Alpha IT AS Breached by PEAR Group: Ransomware Claim — What’s Alleged & What To Do
Alpha IT AS has been breached by the group known as PEAR, with the incident disclosed on June 4, 2026. An undisclosed number of individuals may have been affected; anyone connected to the company should review their accounts and change passwords.
What happened
Public records show that the breach at Alpha IT AS was reported on June 4, 2026, and was accompanied by a claim from the PEAR threat actor that 21TB of data had been taken. The incident listing on Breachsense and Ransomware.live followed six days later.
No further details on the date of the intrusion, the access method employed, or the precise contents of the exfiltrated material have been released by the organization or independent investigators.
How a breach like this happens
Incidents that result in the removal of large volumes of data commonly begin with an initial foothold obtained through unpatched software, stolen credentials, or misconfigured remote-access services. Once inside the network, an actor may spend time locating and copying files from servers and storage systems before any detection occurs.
Such operations do not require advanced techniques in every case; many rely on known vulnerabilities that remain unaddressed or on credentials reused across multiple systems.
Alpha IT AS and its sector
Alpha IT AS provides information-technology services to clients in Norway. Companies in this sector routinely manage networks, host data, and deliver support functions that can involve access to customer systems and records.
Because these providers often sit between clients and their own digital infrastructure, any compromise can extend beyond the provider's own records to information belonging to the businesses it serves.
What was likely exposed
The specific types of data taken in this incident have not been disclosed. Organizations that deliver IT services typically store client account details, configuration files, logs, and in some cases personal or operational data belonging to those clients.
Until the company or a verified investigation publishes a list of affected data categories, the exact contents of the 21TB remain unconfirmed.
Why it matters
When an IT services provider holds data on behalf of other organizations, exposure can create downstream risks for those clients, including the possibility of follow-on attempts to use any credentials or internal information that may have been taken.
For Alpha IT AS itself, the event may require technical remediation, notification obligations, and adjustments to security controls, regardless of whether the full scope of the data is ever published.
What to do if you're exposed
Anyone who believes their information may have been held by Alpha IT AS should review account activity for signs of unauthorized access and update passwords, especially where the same credentials are used elsewhere. Enabling multi-factor authentication on important accounts provides an additional layer of protection.
Individuals can also use free online tools that allow an email address to be checked against known breach datasets to determine whether it has appeared in previously published incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
SBI Software Hit by Genesis Data LeakSISINT Engineering Firm Breached by QilinBri-Tech 588GB Data Leak Claimed by Genesis GroupNATO Contractor Indra Group Targeted by TheGentlemenLatest breaches
Read GalaxyWarden’s full analysis of the Alpha IT AS Breached by PEAR Group →
Publicly posted — pending verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.