LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Cheyney University Listed by pear Ransomware Group

HIGH severityUnverified claimHow we verify

Cheyney University Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 18, 2025
Cheyney University Listed by pear Ransomware Group

Reported August 18, 2025.

HIGH
Severity
August 18, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Cheyney University was listed by the pear ransomware group on August 18, 2025, after internal files were exfiltrated in a ransomware attack. Individuals whose data may have been involved should check for official notices and take steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Cheyney University of Pennsylvania, the nation’s first Historically Black College and University, has been listed by the ransomware group known as pear. Public reporting dated August 18, 2025, states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.

This listing places the university’s data among those claimed by a ransomware actor. For students, alumni, faculty, staff and partners, the practical question is what information may have left the institution’s control and what steps can reduce personal risk while official confirmation is still limited.

Breaking down the breach

According to available public information, Cheyney University appears on a leak-site listing associated with the pear ransomware group. The reported summary indicates that internal files were exfiltrated during a ransomware attack. The date of the listing or public report is August 18, 2025. No confirmed figures have been released for the volume of data taken, the precise systems involved, the initial access method, or the total number of individuals whose information may be included. Public detail on timing of the intrusion itself, ransom demands, or any negotiation is also undisclosed. The group’s listing constitutes a claim that data was stolen; independent verification of the full scope has not been provided in the facts available.

Who is pear?

Pear is a ransomware group that, like other actors in this category, typically encrypts systems and claims to have copied data beforehand, then lists victims on dedicated leak sites to pressure payment. Such groups commonly operate on a double-extortion model: they threaten both operational disruption and public release of stolen files. Public reporting on pear and similar operators shows they target a range of organizations, including educational institutions, and post victim names along with sample files or descriptions when they assert a successful intrusion. In this case the group claims Cheyney University as a victim and asserts that internal files were exfiltrated; no additional statements from pear specifically detailing this incident beyond the listing itself are part of the known facts. Attribution rests on the group’s own claim unless further confirmation emerges.

Cheyney University and its sector

Cheyney University of Pennsylvania is the nation’s first Historically Black College and University. As a public higher-education institution it serves students, employs faculty and staff, maintains alumni records, and handles administrative, financial and academic operations. Universities in this sector routinely hold large volumes of personal and institutional data: student records, employee information, financial aid details, research materials, and internal correspondence. A ransomware incident at an HBCU carries particular weight because these institutions often operate with constrained resources while serving communities that may already face elevated risks from identity theft or financial fraud. The listing therefore raises concerns not only for operational continuity but also for the privacy of people connected to the university.

The information in question

The facts state that internal files were exfiltrated in the ransomware attack. Exact data types beyond that description, file counts, or categories of personal information have not been disclosed. Organizations of this kind typically store student and employee personally identifiable information, academic transcripts, financial records, health-related forms where applicable, email archives, and internal administrative documents. Because the precise contents remain unconfirmed, it is not possible to state which specific records left the university’s control. The claim of exfiltration of internal files is the only concrete assertion available at present.

What's at stake

If internal files containing personal data were taken, affected individuals could face risks of identity theft, phishing campaigns that reference genuine university details, or fraudulent use of academic or financial information. For the university, consequences may include regulatory notification obligations, reputational harm, potential disruption of services, and the cost of investigation and remediation. Because the number of people affected is unknown and the exact data types are limited to the description of internal files, the full scale of personal exposure cannot yet be quantified. Even limited leaks of administrative or contact data can enable targeted social-engineering attacks against students, staff or alumni.

What to do if you're exposed

Anyone with a past or present connection to Cheyney University should treat the possibility of exposure seriously while awaiting further official statements. Practical first steps include:

Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Remain cautious of unsolicited offers of help and rely on verified channels for updates from the institution itself.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCheyney University security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Cheyney University’s full breach history →

More recent breaches

Monmouth University Listed by pear Ransomware GroupMarch 26, 2026Private University Listed by pear Ransomware GroupMarch 15, 2026Gordon Clifford Properties Inc. Listed by pear Ransomware GroupDecember 11, 2025Angstrom Automotive Group Listed by pear Ransomware GroupDecember 1, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Cheyney University Listed by pear Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by pear — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram