Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Cyber Security

Document Tech Firm Hit as New Cyber Gang Expands Reach

Cyberinchief by Cyberinchief
November 16, 2025
Reading Time: 3 mins read
0
Document Tech Firm Hit as New Cyber Gang Expands Reach


Data Breach Notification
,
Data Security
,
Fraud Management & Cybercrime

RELATED POSTS

How Russia’s Largest Private University is Linked to a $25M Essay Mill – Krebs on Security

Malicious Go Packages Impersonate Google’s UUID Library to Steal Sensitive Data

Warning: React2Shell vulnerability already being exploited by threat actors

Kazu Demands $200K Ransom, Begins Leaking 1.2M Stolen Patient Records

Marianne Kolbasuk McGee (HealthInfoSec) •
November 14, 2025    

Document Tech Firm Hit as New Cyber Gang Expands Reach
Doctor Alliance, a Texas-based document management tech services firm, is investigating claims that newcomer cybercrime gang Kazu stole 1.2 million of the company’s records. (Image: Doctor Alliance)

Kazu, a relative newcomer among cybercrime gangs, is threatening to post 353 gigabytes of data allegedly stolen in recent weeks from Doctor Alliance, a Texas-based company that provides document and billing management technology and services to physician practices. The attack appears to be the gang’s first in North America.

See Also: OnDemand | Transform API Security with Unmatched Discovery and Defense

Doctor Alliance in a statement to Information Security Media Group on Friday said the firm is working with independent security experts to investigate Kazu’s claims of having exfiltrated 1.2 million Doctor Alliance client records. Kazu is demanding Doctor Alliance pay a $200,000 ransom to stop the gang from publishing the stolen data on the dark web.

Leaked Doctor Alliance client data so far includes patients name, date of birth, address, phone number, email address, Medicare number, medical record number, primary and secondary diagnoses, treatment plans, medications and dosages, and provider information, according to one of three proposed federal class action lawsuits filed this week against the company related to the hack.

In addition to those lawsuits – which seek financial damages and allege claims including negligence – several other law firms in recent days have also issued public statements saying they, too, are investigating the Doctor Alliance data breach for potential class action litigation.

Buy JNews
ADVERTISEMENT

In Doctor Alliance’s statement to ISMG, the company said it is digging into the data theft claims.

“Doctor Alliance recently identified unauthorized access involving a single client account,” Doctor Alliance said in its statement to ISMG.

“The issue was contained immediately, impacted systems were secured and the vulnerability was corrected the same day. We are currently working with independent security experts to complete a thorough analysis of the incident. At this stage, we have not verified the claims or numbers circulating online.”

Doctor Alliance did not comment specifically on Kazu’s demands.

Data Theft-Focused

Kazu appears to be a relative newcomer to cybercrime, some experts told ISMG.

“Looking at its extortion site, the group accelerated data dump activity in the June to July 2025 timeframe but intel reports make mention of Kazu associated data dumps and forum postings back in spring of 2025 in the March-April timeframe,” said John Dwyer, deputy CTO and head of ARC Labs at security firm Binary Defense.

Despite the group’s recent emergence, Kazu has already leaked data from government, military and healthcare organizations, said threat researcher Jade Brown of security firm Bitdefender in a report issued Thursday. The majority of Kazu’s nearly three dozen victims so far are based in Southeast Asia, Middle East and South America, Brown said.

So far, the group’s other victims include the National Civil Service Commission of Colombia and Defensoría del Pueblo de Colombia, according to threat intelligence monitoring website Ransomware.live.

The Doctor Alliance hack may indicate Kazu just recently extended its attacks to North America, Dwyer said.

“While we don’t have any concrete data on exploits used, based on the data and referenced names on Kazu’s site, there appears to be a strong focus on web portals and web-enabled services,” Dwyer said.

“This is a strong indication that this group made use of an exploit in a web application or web hosting platform to gain unauthorized access to the data directly from a web application, rather than gaining access to internal systems and stealing data from an internal file server,” he said.

To avoid becoming one of Kazu’s next victims, he said, “now is as good as a time as ever to identify and address any issues on internet-facing web applications with known vulnerabilities. It also would be a great time to push all efforts regarding multifactor authentication on web-enabled portals.”

Kazu’s attacks appear to be focused on data theft extortion, and not ransomware encryption, Dwyer said. Encryption malware is a typical indicator researchers use for cybercrime group attribution.

“We don’t have any solid evidence that Kazu is a rebrand of another extortion based group. I couldn’t find any rebranding information or affiliations of Kazu with any known group,” he said.

“At this point, Kazu is being tracked as a brand new rather than an obvious rebrand or splinter off from a known ransomware group, that may change over time but that’s the info we have now.”





Source link

Tags: CyberDocumentExpandsFirmgangHitReachtech
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

How Russia’s Largest Private University is Linked to a $25M Essay Mill – Krebs on Security
Cyber Security

How Russia’s Largest Private University is Linked to a $25M Essay Mill – Krebs on Security

December 8, 2025
Malicious Go Packages Impersonate Google’s UUID Library to Steal Sensitive Data
Cyber Security

Malicious Go Packages Impersonate Google’s UUID Library to Steal Sensitive Data

December 8, 2025
Warning: React2Shell vulnerability already being exploited by threat actors
Cyber Security

Warning: React2Shell vulnerability already being exploited by threat actors

December 7, 2025
News brief: RCE flaws persist as top cybersecurity threat
Cyber Security

News brief: RCE flaws persist as top cybersecurity threat

December 7, 2025
Barts Health NHS Confirms Cl0p Ransomware Behind Data Breach – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Cyber Security

Barts Health NHS Confirms Cl0p Ransomware Behind Data Breach – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More

December 6, 2025
GOLD BLADE’s strategic evolution – Sophos News
Cyber Security

GOLD BLADE’s strategic evolution – Sophos News

December 6, 2025
Next Post
Movie Piracy 22 Crore Accused A1 Arrested | Cyber Crime Inspector S Naresh | How to Piracy a Movie?

Movie Piracy 22 Crore Accused A1 Arrested | Cyber Crime Inspector S Naresh | How to Piracy a Movie?

Part 1: The importance of Cyber Resiliency in Cyber Security: Cohesity VP James Blake explains all

Part 1: The importance of Cyber Resiliency in Cyber Security: Cohesity VP James Blake explains all

Recommended Stories

The state of Australia’s cyber security laid bare

The state of Australia’s cyber security laid bare

October 24, 2025
From Bartender to Cybersecurity: Brent “CodeBrew” Buch’s Unique Journey | Simply Secured S2 E6

From Bartender to Cybersecurity: Brent “CodeBrew” Buch’s Unique Journey | Simply Secured S2 E6

November 13, 2025
Cybersecurity Architecture: Who Are You? Identity and Access Management

Cybersecurity Architecture: Who Are You? Identity and Access Management

December 7, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested