PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)

PEAR ransomware group claims data leak from South Plains (TL-2026-2212) is a high-severity data breach, first published 2026-08-29. It is attributed to PEAR with medium confidence, affects South Plains Rural Health Services, Inc. Patient, employee, and, maps to 15 MITRE ATT&CK techniques (T1003, T1021.002, T1047), and is covered by 9 detection rules and 13 indicators of compromise.

Key facts for TL-2026-2212

Threat ID
TL-2026-2212
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-29
Last reviewed
2026-08-29
Attribution
PEAR
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health
Target regions
united states of america, North America
Detection rules
9
Indicators of compromise
13

Malware and tooling in PEAR ransomware group claims data leak from South Plains

Malware and tooling: Dataleak, pear, AteraAgent, PSEXEC, Rclone - S1040, Splashtop, WinSCP

The data-extortion group PEAR claims to have exfiltrated approximately 1.4 TB of data from South Plains Rural Health Services, Inc. (SPRHS), a nonprofit Federally Qualified Health Center serving rural West Texas, including personal and medical information on thousands of patients plus employee and administrative records. SPRHS has not publicly confirmed or denied the claim, and no notification had appeared on the Texas Attorney General breach site as of the August 29, 2026 report.

How PEAR ransomware group claims data leak from South Plains works

On August 29, 2026, DataBreaches.Net (mirrored on malware.news) reported that the data-extortion group PEAR had posted South Plains Rural Health Services, Inc. (SPRHS) to its Tor leak site, claiming exfiltration of roughly 1.4 TB of data including patient personal/medical information and employee and administrative records. SPRHS is a nonprofit, Federally Qualified Health Center (FQHC) operating clinics in Levelland, Lamesa, and Big Spring, Texas, providing family medicine, dental, behavioral health, optometry, and pharmacy services to rural West Texas communities. Ransomware.live independently indexed the SPRHS listing on PEAR's leak site on July 15, 2026, and PEAR's own claim states SPRHS was notified of the intrusion on June 17, 2026 -- consistent with the group's documented multi-week dwell time between compromise and public posting.

PEAR (self-described as standing for 'Pure Extraction And Ransom') is a data-extortion operation first observed active around June-July 2025 that does not deploy encryption or custom malware. Independent trackers (Halcyon.ai, CyberXTron, At-Bay) describe a human-operated intrusion pattern built entirely on abuse of valid accounts and legitimate administrative/remote-access tooling: initial access via compromised third-party credentials, phishing, or internet-exposed RDP/VPN services lacking MFA; persistence via commodity RMM tools (AteraAgent, Splashtop) that are commonly allow-listed by security software; lateral movement and credential harvesting via PsExec-style tooling, PowerShell, and WMI; staged data collection including email/mailbox harvesting; and bulk exfiltration via WinSCP and RClone (frequently renamed to evade detection) to external infrastructure, in one documented case moving ~732 GB in 24 hours. Prior to leak-site posting, PEAR has been observed deleting backups and disabling audit/event logging to blunt recovery and forensic response. The group negotiates directly and manually -- including SMS/WhatsApp messages to employees' personal phones -- via a Tor leak site, an onionmail.org contact address, and a Tox messaging ID, applying strict payment deadlines with a rapid-payment discount of up to 10%. PEAR has scaled to 90+ claimed victims across roughly 9 countries (heavily concentrated in the US), with healthcare, legal, business-services, and financial-services organizations as recurring targets; a prior healthcare victim saw ~3.5 TB exfiltrated and 200,000 individuals affected, triggering HHS/FBI notification. No CVE exploitation or custom malware has been attributed to the group by any tracked source, and PEAR states it has 'nothing in common with any other threat actors.'

As of the August 29, 2026 report, SPRHS had made no public statement, and the group's claim remained unverified by the victim. Given the June 17, 2026 notification/discovery date PEAR states, both the Texas Attorney General's 30-day breach-reporting deadline (~July 17, 2026) and the HIPAA Breach Notification Rule's 60-day deadline for affected individuals/HHS (~August 16-17, 2026) had already lapsed with no corresponding filing found on the Texas AG breach-notification site, raising a secondary regulatory-compliance concern independent of whether PEAR's data claims are ultimately substantiated.

MITRE ATT&CK techniques used in TL-2026-2212

Credential Access

T1003 OS Credential Dumping

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration to Cloud Storage

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing

Collection

T1114 Email Collection

Command and Control

T1219 Remote Access Tools

Impact

T1490 Inhibit System Recovery; T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in PEAR ransomware group claims data leak from South Plains

  • South Plains Rural Health Services, Inc. — Patient, employee, and administrative record systems (IT environment)

Remediation for PEAR ransomware group claims data leak from South Plains

Immediate actions

  • Engage independent forensic incident response to confirm or refute PEAR's claim and scope the alleged June 17, 2026 compromise
  • Rotate all VPN, RDP, and administrative credentials network-wide, since PEAR's documented initial-access pattern relies on reused/compromised valid accounts
  • Enforce MFA on every internet-exposed remote-access service (VPN, RDP, webmail) to close PEAR's most consistently reported entry vector
  • Hunt for AteraAgent, Splashtop, PsExec, WinSCP, and RClone execution or network artifacts, PEAR's documented toolset, across endpoints and egress logs
  • File any confirmed breach with the Texas Attorney General and begin HIPAA Breach Notification Rule assessment immediately given the lapsed statutory windows

Workarounds

  • Remove or strictly allow-list RMM tools (AteraAgent, Splashtop) so unauthorized instances cannot blend in with sanctioned IT tooling
  • Disable unused SMB admin shares and legacy remote-management protocols where not operationally required

Longer-term hardening

  • Deploy EDR with tamper protection and centralized, write-once logging to detect the audit-log clearing and AV/EDR circumvention PEAR relies on pre-extortion
  • Segment clinical systems from administrative networks and restrict SMB/Windows admin-share reachability to limit PEAR's lateral-movement path
  • Maintain offline/immutable backups resilient to pre-extortion backup deletion
  • Stand up continuous monitoring for organizational credentials appearing in third-party breach databases, PEAR's primary initial-access source

Timeline of PEAR ransomware group claims data leak from South Plains

  • PEAR data-extortion group first reported active (month-level precision: June 2025); trackers describe a coordinated debut of nearly 20 victims posted to its Tor leak site in a single wave shortly after.
  • Per PEAR's own claim, SPRHS was notified of the breach on June 17, 2026 -- treated as the compromise/discovery reference date for the incident.
  • Ransomware.live indexes South Plains Rural Health Services, Inc. as a PEAR victim at 10:59 UTC, noting a leak screenshot published on PEAR's Tor site.
  • Texas's statutory 30-day-from-discovery deadline to report a qualifying breach to the Texas Attorney General passes with no filing found on the AG breach-notification site.
  • HIPAA Breach Notification Rule's 60-day-from-discovery deadline for notifying affected individuals and HHS passes, based on the June 17, 2026 discovery date PEAR states.
  • PEAR lists an unrelated new victim, Club One Casino, on its leak site, evidencing continued active posting cadence around the same period as the SPRHS claim.
  • DataBreaches.Net (mirrored on malware.news) publishes the report on PEAR's claim against SPRHS; SPRHS has made no public confirmation or denial, and no Texas AG breach-site notification is found as of publication.

Sources cited for PEAR ransomware group claims data leak from South Plains

More in data breach

Detection coverage for TL-2026-2212

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2212 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats