Brazil Mobilemed Data Breach

Alleged

Ransomware claim involving Brazil Mobilemed.

Published: Aug 23, 2026 Kazu
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Brazil Mobilemed
Industry
Healthcare
Threat Actor
Kazu
Date of Incident
Aug 23, 2026

Executive Summary

Brazil Mobilemed, a cloud-based PACS platform operating in Brazil, was identified on the Kazu ransomware group’s leak site on August 23, 2026. This platform is crucial for storing and distributing medical imaging data, including diagnostic scans and patient records, for healthcare providers within the Brazilian market. The sensitive nature of the data handled by Mobilemed makes this listing a significant concern regarding potential patient data exposure. In the preceding 60 days, Kazu has claimed approximately nine victims, with a strong focus on the Healthcare industry and Brazil as a primary target country. Brazil Mobilemed is the second Brazilian healthcare entity listed by Kazu, following Meducar, indicating a potential cluster targeting within this sector in Brazil. Other victims in Kazu’s recent campaign include ConsultorioMovil and Centro Médico Especializado OSI in Mexico, and Dr. Akbar Niazi Teaching Hospital in Pakistan, further underscoring the group’s focus on healthcare. The specific targeting of a PACS platform is noteworthy, as these systems aggregate sensitive patient information and critical healthcare infrastructure.

Technical Analysis

A review of SOCRadar’s stealer-log telemetry for the domain mobilemed.com.br yielded no direct records within the queried sample. However, it is important to note that a null result from this specific, paginated query does not confirm the absence of compromise. Alternative corporate domains, the use of personal email aliases, and credentials that may have been used and subsequently rotated before indexing are not covered by this particular data slice. Infostealer-harvested credentials are a primary initial access vector for many ransomware operations. While this query did not surface direct evidence linking Kazu’s activity to mobilemed.com.br via stealer logs, the absence of evidence does not equate to a confirmed clean posture. Ransomware groups like Kazu commonly leverage compromised credentials obtained through phishing, exposed VPNs, or credential stuffing. Affected organizations are strongly advised to proactively monitor authentication logs, implement multi-factor authentication for all internet-facing services, and consider the leak site listing itself as an indicator that the threat actor has likely acquired sufficient intelligence for potential future exploitation. Continued monitoring of dark web and stealer-log feeds for related or new indicators is recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.