ConsultorioMovil Data Breach

Alleged

Ransomware claim involving ConsultorioMovil

Published: Aug 23, 2026 Kazu
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
ConsultorioMovil
Industry
Business Services
Threat Actor
Kazu
Date of Incident
Aug 23, 2026

Executive Summary

ConsultorioMovil, a telemedicine and healthcare management platform based in Mexico, was listed on the Kazu ransomware group’s leak site on August 23, 2026. The platform offers mobile and cloud-based healthcare consultation services. ConsultorioMovil’s listing is part of a Kazu campaign that has primarily targeted digital health platforms and medical service providers in Latin America. Over the past 60 days, Kazu has claimed approximately nine victims, with Healthcare and Professional Services as its top targeted industries, and Mexico, Brazil, and the United States as the group’s most active victim countries. The current victim profile reflects a healthcare-focused Kazu campaign, with organizations like Centro Médico Especializado OSI (Mexico), Meducar (Brazil), and Dr. Akbar Niazi Teaching Hospital (Pakistan) listed alongside ConsultorioMovil. PawlyClinic (United States) extends this pattern into North America. ConsultorioMovil’s role as a telemedicine provider, handling significant patient data, makes it a high-value target within Kazu’s documented sector focus.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for consultoriomovil.net in the queried slice. It is important to note that a null result does not confirm a clean posture. The sample was paginated, and alternate domains or personal email aliases may exist outside the scope of this query. Furthermore, credentials might have been used and rotated before their inclusion in the dataset. Infostealer-sourced credentials are a primary initial-access vector for ransomware groups. While no direct stealer-log evidence was found for this domain in this specific query, the absence of findings in a limited sample does not guarantee that no compromise has occurred. Kazu’s operational profile includes phishing, exposed VPN appliances, and recycled credentials as common entry paths. Affected organizations are advised to audit authentication logs, enforce multi-factor authentication on internet-exposed services, and consider the leak-site listing as an indicator that the threat actor has gathered sufficient operational intelligence.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.