LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Martin Lawrence Galleries Listed by Pear Ransomware Group

HIGH severityUnverified claimHow we verify

Martin Lawrence Galleries Listed by Pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 24, 2026
Martin Lawrence Galleries Listed by Pear Ransomware Group

Reported September 24, 2026.

HIGH
Severity
September 24, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Martin Lawrence Galleries was listed by the Pear ransomware group on September 24, 2026, in an extortion claim that has not been corroborated by the organisation or any other source. Individuals who have done business with the galleries should check whether their information appears in any later listings and take steps to protect their accounts.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group has publicly named Martin Lawrence Galleries on its leak site, raising practical questions for anyone who has bought art, inquired about pieces, worked with the gallery, or shared contact and payment details in the course of ordinary business. As of writing, Martin Lawrence Galleries has not publicly confirmed that an incident occurred, and independent verification is not reflected in the available record. What exists so far is an accusation posted by the group, not a settled account of stolen files or confirmed victims.

For customers, staff, and partners, the immediate concern is conditional: if personal or financial information were copied in an intrusion, it could be misused for fraud, phishing, or unwanted contact. Because the listing does not establish what, if anything, left the organisation’s systems, people connected to the gallery are left to weigh ordinary precautions against an unproven claim rather than against a verified breach notice.

What is being claimed

According to a leak-site listing attributed to the group known as Pear, Martin Lawrence Galleries has been named as a victim. The claim was reported on September 24, 2026. Public detail in that report is thin. The number of people who might be affected is unknown. The types of data supposedly involved are not disclosed. Method of access, duration of any intrusion, and whether files were actually exfiltrated are likewise undisclosed in the material provided.

Pear’s listing functions as pressure typical of ransomware and extortion crews: name an organisation, threaten publication, and seek payment or leverage. That pattern does not, by itself, prove that Martin Lawrence Galleries’ systems were compromised or that any customer records left its control. The company has not publicly confirmed the claim as of writing. Readers should treat the episode as an unverified claim on a criminal leak site until the organisation, a regulator, or another authoritative source says otherwise.

The group behind it: Pear

Pear appears in open reporting as a ransomware and data-extortion actor that, like many peers, uses leak sites to advertise alleged victims and to threaten release of material unless demands are met. Groups in this category commonly claim to have encrypted systems, stolen copies of data, or both, then set deadlines and drip samples—tactics meant to coerce payment and amplify reputational harm. Public write-ups of such crews generally describe double-extortion playbooks rather than a single fixed technical signature unique to every listing.

For this specific case, only the listing itself is in the record: Pear has listed Martin Lawrence Galleries and, in the available summary, offers little beyond naming the organisation. No confirmed inventory of files, no verified sample set tied to this victim in the facts at hand, and no independent confirmation are stated. Anything beyond “the group claims the gallery is a victim” would be speculation. Leak-site posts can be inaccurate, recycled, inflated, or false; they are marketing for criminals, not audited disclosure.

Martin Lawrence Galleries and its sector

Martin Lawrence Galleries is described in the reported summary as a premier gallery of fine art in America. Fine-art galleries of this kind typically sit at the intersection of high-value inventory, private client relationships, and commercial operations that can span multiple locations and long-running collector relationships. They are not banks or hospitals, but they still handle identity, contact, and transaction information as a normal part of sales, shipping, insurance, and client service.

A claimed incident involving a named gallery matters because art-market clients often expect discretion, and because the same contact and payment channels used for legitimate purchases are attractive to fraudsters if those channels are abused. Consequential risk here is not limited to “art world” prestige; it is about whether ordinary personal and commercial data associated with buying, selling, or working around fine art could be misused if a claim turned out to be true. The leak-site listing does not establish that such a compromise happened. It does explain why people with a relationship to the gallery pay attention when a crew names the business in public.

What data was at risk

The facts state that data types named as exposed are not disclosed. It is therefore not possible to say which fields, documents, or systems—if any—were involved. Asserting a specific inventory would repeat the attackers’ marketing as if it were fact.

If files were taken from an organisation in this sector, firms of this kind typically hold some mix of customer and prospect contact details, purchase and inquiry history, shipping and delivery information, invoices or payment-related records, employee or contractor information, and internal business documents. Some galleries also retain identity or financial details needed for high-value transactions, loans, or shipping of works. None of that list is confirmed as present in any Pear haul related to Martin Lawrence Galleries; it is a sector-typical picture offered only so readers can think conditionally about exposure. Exact contents remain unconfirmed, and the number of people affected remains unknown.

The real-world impact

For individuals, the realistic risks—if a copy of their information were ever published or traded—are familiar rather than cinematic: targeted phishing that references art purchases or gallery relationships, attempts to reset accounts using known email addresses, fraudulent invoices or shipping notices, and identity or payment fraud where enough identifiers exist. People who never dealt with the gallery directly may still be unaffected even if a claim were later substantiated; without a confirmed dataset, no one can truthfully say “your record is in this dump.”

For the organisation, a public extortion listing can mean reputational strain, customer anxiety, and the operational cost of investigating and responding whether or not the claim is accurate. Criminal crews rely on that pressure. What the listing does establish is that Pear chose to name Martin Lawrence Galleries in a public extortion channel on or around the reported date. What it does not establish is confirmed theft, confirmed file contents, confirmed victim counts, or any verified failure of controls. Those points remain open until reliable confirmation exists.

What to do now

Treat the situation as a claim, not a personal notification that your data is out. If you are a client, employee, or partner, watch for unexpected messages that cite the gallery, urgent payment requests, or links you did not expect; verify any financial or shipping change through a channel you already trust. Prefer unique passwords and multi-factor authentication on email and financial accounts you use for purchases. If you paid by card through the gallery or related processors, monitor statements and consider issuer alerts. If you later receive a formal notice from the gallery or a regulator, follow that guidance—it will be more specific than a leak-site post.

You can also run a free exposure scan of your email to check whether your address has already appeared in other known breach datasets, which helps separate this unverified listing from older, unrelated exposures. Stay calm, keep precautions proportional, and remember: Pear has listed Martin Lawrence Galleries; the company has not publicly confirmed an incident as of writing, and public detail on scope and data remains limited.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyMartin Lawrence Galleries security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Martin Lawrence Galleries’s full breach history →

More recent breaches

Indroj Medical Group Inc. Listed by Pear Ransomware GroupSeptember 24, 2026Westside GI Listed by Pear Ransomware GroupSeptember 24, 2026Foss Inc. Listed by Pear Ransomware GroupSeptember 11, 2026Kovo Healthtech Listed by Pear Ransomware GroupSeptember 4, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Martin Lawrence Galleries Listed by Pear Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by pear — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram