Kazu has claimed another healthcare data breach, this time targeting Clínica Vesalio in Peru and publishing what it says is a database containing 1,011,464 records tied to patients, physicians, appointments, and clinical encounters.
The October 3, 2026 claim includes a sample of the purported database containing patient identity and contact information alongside appointment and physician data. The material reviewed by BreachNews appears to include names, dates of birth, telephone numbers, identity document information, appointment times, treating physicians, consultation locations, and administrative notes.
Some entries also reference triage, pediatric emergency care, traumatology, gynecology, and other medical services. BreachNews is not reproducing the exposed records, personal information, or links to the purported stolen data.
Clínica Vesalio had not issued any public statement confirming the alleged breach at time of publication, and BreachNews has not independently verified that all 1,011,464 claimed records originated from the clinic.
Dataset appears tied to patient appointments and clinical encounters
The structure of the purported database suggests the information is connected to patient scheduling and clinical encounters rather than a conventional marketing or customer contact database.
Fields visible in the sample include physician information, consultation locations, appointment times, patient identity document fields, names, birth dates, telephone numbers, and administrative comments associated with appointments.
The exposed material also appears to contain records associated with emergency and triage services. Some entries reference pediatric care, indicating that information associated with minors may be present in the alleged dataset.
However, the claimed total of 1,011,464 records should not be interpreted as 1,011,464 unique patients. The sample appears capable of recording multiple appointments or encounters involving the same person, meaning an individual could potentially appear more than once.
No reliable victim count can therefore be established from the record total alone.
Kazu has repeatedly targeted healthcare data
The Clínica Vesalio claim adds to a series of incidents attributed to Kazu in recent months, several of which have involved healthcare organizations or platforms holding large volumes of appointment and patient information.
In June, BreachNews reported that Kazu claimed to have stolen more than 307,000 patient records from WELL Health Kensington Medical Centres in Canada. In that incident, the group allegedly demanded $70,000 and threatened to sell the information if the organization did not pay.
Days later, the group claimed a much larger compromise involving appointment management provider Yocale. Kazu alleged it obtained approximately 51 GB containing more than 6 million appointment records and demanded $500,000. The purported information included customer, provider, appointment, business, and contact data. BreachNews previously examined the Kazu claim involving 6 million Yocale appointment records.
The similarities between the Yocale and Clínica Vesalio claims are notable because both allegedly involve structured appointment information, provider details, customer or patient records, and scheduling data. There is currently no evidence establishing that the incidents share an intrusion method, infrastructure, or underlying software platform, however.
Kazu has also moved outside healthcare. In September, the group claimed a 170 GB breach of Spirit Cultural Exchange, alleging the theft of 136,817 files containing sensitive identity, employment, education, and program documentation. That claim included a $100,000 extortion demand.
The previous activity suggests Kazu has focused heavily on organizations holding sensitive personal information, although the authenticity and scope of individual claims have varied and have not always been independently confirmed.
Clínica Vesalio handles a broad range of medical services
Clínica Vesalio is a private healthcare provider based in San Borja, Lima. The organization says it has operated for 40 years and provides more than 30 medical specialties.
Its services include 24-hour emergency care, hospitalization, intensive care, surgery, laboratory services, diagnostic imaging, pediatrics, cardiology, urology, neurocirurgery, and other specialist treatment. The clinic also operates online and WhatsApp-based appointment scheduling services.
The breadth of those services provides context for the variety of clinical departments referenced in the purported leaked records. The sample supplied with the breach claim contains records associated with regular consultations as well as triage and emergency services.
Clínica Vesalio’s privacy policy states that it processes personal information belonging to users, suppliers, and workers. The clinic says it applies security measures intended to prevent alteration, loss, unauthorized processing, and unauthorized access to personal information.
The policy also specifically addresses information involving minors, stating that the clinic does not voluntarily process children’s personal data without the appropriate consent required under applicable law.
Exposed context could make phishing more convincing
If the database is authentic, the risk extends beyond the disclosure of basic names and telephone numbers. Combining identity information with knowledge of a person’s healthcare provider, physician, appointment history, or medical department can provide attackers with useful context for targeted fraud.
An attacker could potentially impersonate a clinic, insurer, physician’s office, or other healthcare service while already knowing details that make a fraudulent communication appear legitimate. Government identity document information and dates of birth could also increase identity theft risks when combined with information obtained from other breaches.
The apparent presence of records associated with children adds another concern. Personal information belonging to minors can remain useful to identity criminals for years, particularly when identity document information and dates of birth are involved.
The sample does not appear sufficient to determine whether detailed diagnoses, medical histories, laboratory results, prescriptions, payment card information, or clinical notes are included in the complete alleged dataset. BreachNews is therefore not attributing those data categories to the incident.
Scale and intrusion method remain unknown
Kazu has not publicly provided enough technical information to establish how Clínica Vesalio was allegedly compromised. The available claim does not reliably identify an exploited vulnerability, compromised account, third-party provider, exposed database, or other initial access method.
It is also unclear whether the claimed database represents information taken directly from Clínica Vesalio’s infrastructure or from another system used to manage appointments and patient encounters.
The presence of a sample provides more substance than a breach claim consisting only of a victim name, but it does not independently establish the origin, completeness, or age of the entire dataset.
Clínica Vesalio had not issued any public statement about the alleged incident at time of publication. Until the healthcare provider confirms an intrusion or additional independently verifiable evidence emerges, the claimed 1,011,464-record breach remains unconfirmed.












