Kazu has named U.S. J-1 visa program sponsor Spirit Cultural Exchange as its latest alleged victim, claiming to have stolen 170 GB of highly sensitive documents including passport files, facial images, criminal background checks and employment records.
The group claims the dataset contains 136,817 files and is demanding $100,000 from the organization. Kazu has set a Sept. 20 deadline and threatens to offer the allegedly stolen information for sale if its demand is not met.
Spirit Cultural Exchange had not issued any public statement confirming the alleged breach at time of publication.
Passport and background-check documents allegedly stolen
The potential sensitivity of the documents distinguishes the Spirit Cultural Exchange claim from a typical database leak.
According to Kazu, the 170 GB collection contains documents associated with participants in cultural exchange and employment programs. The group listed numerous categories of allegedly compromised files, including:
- Passport files and facial images
- Criminal background checks
- Teaching certificates and degree or diploma records
- Employment verification documents
- Foreign credential evaluations
- Supervisor and personal reference letters
- Participation agreements
- Teacher program offers
- School and cultural activity documentation
BreachNews has not independently verified the 170 GB figure or the group’s claim that 136,817 files were obtained.
If authentic, the combination of government identity documents, photographs, background checks and professional records could create substantial identity theft and impersonation risks for affected participants. Unlike passwords, many of the identity attributes contained in documents such as passports and credential records cannot simply be changed following exposure.
J-1 program participants could be affected
Spirit Cultural Exchange operates programs for international students, teachers and young professionals traveling to the United States under the BridgeUSA J-1 visa program.
The organization is designated by the U.S. Department of State as a BridgeUSA sponsor for Summer Work and Travel, Intern, Trainee and Teacher exchange programs.
That role potentially explains the types of documents described in Kazu’s claim. Applicants and participants may need to provide educational, professional and identity documentation while establishing eligibility and arranging placements.
The available information does not establish how many individuals may be represented in the alleged 136,817 files. A single participant could have multiple documents associated with their application or program, meaning the file count should not be interpreted as a victim count.
Kazu sets Sept. 20 deadline
Kazu is demanding $100,000 and claims it will modify its listing to sell the dataset if Spirit Cultural Exchange does not pay by Sept. 20.
The group published what it describes as samples supporting its claim, but BreachNews is not reproducing leaked identity documents, personal information, underground contact details or links to the purported stolen material.
The latest listing follows several healthcare-related extortion claims attributed to Kazu. BreachNews previously reported that the Kazu group claimed to have stolen approximately 6 million appointment records from Yocale.
The group subsequently targeted WELL Health and Kensington Health in additional claims, alleging the theft of hundreds of thousands of patient records.
The Spirit Cultural Exchange listing shows Kazu extending its current extortion activity beyond healthcare while continuing to focus on organizations holding unusually sensitive personal information.
At this stage, there is no public confirmation that Kazu successfully compromised Spirit Cultural Exchange, that the claimed 170 GB dataset is authentic, or that the group obtained all of the document categories described in its post.












