Quick Summary
AllegedExecutive Summary
Centro Médico Especializado OSI, a healthcare solutions provider based in Mexico, was listed as a victim on the Kazu ransomware group’s leak site on August 23, 2026. The organization delivers specialized medical care and health system services within the Mexican market. Centro Médico Especializado OSI is one of two Mexican healthcare entities listed by Kazu in the current reporting period, suggesting the group is specifically targeting Mexican medical infrastructure. Over the past 60 days, Kazu has claimed approximately 9 victims, with Healthcare as its dominant industry focus and Mexico, Brazil, and the United States as the leading victim countries. Mexico’s top-country position in Kazu’s victim geography is directly reflected by this listing and by the concurrent targeting of ConsultorioMovil, another Mexican healthcare platform. Meducar (Brazil) and Dr. Akbar Niazi Teaching Hospital (Pakistan) extend the campaign’s healthcare-exclusive scope across Latin America and South Asia. PawlyClinic (United States) adds North American healthcare representation to the cluster. Centro Médico Especializado OSI’s specialized medical profile adds patient data sensitivity that increases the real-world impact of this listing beyond its organizational footprint.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for centromedicoosi.com in the queried slice. A null result is not the same as a clean bill of health — the sample is paginated, alternate domains and personal email aliases fall outside this query, and credentials may have been used and rotated before indexing. Infostealer-sourced credentials remain one of the most reliable initial-access vectors for ransomware groups operating at scale. While no stealer-log evidence was surfaced for this domain in this query, the absence of a finding in a paginated sample is not equivalent to confirmed clean posture. Kazu’s operational profile is consistent with phishing, exposed VPN appliances, and recycled credentials as entry paths; affected organizations are advised to audit authentication logs, enforce MFA on internet-exposed services, and treat the listing itself as an indicator that the threat actor has gathered sufficient operational intelligence about the target.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.