Kazu
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:23:23
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical
Targeted regions: country_code:co country_code:nz
Context
Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group has claimed responsibility for multiple high-profile breaches, including those of Manage My Health and the Defensoría del Pueblo de Colombia, exfiltrating sensitive data through techniques like exploiting unpatched vulnerabilities and credential reuse. Kazu has demanded ransoms ranging from $60,000 to $500,000, threatening public disclosure of stolen data if payments are not made. Their operations have primarily focused on entities in Latin America, Asia, and the Middle East, with a notable presence on dark web leak sites.
Reports & references
- cyfirma.com — Cyber Threat Landscape Report United Arab Emirates Uae (report)
- botcrawl.com — National Civil Service Commission Of Colombia Data Breach (report)
- hipaajournal.com — Doctor Alliance Data Breach Claim (report)
- databreaches.net — From Bad To Worse Doctor Alliance Hacked Again By Same Threat Actor (report)
- botcrawl.com — Saudi Icon Data Breach (report)