Quick Summary
AllegedExecutive Summary
Canada Yocale, an appointment and business management software provider based in Canada, was listed as a victim on the Kazu ransomware group’s leak site on August 23, 2026. The platform delivers scheduling, booking, and practice management services to health and wellness businesses across North America. Canada Yocale’s listing stands out within Kazu’s current campaign as the group’s sole non-healthcare, non-Latin American victim in this reporting window. Over the past 60 days, Kazu has claimed approximately 9 victims, with Healthcare as its primary industry focus and Mexico, Brazil, and the United States as its top victim geographies. Canada falls outside the group’s top-three country concentration, and Professional Services is not among Kazu’s leading targeted sectors. The overwhelming healthcare character of the remainder of Kazu’s current victim list — ConsultorioMovil, Meducar, Centro Médico Especializado OSI, Dr. Akbar Niazi Teaching Hospital, PawlyClinic, Brazil Mobilemed, Instituto Ferrero, and PappyJoe — positions Canada Yocale as an outlier that may reflect cross-sector opportunism or an access pivot from a healthcare-adjacent client base. As a scheduling platform serving healthcare providers, Yocale may hold indirect patient data through its customer workflows.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for www.yocale.com in the queried slice. A null result is not the same as a clean bill of health — the sample is paginated, alternate domains and personal email aliases fall outside this query, and credentials may have been used and rotated before indexing. Infostealer-sourced credentials remain one of the most reliable initial-access vectors for ransomware groups operating at scale. While no stealer-log evidence was surfaced for this domain in this query, the absence of a finding in a paginated sample is not equivalent to confirmed clean posture. Kazu’s operational profile is consistent with phishing, exposed VPN appliances, and recycled credentials as entry paths; affected organizations are advised to audit authentication logs, enforce MFA on internet-exposed services, and treat the listing itself as an indicator that the threat actor has gathered sufficient operational intelligence about the target.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.