Doctor Alliance, a Texas-based document management and billing technology provider for physician practices, is investigating a major data breach attributed to the emerging cybercrime group Kazu. The attackers claim to have exfiltrated 1.2 million client records, including sensitive patient information such as names, dates of birth, contact details, Medicare numbers, medical record numbers, diagnoses, treatment plans, and provider data. Kazu is demanding a $200,000 ransom to prevent the release of 353 gigabytes of stolen data on the dark web, and has already begun leaking portions of the data. The incident has prompted at least three proposed federal class action lawsuits against Doctor Alliance, highlighting the significant legal and reputational risks following the breach.
This attack marks Kazu's first known operation in North America, signaling the group's expanding reach and growing threat to healthcare and technology service providers. Security experts are assisting Doctor Alliance in investigating the breach and assessing the full scope of the compromise. Industry reports also note Kazu's emergence alongside other major ransomware actors, with increased activity on dark web forums and a focus on data exfiltration and extortion tactics. Organizations in the healthcare sector are urged to review their security posture and incident response plans in light of this evolving threat landscape.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Multiple proposed federal class action lawsuits were filed against Doctor Alliance, alleging negligence and seeking damages over the reported exposure of patient PII and PHI.
Doctor Alliance said it was investigating Kazu's allegations and had not verified the gang's online claims or the reported number of affected records.
The Kazu gang claimed it stole 1.2 million Doctor Alliance client records and 353 GB of data, demanded a $200,000 ransom, and began leaking allegedly stolen patient information.
Doctor Alliance said it identified unauthorized access involving a single client account, immediately contained the incident, secured affected systems, and corrected the vulnerability the same day.
Analysts said Kazu ramped up its data-dump activity in mid-2025, with most known victims located in Southeast Asia, the Middle East, and South America.
Researchers cited in the coverage said Kazu was first mentioned in spring 2025, marking the group's early emergence as a new extortion-focused threat actor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.