SYMBOLCOMMON_NAMEaka. SYNONYMS

Kazu  (Back to overview)


Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group has claimed responsibility for multiple high-profile breaches, including those of Manage My Health and the Defensoría del Pueblo de Colombia, exfiltrating sensitive data through techniques like exploiting unpatched vulnerabilities and credential reuse. Kazu has demanded ransoms ranging from $60,000 to $500,000, threatening public disclosure of stolen data if payments are not made. Their operations have primarily focused on entities in Latin America, Asia, and the Middle East, with a notable presence on dark web leak sites.


Associated Families

There are currently no families associated with this actor.


References
2025-12-30BotcrawlSean Doyle
Saudi Icon Data Breach Exposes 4.15TB in Alleged Kazu Ransomware Attack
Kazu
2025-11-18DataBreaches.netDissent
From bad to worse: Doctor Alliance hacked again by same threat actor (2)
Kazu
2025-11-17The HIPAA JournalSteve Alder
Doctor Alliance Investigating 353 GB Data Theft Claim
Kazu
2025-11-11BotcrawlSean Doyle
National Civil Service Commission of Colombia Data Breach Exposes 2.9 TB of Government Files
Kazu
2025-10-08Cyfirmacyfirma
CYBER THREAT LANDSCAPE REPORT – UNITED ARAB EMIRATES (UAE)
Kazu

Credits: MISP Project