LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Alpha IT AS Breached by PEAR Group

HIGH severityUnverified claimHow we verify

Alpha IT AS Breached by PEAR Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 4, 2026
Alpha IT AS Breached by PEAR Group

Reported June 4, 2026.

HIGH
Severity
1
Data types exposed
June 4, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Alpha IT AS has been breached by the group known as PEAR, with the incident disclosed on June 4, 2026. An undisclosed number of individuals may have been affected; anyone connected to the company should review their accounts and change passwords.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Alpha IT AS, a Norwegian IT services provider operating under alphait.no, experienced a data breach that was first reported on June 4, 2026. The incident involved a claim of responsibility by the PEAR threat actor, with reports stating that 21TB of data had been removed from the organization's systems. The matter appeared on the breach-tracking platforms Breachsense and Ransomware.live on June 10. The number of people affected and the categories of data involved have not been made public.

What happened

Public records show that the breach at Alpha IT AS was reported on June 4, 2026, and was accompanied by a claim from the PEAR threat actor that 21TB of data had been taken. The incident listing on Breachsense and Ransomware.live followed six days later.

No further details on the date of the intrusion, the access method employed, or the precise contents of the exfiltrated material have been released by the organization or independent investigators.

How a breach like this happens

Incidents that result in the removal of large volumes of data commonly begin with an initial foothold obtained through unpatched software, stolen credentials, or misconfigured remote-access services. Once inside the network, an actor may spend time locating and copying files from servers and storage systems before any detection occurs.

Such operations do not require advanced techniques in every case; many rely on known vulnerabilities that remain unaddressed or on credentials reused across multiple systems.

Alpha IT AS and its sector

Alpha IT AS provides information-technology services to clients in Norway. Companies in this sector routinely manage networks, host data, and deliver support functions that can involve access to customer systems and records.

Because these providers often sit between clients and their own digital infrastructure, any compromise can extend beyond the provider's own records to information belonging to the businesses it serves.

What was likely exposed

The specific types of data taken in this incident have not been disclosed. Organizations that deliver IT services typically store client account details, configuration files, logs, and in some cases personal or operational data belonging to those clients.

Until the company or a verified investigation publishes a list of affected data categories, the exact contents of the 21TB remain unconfirmed.

Why it matters

When an IT services provider holds data on behalf of other organizations, exposure can create downstream risks for those clients, including the possibility of follow-on attempts to use any credentials or internal information that may have been taken.

For Alpha IT AS itself, the event may require technical remediation, notification obligations, and adjustments to security controls, regardless of whether the full scope of the data is ever published.

What to do if you're exposed

Anyone who believes their information may have been held by Alpha IT AS should review account activity for signs of unauthorized access and update passwords, especially where the same credentials are used elsewhere. Enabling multi-factor authentication on important accounts provides an additional layer of protection.

Individuals can also use free online tools that allow an email address to be checked against known breach datasets to determine whether it has appeared in previously published incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyAlpha IT AS security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Alpha IT AS’s full breach history →

More recent breaches

SBI Software Hit by Genesis Data LeakJuly 6, 2026SISINT Engineering Firm Breached by QilinJuly 3, 2026Bri-Tech 588GB Data Leak Claimed by Genesis GroupJuly 3, 2026NATO Contractor Indra Group Targeted by TheGentlemenJune 24, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Alpha IT AS Breached by PEAR Group →

Source: BreachSense

Publicly posted — pending verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram