PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS) — Threadlinqs Intelligence
As of 2026-08-29, PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS) is a high-severity data breach threat attributed to PEAR, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 13 indicators of compromise.
Threat ID: TL-2026-2212 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: PEAR · FINANCIAL
The data-extortion group PEAR claims to have exfiltrated approximately 1.4 TB of data from South Plains Rural Health Services, Inc. (SPRHS), a nonprofit Federally Qualified Health Center serving rural
On August 29, 2026, DataBreaches.Net (mirrored on malware.news) reported that the data-extortion group PEAR had posted South Plains Rural Health Services, Inc. (SPRHS) to its Tor leak site, claiming exfiltration of roughly 1.4 TB of data including patient personal/medical information and employee and administrative records. SPRHS is a nonprofit, Federally Qualified Health Center (FQHC) operating clinics in Levelland, Lamesa, and Big Spring, Texas, providing family medicine, dental, behavioral health, optometry, and pharmacy services to rural West Texas communities. Ransomware.live independently indexed the SPRHS listing on PEAR's leak site on July 15, 2026, and PEAR's own claim states SPRHS was notified of the intrusion on June 17, 2026 -- consistent with the group's documented multi-week dwell time between compromise and public posting.
PEAR (self-described as standing for 'Pure Extraction And Ransom') is a data-extortion operation first observed active around June-July 2025 that does not deploy encryption or custom malware. Independent trackers (Halcyon.ai, CyberXTron, At-Bay) describe a human-operated intrusion pattern built entirely on abuse of valid accounts and legitimate administrative/remote-access tooling: initial access via compromised third-party credentials, phishing, or internet-exposed RDP/VPN services lacking MFA; persistence via commodity RMM tools (AteraAgent, Splashtop) that are commonly allow-listed by security software; lateral movement and credential harvesting via PsExec-style tooling, PowerShell, and WMI; staged data collection including email/mailbox harvesting; and bulk exfiltration via WinSCP and RClone (frequently renamed to evade detection) to external infrastructure, in one documented case moving ~732 GB in 24 hours. Prior to leak-site posting, PEAR has been observed deleting backups and disabling audit/event logging to blunt recovery and forensic response. The group negotiates directly and manually -- including SMS/WhatsApp messages to employees' personal phones -- via a Tor leak site, an onionmail.org contact address, and a Tox messaging ID, applying strict payment deadlines with a rapid-payment discount of up to 10%. PEAR has scaled to 90+ claimed victims across roughly 9 countries (heavily concentrated in the US), with healthcare, legal, business-services, and financial-services organizations as recurring targets; a prior healthcare victim saw ~3.5 TB exfiltrated and 200,000 individuals affected, triggering HHS/FBI notification. No CVE exploitation or custom malware has been attributed to the group by any tracked source, and PEAR states it has 'nothing in common with any other threat actors.'
As of the August 29, 2026 report, SPRHS had made no public statement, and the group's claim remained unverified by the victim. Given the June 17, 2026 notification/discovery date PEAR states, both the Texas Attorney General's 30-day breach-reporting deadline (~July 17, 2026) and the HIPAA Breach Notification Rule's 60-day deadline for affected individuals/HHS (~August 16-17, 2026) had already lapsed with no corresponding filing found on the Texas AG breach-notification site, raising a secondary regulatory-compliance concern independent of whether PEAR's data claims are ultimately substantiated.
Target sectors: health
Target regions: united states of america, North America
Timeline
- PEAR data-extortion group first reported active (month-level precision: June 2025); trackers describe a coordinated debut of nearly 20 victims posted to its Tor leak site in a single wave shortly after.
- Per PEAR's own claim, SPRHS was notified of the breach on June 17, 2026 -- treated as the compromise/discovery reference date for the incident.
- Ransomware.live indexes South Plains Rural Health Services, Inc. as a PEAR victim at 10:59 UTC, noting a leak screenshot published on PEAR's Tor site.
- Texas's statutory 30-day-from-discovery deadline to report a qualifying breach to the Texas Attorney General passes with no filing found on the AG breach-notification site.
- HIPAA Breach Notification Rule's 60-day-from-discovery deadline for notifying affected individuals and HHS passes, based on the June 17, 2026 discovery date PEAR states.
- PEAR lists an unrelated new victim, Club One Casino, on its leak site, evidencing continued active posting cadence around the same period as the SPRHS claim.
- DataBreaches.Net (mirrored on malware.news) publishes the report on PEAR's claim against SPRHS; SPRHS has made no public confirmation or denial, and no Texas AG breach-site notification is found as of publication.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 13 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1078, T1133, T1566, T1059.001, T1047, T1685, T1685.005, T1003, T1021.002, T1114