Unverified claim — June 23, 2026: Threat actor Kazu is extorting Argentine telemedicine platform Meducar (meducar.com), alleging theft of 3,197,677 patient records and a $150,000 ransom with a July 9, 2026 deadline. Meducar has not confirmed the incident at initial reporting.
What Kazu claims
Per threat-intelligence reporting, Kazu targeted Meducar—a Grupo Cormos platform providing appointments, electronic health records, prescriptions, and telemedicine across Latin America.
Allegedly exposed fields:
- Full names, emails, gender, date of birth, nationality, marital status
- Home address, city, phone and WhatsApp numbers
- Profession, health-insurance (obra social) coverage and member numbers
- Religion (special-category sensitive data)
Why healthcare + religion is catastrophic
Combining clinical-platform context with religion and insurance identifiers enables targeted extortion, discrimination, and medical identity fraud at scale—harm that password resets cannot undo.
Pattern: Kazu vs Grupo Cormos
Reporting notes Kazu posted near-identical healthcare extortion listings against other Grupo Cormos properties—suggesting a sustained campaign against the health-tech group rather than a one-off forum post.
What to do if you use Meducar
- Wait for official notice from Meducar or your clinic—not leak-site downloads.
- Monitor insurance Explanation of Benefits for fraudulent claims.
- Be alert for phishing citing real obra social or appointment details.
Canonical record: Meducar Kazu claim 2026 on BreachHistory (companyConfirmed: false).