Austin Plastic Surgery Institute Listed by Pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Austin Plastic Surgery Institute has been listed by the Pear ransomware group, with the incident disclosed on August 20, 2026. Individuals who may have received services from the institute should review their personal data exposure and take protective steps.
A ransomware group known as Pear has listed Austin Plastic Surgery Institute on its leak site, according to a report dated August 20, 2026. The listing is an unverified claim by the group. As of writing, the institute has not publicly confirmed that any incident occurred, that systems were accessed, or that any patient or staff information left its control. For people who have been patients or employees, the practical question is straightforward: if personal or medical information were ever taken and published, what could that mean and what steps are worth taking while the claim remains unproven.
Public detail is limited. The number of people potentially affected is unknown, and the listing does not spell out which data types, if any, the group says it holds. That uncertainty is itself part of the picture readers should keep in mind.
Inside the listing
According to the available record, Pear has named Austin Plastic Surgery Institute on its leak site. The reported date associated with that listing is August 20, 2026. Beyond the organization’s name and a brief description characterizing it as a center staffed by highly skilled plastic surgeons, the facts provided do not include a ransom demand amount, a countdown, a sample file inventory, a stated method of intrusion, or a confirmed volume of data.
People affected are listed as unknown. Data types named as exposed are not disclosed. Nothing in the record establishes that files were copied, that encryption occurred on the institute’s systems, or that any material has been released to the public. A leak-site entry is a claim by the operators of that site. It is not the same thing as a notification from the organization, a regulator, or an independent breach index. Until the institute or another authoritative source addresses the listing, the scale, timing, and contents of any alleged compromise remain unconfirmed.
Inside Pear
Pear is known publicly as a ransomware and extortion-style operation that pressures organizations by threatening to publish material it says it obtained. Groups in this category typically advertise victims on dedicated leak sites, sometimes posting purported samples and sometimes only names, in an effort to force negotiation. Their public posts are marketing and leverage; they are not audited inventories.
Well-documented patterns among such actors include double-extortion themes—claiming both disruption and data theft—and the use of countdown-style pressure on leak portals. None of that general background proves what happened in this specific case. For Austin Plastic Surgery Institute, the only incident-specific assertion in the given facts is that Pear listed the organization. Any description of what Pear allegedly took from this victim, beyond what the sparse listing record states, would be invention. The group claims a connection; independent confirmation is not part of the record provided here.
Who is Austin Plastic Surgery Institute?
Austin Plastic Surgery Institute is identified in the listing-related summary as a center staffed by highly skilled plastic surgeons. Organizations of this kind typically provide elective and reconstructive surgical care, consultations, and related clinical services in the Austin area and serve patients who entrust them with medical histories, contact details, and other sensitive personal information.
A claimed listing involving a plastic surgery practice matters because healthcare and specialty surgical settings often sit at the intersection of identity data, clinical documentation, and financial or insurance records. That does not establish that any such records left this institute. It explains why patients and staff pay attention when a named clinical organization appears on a criminal leak site, and why careful, conditional reading of the claim is warranted rather than panic or dismissal.
The information in question
The facts state that data types named as exposed are not disclosed. The listing record does not provide an inventory of files, record counts, or categories such as names, dates of birth, Social Security numbers, clinical notes, images, billing data, or employee information. Those specifics are unconfirmed.
If files from a plastic surgery practice were ever taken—an if that remains unproven here—firms in this sector typically hold information needed to schedule care, document procedures, bill insurers or patients, and maintain medical records under healthcare privacy rules. That may include identifiers, contact information, health history, procedure details, and payment-related data. Typical holdings are not the same as a verified breach contents list. Readers should treat any concrete description of “what was allegedly stolen” from this institute as unavailable in the public facts given for this article.
What's at stake
For individuals, the stakes of a genuine healthcare-related data incident—if one occurred and if personal records were involved—can include phishing and social-engineering attempts that reference real appointments or procedures, account-takeover attempts that reuse exposed emails or phone numbers, and longer-term identity or insurance fraud risk when strong identifiers are in criminal hands. Medical details can also be sensitive in employment, family, or personal contexts even when they are not useful for financial fraud alone.
For the organization, a public extortion listing can mean reputational pressure, possible regulatory attention if a reportable incident is later confirmed, and the operational cost of investigation and patient communication—again, only if an incident is established. A leak-site name alone does not prove negligence, poor controls, or a successful intrusion. It establishes that a criminal group chose to publish an accusation. Separating the claim from confirmed harm is essential both for fairness to the named business and for giving affected people advice that matches the evidence.
If your data was involved
If you are a current or former patient, employee, or vendor contact of Austin Plastic Surgery Institute and you are concerned that your information might be implicated if the Pear claim were accurate, treat the situation as precautionary rather than proven. Watch for unexpected messages that cite the practice, surgery dates, or billing details; verify any request for money, passwords, or codes through official channels you already trust; and consider placing fraud alerts or credit freezes if you later receive formal notice that sensitive identifiers were involved. Keep records of any official communications from the institute rather than relying on screenshots from criminal sites.
Because the listing does not confirm what, if anything, was taken, avoid assuming your records are “out.” If the institute issues a notice, follow its instructions and any guidance from regulators or credit bureaus named in that notice. As a general hygiene step, you can also run a free exposure scan of your email to check whether your address has already appeared in other known breach datasets unrelated to this claim, and then strengthen unique passwords and multi-factor authentication on important accounts. Public detail on this particular listing remains limited; calm verification beats treating an extortion page as a finished investigation.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Medical Arts Chemists and Surgicals Listed by Pear Ransomware GroupPracti-Cal Listed by Pear Ransomware GroupClub One Casino Listed by Pear Ransomware GroupExperts Entreprendre Listed by Everest Ransomware GroupLatest breaches
Publicly posted by pear — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.