’ domains; pattern consistent with access purchased from Initial Access Brokers (IABs) on criminal forums.
  • Clinical data at risk: medical records, demographic data, neurophysiology and sleep studies (IFN), DICOM imaging (Mobilemed), rehabilitation records (OSI), EHR telemedicine records (ConsultorioMovil/Meducar), PII of 6.8M Indian patients (PappyJoe).
  • Documented group TTPs: double extortion, leak-site .onion publication, public demand with deadline, use of Telegram and darkweb forums for negotiation.
  • No official confirmation from victims at this time. Investigations are ongoing; local regulatory notifications (Brazil ANPD, Argentina AAIP, etc.) have not yet occurred.

Regulatory implications

FDA (US)

Not directly applicable — no victim is US-based. However, if US patients were treated at these institutions (especially PappyJoe, platform with 6.8M users), referring entities must evaluate HIPAA obligations. Additionally, US-based PACS/cloud imaging manufacturers serving Mobilemed must evaluate notification under §524B FD&C Act.

MDR (EU)

Not directly applicable — no victim is in the EU. But if these platforms served EU citizens (plausible scenario for telemedicine platforms), data controllers must notify the DPO and supervisory authority within 72h (Art. 33 GDPR) and affected parties in case of high risk (Art. 34), for affecting special categories of data (Art. 9 — health data).

GDPR (global reference standard)

Victims must apply GDPR principles as good practice: (a) Art. 33 notification to supervisory authority within 72h; (b) Art. 34 communication to data subjects when high risk to their rights exists; (c) Art. 9 special categories of data (health data) — protection standard is maximum. Affected cloud platforms (Mobilemed, ConsultorioMovil, Meducar) must assume processor responsibility and notify the controller (client hospital/clinic) without undue delay.

NIS2 / ENS

LATAM is not under NIS2/ENS, but Brazilian ANPD regulation (LGPD), Argentina Ley 25.326 Personal Data Protection and Peru Ley N.° 29733 require notification to the national authority and data subjects in case of breach with potential harm. LGPD fines can reach 2% of revenue capped at BRL 50M per incident.

HIPAA (sector reference standard)

We apply HIPAA as a good practice standard for the global healthcare sector. §164.404 patient notification without unreasonable delay; §164.408 notification to HHS (or national equivalent); §164.402 definition of breach includes impermissible use or disclosure. In PappyJoe, 6.8M patients is HIGH magnitude for mandatory notification; for Mobilemed, it depends on the number of patients in the exfiltrated DICOM studies.

Recommendation

Immediate actions within the next 72 hours:

  1. If your hospital or clinic uses Mobilemed, ConsultorioMovil or Meducar (Brazil and LATAM): assume compromise. Disconnect integrations with these platforms until official scope confirmation; review access logs to DICOM studies and medical records in the last 30 days; prepare patient notification kit.
  2. Verify credentials of any account that interacted with mobilemed.com.br, ifn.com.ar, centromedicoosi.com, consultoriomovil.net, meducar.com or pappyjoe.in in the last 12 months. Force password rotation and reset of API keys/tokens.
  3. Block known Kazu IoCs in SIEM/EDR: leak-site domains, published hashes, C2 IPs if known. Monitor entries to ransomware.live/group/kazu for updates.
  4. Enable phishing-resistant MFA (FIDO2/WebAuthn) on ALL accounts with access to EHR/PACS/RIS and telemedicine portals. IAB credentials are the vector; MFA is the compensating control.
  5. Audit endpoints with infostealer detection tools (HudsonRock-style monitoring) on staff with technical relation to these entities — IABs sell access, not a complex technical intrusion.
  6. Do not pay ransom. Kazu demanded $250k on PappyJoe; payment guarantees neither data destruction nor decryption, and directly funds the next wave.
  7. Review the digital supply chain (Cloud PACS, telemedicine) as a priority vector. Regional cloud platforms are now the weak link: a Mobilemed compromise exposes dozens of hospitals.
  8. Coordinate with local authorities: ANPD (Brazil), AAIP (Argentina), Peruvian Personal Data Protection Authority, and national CERTs for shared IoCs.

30-day actions:

  • Deploy a Zero Trust model with microsegmentation between PACS/EHR and the rest of the clinical network (assume the next compromise will come through a cloud vendor).
  • Negotiate with PACS cloud and telemedicine vendors contractual breach notification clauses in ≤24h, audit rights and mandatory SOC2/ISO 27001.
  • Include in BCP/DR a scenario of “PACS or telemedicine vendor down for ≥72h” — paper, plates, FAX as contingency.
  • Response drill assuming a starting point with legitimate credentials compromised by infostealer (the pattern confirmed by HudsonRock in this wave).

Sources:

This analysis is part of HealthSec, the weekly newsletter on healthcare cybersecurity.