Kazu Ransomware Group Claims MSM Unify as Victim With 1.45TB of Data
The Kazu ransomware and data-extortion group has claimed a new victim, listing global education marketplace MSM Unify on its ransom site after several months with no apparent new listings. The group claims to have obtained more than 2 million records covering approximately 319,000 users and 1.45TB of data, with a ransom demand of US$400,000.
At the time of writing, the claims made by Kazu have not been independently verified, and there has been no public confirmation from MSM Unify that a compromise has occurred. There is a database sample listed by the Threat actor though we have not verified the contents.
Who is MSM Unify?
MSM Unify is a global student marketplace that connects students with educational institutions and recruitment partners.
The platform describes itself as bringing together organisations across the international education sector, allowing them to collaborate in reaching students and providing them with education options.
That makes MSM Unify an interesting target from a cyber security perspective.
Unlike an individual education provider, a platform operating across the international education ecosystem can potentially sit between students, education providers and recruitment partners, creating the possibility of access to large volumes of information across multiple organisations.
According to the claim made by Kazu, the alleged dataset contains more than 2 million records, relating to approximately 319,000 users, with a total volume of around 1.45TB.
Kazu is demanding US$400,000 for the alleged data.

Again, these figures are currently claims made by the threat actor and should not be interpreted as confirmed breach statistics.
Kazu returns to the ransomware spotlight
Kazu is a financially motivated ransomware and data-extortion operation that emerged around mid-to-late 2025.
The group has used a traditional double-extortion model, where attackers steal data from a victim and may also encrypt systems. The stolen information is then used as leverage, with the threat actor threatening to publish or sell the information if the victim does not pay.
Kazu has targeted organisations in a range of sectors, with previous activity including healthcare, government and education-related organisations.
The group’s ransom demands have varied considerably, with demands reported from tens of thousands of dollars through to several hundred thousand dollars.
The alleged MSM Unify demand of US$400,000 therefore falls within the range seen in previous Kazu activity.
Kazu has already targeted New Zealand healthcare
The Kazu name will be particularly familiar to organisations in New Zealand following the attack against Manage My Health.
In December 2025, Kazu claimed responsibility for compromising the New Zealand patient portal and stealing hundreds of thousands of files.
The incident subsequently became one of New Zealand’s most significant privacy breaches.
New Zealand authorities confirmed that the incident involved patient information. An independent review found that Kazu gained unauthorised access using stolen credentials and exploited a security weakness to access other patient accounts and extract patient files.
Manage My Health ultimately confirmed that approximately 99,000 people were affected.
The incident demonstrates the type of data-rich organisation Kazu appears interested in: organisations where compromising a single platform can potentially provide access to large volumes of sensitive information.
Why an education marketplace is an attractive target
Education organisations hold considerably more sensitive information than simply a student’s name and email address.
Depending on the systems involved, education-sector data can include:
- Names and contact details
- Dates of birth
- Identification documents
- Academic records
- Applications and enrolment information
- Immigration and visa information
- Financial information
- Education history
- Student communications
- Recruitment and agent information
- Authentication credentials
- Information relating to parents or guardians
For an organisation operating internationally, the potential data set can also span multiple jurisdictions and privacy regimes.
The alleged scale of the MSM Unify claim — 319,000 users and 1.45TB of data — illustrates why platforms sitting in the education supply chain can be particularly attractive to financially motivated threat actors.
Australian and New Zealand education providers
There is another reason the MSM Unify claim deserves attention from the Australian and New Zealand education sectors.
MSM Unify’s website currently lists a number of Australian and New Zealand education providers.
The Australian institutions displayed on the site’s Australia page include:
| Education provider | Country |
|---|---|
| Deakin University | Australia |
| Flinders University | Australia |
| Macquarie University | Australia |
| Swinburne University of Technology | Australia |
| Victoria University Sydney | Australia |
| Australian Catholic University | Australia |
| James Cook University Brisbane | Australia |
| The University of Adelaide | Australia |
| Monash University | Australia |
| Swinburne University Sydney | Australia |
The New Zealand institutions displayed by MSM Unify include:
| Education provider | Country |
|---|---|
| Lincoln University | New Zealand |
| Ara Institute of Canterbury | New Zealand |
| Cut Above Academy | New Zealand |
| University of Canterbury | New Zealand |
| Auckland Institute of Studies | New Zealand |
| Future Skills Academy Limited | New Zealand |
| Crimson Global Academy | New Zealand |
| Elite School of Beauty and Spa | New Zealand |
| Le Cordon Bleu New Zealand | New Zealand |
| Victoria University of Wellington | New Zealand |
Being listed by MSM Unify does not mean any of these organisations have been compromised as again we have not verified the contents of the database sample of the 1.45TB taken.
If the Kazu claims ultimately prove accurate, affected organisations would need to establish exactly what information was held by MSM Unify, what information was accessed or exfiltrated, and whether any data relating to their students, staff, applicants or partners was included.
The third-party risk question
The alleged MSM Unify incident is also a reminder that organisations cannot limit cyber security assessments to systems they directly own and operate.
Universities and education providers increasingly depend on third parties for:
- Student recruitment
- Application processing
- Identity verification
- Payment services
- Cloud hosting
- Learning platforms
- Student accommodation
- International student services
- Marketing
- Education agents
- Data analytics
A compromise of one supplier can potentially expose information belonging to many customers.
This is exactly why third-party cyber security assurance needs to go beyond asking a supplier to complete an annual questionnaire.
Organisations should understand:
- What data does the supplier hold?
- Why does the supplier need that data?
- Where is the data stored?
- Who can access it?
- What other organisations can access it?
- What security controls protect it?
- How quickly will the organisation notify customers of a breach?
- Can the supplier demonstrate that its controls actually work?
- What happens to the data when the relationship ends?
- Can the supplier provide meaningful evidence of its security posture?
The alleged 1.45TB should not be the headline risk
While 1.45TB sounds significant, the volume of stolen data isn’t necessarily the best measure of the potential impact.
Two million records containing relatively low-risk information could be less damaging than a much smaller database containing passports, identity documents, financial information or authentication credentials.
The more important questions are:
What data was allegedly stolen?
Whose data was it?
How current was it?
Could it be used for identity theft or fraud?
Could it be used to conduct targeted phishing attacks?
Could the information provide access to other systems?
These questions will ultimately determine the real-world impact if the Kazu claim is substantiated.
A warning for education providers
The MSM Unify claim is a useful reminder for Australian and New Zealand education providers that their cyber security perimeter extends beyond their own network.
The education sector is particularly attractive to attackers because of the combination of:
Large user populations + valuable personal information + extensive third-party relationships.
The Kazu claim against MSM Unify should therefore prompt education providers to review their supplier relationships and identify where sensitive student and applicant information is being concentrated. Recently the NZ Privacy Commissioner found Health New Zealand to have failed in its obligations to do due diligence when using Manage My Health as a 3rd party provider so this may open up the New Zealand Education providers to the same liabilty.
What happens next?
At present, the MSM Unify listing should be treated as an unverified threat-actor claim.
The key indicators to watch will be whether MSM Unify confirms an incident, whether evidence of compromise or stolen data is released, whether the claimed volume of data can be corroborated, and whether organisations connected to the platform are subsequently notified.
For Australian and New Zealand education providers, the incident is worth watching regardless of whether the claim ultimately proves accurate.
Third-party platforms can become a single point of exposure for data belonging to thousands of students and applicants.
The lesson from incidents such as Manage My Health is that by the time a ransomware group appears on a leak site, the most important security controls should already have been in place.
Organisations need to know where their data is, who can access it, and whether their suppliers can actually protect it.