Clarkston First Baptist Church Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Clarkston First Baptist Church was listed by the pear ransomware group on June 26, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who may have shared personal information with the church should check for follow-up notices and consider protective steps such as monitoring accounts and changing passwords.
Clarkston First Baptist Church, a longstanding congregation in Clarkston, Georgia, was listed by the pear ransomware group on or around June 26, 2025. Public reporting indicates the group claims to have exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
For members, staff, donors, and others connected to the church, the listing raises questions about the security of information the organization holds. Exact confirmation of the intrusion and the full scope of any data movement are not available in public records at this time.
Inside the incident
According to available reports dated June 26, 2025, Clarkston First Baptist Church appears on a listing associated with the pear ransomware group. The group asserts that internal files were taken as part of a ransomware attack. No public confirmation has been issued by the church itself regarding the claim, the timing of any intrusion, the method used, or whether systems were encrypted or otherwise disrupted.
The number of individuals potentially affected is listed as unknown. No specific file counts, volumes of data, or timelines beyond the reporting date have been released. Public detail on how the incident was detected or contained is limited, and no independent verification of the group's assertions has been published.
Inside pear
Pear is a ransomware group that has operated by targeting organizations, encrypting systems or data where possible, and posting claims of stolen information on leak sites when ransom demands are not met. Like other groups in this category, it typically publicizes victim names to apply pressure and sometimes releases samples or larger data sets if negotiations fail. These listings represent claims by the group rather than independently Reported Facts.
Public knowledge of pear's activity shows a pattern of focusing on entities that hold operational or personal records, with the goal of monetizing access through extortion. The group has been associated with double-extortion tactics—threatening both operational disruption and public data release. No specific statements from pear beyond the listing of Clarkston First Baptist Church are documented in the available facts for this incident, so any broader motives or technical details tied solely to this case remain unconfirmed.
About Clarkston First Baptist Church
Clarkston First Baptist Church traces its origins to 1881, when it was founded by former slaves on donated land. It has grown into a recognized institution serving the community in the heart of Clarkston, Georgia. As a Baptist congregation, it functions as a place of worship, fellowship, and local outreach, typically maintaining records related to membership, pastoral care, events, and administrative operations.
Organizations of this type commonly hold contact details, contribution histories, volunteer information, and internal correspondence. A breach involving such an entity can affect not only current members and staff but also historical records and community partners who interact with the church. The church's long history and local influence mean that any compromise of its systems carries implications for trust within its congregation and the surrounding area.
What data was at risk
Reports state that internal files were exfiltrated in the claimed ransomware attack. No further breakdown of those files—such as specific categories like membership lists, financial records, or communications—has been disclosed. The exact contents remain unconfirmed.
Churches of this kind typically store personal information belonging to members and attendees, including names, addresses, phone numbers, email addresses, and donation or giving records. They may also retain staff employment details, vendor contracts, and internal planning documents. Because the facts do not name precise data types beyond "internal files," it is not possible to state with certainty what was taken. Any assessment of exposure must therefore treat the full inventory as unknown pending further disclosure.
Why it matters
When internal files from a religious organization are claimed to have been removed, the practical risks center on misuse of personal details. Individuals whose information appears in such files could face phishing attempts, identity fraud, or unwanted contact that leverages knowledge of their church affiliation or giving history. For the church itself, the incident can disrupt administrative continuity, strain resources needed for recovery, and affect the confidence of members who entrust the organization with sensitive matters.
Even without confirmed numbers of affected people, the mere listing creates uncertainty that requires careful monitoring. Ransomware claims of this nature often lead to secondary risks, such as fraudulent solicitations that impersonate the church or its leaders. The absence of detailed public information means those connected to Clarkston First Baptist Church must weigh the possibility of exposure against the limited facts currently available.
If your data was in this claimed breach
If you have been associated with Clarkston First Baptist Church as a member, donor, staff member, or volunteer, treat the possibility of exposure seriously even though the exact data set is unconfirmed. Begin by monitoring financial accounts and credit reports for unexpected activity. Change passwords on any accounts that may have reused credentials linked to church communications, and enable multi-factor authentication where available. Be alert for phishing messages that reference the church or request personal details under the guise of assistance.
Document any suspicious contacts and report them to relevant authorities if fraud is suspected. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Stay informed through official channels from the church if further statements are released, and avoid sharing additional personal information in response to unsolicited requests.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
West Chester Listed by pear Ransomware GroupRescue Mission Alliance Listed by pear Ransomware GroupCatholic Charities of the Diocese of Albany Listed by pear Ransomware GroupTwin Oaks Presbyterian Church Listed by pear Ransomware GroupLatest breaches
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.