← Blog

Meducar Breach Claim: 3.2M Argentine Telemedicine Records Held to Ransom

Share on X

Unverified claim — June 23, 2026: Threat actor Kazu is extorting Argentine telemedicine platform Meducar (meducar.com), alleging theft of 3,197,677 patient records and a $150,000 ransom with a July 9, 2026 deadline. Meducar has not confirmed the incident at initial reporting.

What Kazu claims

Per threat-intelligence reporting, Kazu targeted Meducar—a Grupo Cormos platform providing appointments, electronic health records, prescriptions, and telemedicine across Latin America.

Allegedly exposed fields:

  • Full names, emails, gender, date of birth, nationality, marital status
  • Home address, city, phone and WhatsApp numbers
  • Profession, health-insurance (obra social) coverage and member numbers
  • Religion (special-category sensitive data)

Why healthcare + religion is catastrophic

Combining clinical-platform context with religion and insurance identifiers enables targeted extortion, discrimination, and medical identity fraud at scale—harm that password resets cannot undo.

Pattern: Kazu vs Grupo Cormos

Reporting notes Kazu posted near-identical healthcare extortion listings against other Grupo Cormos properties—suggesting a sustained campaign against the health-tech group rather than a one-off forum post.

What to do if you use Meducar

  1. Wait for official notice from Meducar or your clinic—not leak-site downloads.
  2. Monitor insurance Explanation of Benefits for fraudulent claims.
  3. Be alert for phishing citing real obra social or appointment details.

Canonical record: Meducar Kazu claim 2026 on BreachHistory (companyConfirmed: false).