2026 Meducar — unverified Kazu extortion; 3.2M Argentine telemedicine patient records claimed
Data compromised
Actor-claimed 3,197,677 user records: names, emails, DOB, gender, nationality, marital status, addresses, phone/WhatsApp numbers, profession, health-insurance (obra social) coverage and member numbers, religion (special-category data)—Meducar/Grupo Cormos has not confirmed
Technical writeup
Unverified extortion claim — June 23, 2026. Threat-intelligence reporting (Dark Web Informer) documents actor Kazu extorting Meducar (meducar.com), an Argentine telemedicine and patient-management platform owned by Grupo Cormos, claiming 3,197,677 users' PII stolen with a $150,000 ransom and July 9, 2026 deadline threatening public sale. Claimed fields include identity, contact, health-insurance, and religion data from a platform handling appointments, EHR, prescriptions, and telemedicine. Kazu posted similar healthcare extortion listings against other Grupo Cormos properties. Meducar has not publicly confirmed the incident at catalog time. BreachHistory indexes the actor-cited 3,197,677 figure as unverified.
Root cause
Threat actor alias Kazu claims exfiltration from Meducar (Grupo Cormos) telemedicine platform; $150,000 ransom demand with July 9, 2026 deadline—unverified by company