CiberLATAMbywhalemate

Kazu Targets OSI

Kazu listed OSI and Brazil’s Mobilemed as victims, but public confirmation of the attacks remains limited.

Whalemate Labs · AI-assisted researchPublished:3 min read

Kazu listed Centro Médico Especializado OSI: Healthcare Solutions as a victim on its leak site, with an estimated ransom of US$250,000 and 222 users compromised, according to ransomware.live. Brazil’s Mobilemed also appeared among the group’s attributed targets, although available reporting says both claims remain publicly unconfirmed by the alleged victims.

Kazu has again drawn attention to the healthcare sector in Latin America after posting Centro Médico Especializado OSI: Healthcare Solutions and Brazil Mobilemed on its leak site. In OSI’s case, ransomware.live assigned an estimated ransom of US$250,000 and 222 compromised users. Coverage of Mobilemed also repeats the group attribution, but without independent public validation of a successful attack.

What is known about Centro Médico Especializado OSI?

Available information places Centro Médico Especializado OSI: Healthcare Solutions among the victims listed by Kazu on August 23, but there is no public confirmation from the company about service disruption, data exposure, or ransom payment. The ransomware.live entry attributes an estimated ransom of US$250,000 and 222 compromised users.

Breach House also logged the case as a Kazu-attributed ransomware incident, with Mexico as the country and healthcare as the sector. In an analysis of the group’s campaign, HookPhish included a dedicated section for OSI and labeled it a Kazu target dated August 23, 2026, in Mexico, while noting there were no public details about service interruption, payment amount, or notices to patients.

The breach intelligence account IBreaches repeated the leak site entry on August 24, without adding independent evidence of operational impact or data theft. MedRisk, for its part, pointed out that Kazu’s lists included several Latin American healthcare organizations, but stressed that all of the claims were unconfirmed and that none of the alleged victims had commented publicly.

How does Mobilemed appear in the reporting?

Mobilemed appears in multiple reports as a presumed Kazu victim, linked to a Brazilian cloud PACS provider for radiology and medical imaging, but the available material also says independent confirmation remains limited. Dexpose and Cyber News Live repeat the group attribution and the same domain, report date, and Cloud PACS Platform label, without providing verified technical indicators or an official company response.

Undercode News said the link between Mobilemed and Kazu comes from earlier threat intelligence reports, and cited a VECERT report that had already listed a presumed breach associated with the group dated July 10, 2026. In another article, Undercode News said Kazu had hit Mobilemed and that the technical details and independent validation of the incident were still limited.

The context widened with a report from eAgora, which estimated that the platform serves more than 5,000 radiologists and hundreds of hospitals and diagnostic centers in Brazil. That report also said Kazu claims to have stolen about 23.5 TB of data and demanded a US$1.5 million ransom, but noted that the company has not issued any public statement confirming or denying the attack.

What do the reports show about Kazu’s wave?

The coverage agrees that Kazu posted multiple healthcare victims in a single day, but insists that leak site listings alone do not amount to a confirmed intrusion. Security Arsenal said seven of the nine victims listed that day were healthcare organizations or platforms, including Centro Médico Especializado OSI and Mobilemed, and proposed detection rules and associated TTPs rather than validating successful attacks.

MedRisk described the wave as a set of eight healthcare targets that included traditional hospitals as well as SaaS platforms for telemedicine and medical imaging. HookPhish and IBreaches limited themselves to reproducing the group’s posted entries, without independent evidence of operational impact, verified data theft, or visible regulatory notices at the time of publication.

Sources

View all