Ransomware crew targets the software clinics run on

On 23 August nine names appeared on the leak site of a ransomware crew called Kazu. Six of them were not clinics. They were the companies that sell clinics their software: a practice management platform, a cloud archive for medical images, two telemedicine systems, a veterinary consultation service, and an appointment booking platform used by healthcare providers.

The other three were the customers. A 500 bed teaching hospital in Islamabad, a neurology and sleep clinic in Argentina, and a rehabilitation network the listing describes as running several clinics around Lima.

Almost seven months of silence, then nine names

Kazu's site has been tracked since November 2025, and its earliest entry carries a 6 November 2025 date. It listed victims steadily through the winter, then stopped. The last name before August was a chiropractic records platform on 26 January. Nothing followed for almost seven months. All nine August entries surfaced in a single sweep of the site, and no separate publication date was recorded for any of them, so what can be said is that they became visible together, not that they were written together. A tenth entry went up on 25 August with the name withheld and a one word description: "Soon".

The supplier holds what the clinic holds, multiplied

This is why the shape of the list matters more than its length. A London dental imaging center Kazu listed in December describes itself as serving over 10,000 UK practices. A cloud PACS platform stores and moves diagnostic images for hospitals and imaging centers that keep no copy of that infrastructure themselves. An electronic records system holds the notes of every practice on it. Reaching one of those reaches much further than reaching a single surgery, and the practices whose patients are affected will not see it on their own network at all. They find out from a supplier's email, or from a leak site.

All but four listings point the same way

Across the whole life of the site, nineteen entries, every one but four names a healthcare organization or a company that sells software to one. The exceptions are two Colombian government bodies listed in November 2025, a Saudi design and build contractor, and the withheld name from 25 August. Colombia's public sector turns up repeatedly on leak sites under other crews as well. Kazu's full record sits on its actor profile.

These are claims, and the labels are rough

Every entry is an accusation made by the people who say they carried it out. None of the named organizations has publicly confirmed anything, no sample of stolen data has been examined here, and extortion crews routinely inflate, recycle or invent what they advertise. The country tags belong to the tracker rather than to the victims, and two are visibly off in this batch alone: one platform tagged to the United States is described in its own listing as India based, and the rehabilitation network tagged to Mexico is described as headquartered in Lima.

Ask your software vendors before the files land

Nothing in these posts says how Kazu got in, so there is no patch to name. The useful work is upstream of the clinic. Establish which suppliers hold patient data rather than merely handle it, ask each in writing whether they have been contacted or listed anywhere, and check what the contract promises about notification timing. Healthcare has had a hard month on this front already: US authorities issued a joint advisory on another crew hitting hospitals earlier in August.

Nine names in one sweep is a morning's work for whoever runs the site. What they advertise is a targeting decision taken months ago, and one that keeps paying as long as small clinics buy their systems from companies smaller than they are.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions