LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Mogren Listed by Pear Ransomware Group

HIGH severityUnverified claimHow we verify

Mogren Listed by Pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 22, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Mogren Listed by Pear Ransomware Group

Reported August 22, 2026.

HIGH
Severity
August 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Mogren was listed by the Pear ransomware group on August 22, 2026, with personal data reportedly exposed. Individuals should check whether their information was affected and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group known as Pear has listed Mogren on its leak site, according to a report dated August 22, 2026. Mogren has not publicly confirmed the claim as of writing. The listing does not establish what, if anything, was taken, how many people might be involved, or whether the claim is accurate, exaggerated, or false. For clients and others who deal with a family-law practice, the practical stakes are clear: if sensitive files were ever copied in an intrusion of this kind, the material could touch private family, financial, and legal matters that people reasonably expect to stay confidential.

Until a company, regulator, or independent investigation confirms or disputes a claim, a leak-site post remains an unverified accusation used in an extortion process. Readers should treat the situation as unresolved and focus on conditional precautions rather than assuming their records are already public.

What the listing says

Public reporting states that Pear has listed Mogren on its leak site. The report is dated August 22, 2026. Beyond the organisation’s name and a brief note that Mogren offers services in family law, the available summary does not describe a method of intrusion, a timeline of alleged access, a volume of data, a ransom demand, or a countdown. The number of people potentially affected is unknown. Data types named as exposed are not disclosed in the material provided.

In short, the listing is a claim that Mogren appears on Pear’s site. It is not a verified inventory of stolen files, and it does not by itself prove that a breach occurred. Mogren has not publicly confirmed the claim as of writing. Details that are often discussed after confirmed incidents—such as how attackers supposedly entered systems, whether backups were involved, or what folders were allegedly copied—are simply not part of the disclosed record here.

The group behind it: Pear

Pear is presented in public reporting as a ransomware and extortion crew. Groups in this category commonly claim to have encrypted or stolen an organisation’s data and then pressure the target by threatening to publish material on a dedicated leak site if payment is not made. Listings on such sites are part of that pressure campaign. They can include company names, countdown timers, sample files, or marketing language about the scale of a haul; none of that content should be read as an audited fact sheet.

Well-established patterns among ransomware operators include double-extortion tactics—combining system disruption with the threat of data publication—and the use of leak sites to amplify leverage. Prior activity attributed to named crews is often tracked by security researchers and journalists, but those general patterns do not prove what happened in any single unconfirmed case. For this listing specifically, only what the public summary states should be attributed to Pear: that the group has named Mogren. Any further assertion about what Pear obtained from Mogren would go beyond the facts given and is not repeated here.

Mogren and its sector

Mogren is described in the reported summary as providing services in family law. Family-law practices advise and represent people in matters such as divorce, separation, child custody and support, adoption, domestic arrangements, and related financial settlements. Work of this kind routinely involves correspondence with courts, opposing counsel, and clients, as well as documents that record highly personal circumstances.

A credible intrusion into any organisation in this sector would matter because the subject matter is inherently sensitive. Clients often share details they would not disclose in ordinary commercial settings. Even an unconfirmed leak-site claim can cause worry among current and former clients, staff, and counterparties, because people cannot immediately know whether the claim is empty, recycled, or tied to real files. That uncertainty is itself a reason to explain carefully what a listing does and does not establish, rather than treating the accusation as settled history.

The information in question

The facts available for this report do not name specific data types as exposed. Exact contents tied to the Pear listing are therefore unconfirmed. It would be incorrect to state that particular categories of records were stolen or published.

If files from a family-law practice were ever taken in any incident, organisations in this sector typically hold materials such as client contact details, case files and pleadings, correspondence, financial disclosures used in support or property matters, identity documents supplied for legal processes, and notes touching children, health, or domestic circumstances where those issues arise in a case. Those are sector norms, not a confirmed inventory for Mogren. Whether any such material is involved here remains unknown on the public record described above.

The real-world impact

For individuals, the main risks if confidential legal files were actually copied and later misused include targeted phishing that references real case details, identity fraud using personal identifiers, embarrassment or harm from private family information becoming known to the wrong people, and pressure or scams that exploit knowledge of ongoing disputes. None of those outcomes is proven by a listing alone; they are the kinds of harm that follow when sensitive legal data truly circulates without authorisation.

For the organisation, an extortion listing can mean reputational strain, client questions, possible regulatory or professional-ethics inquiries depending on jurisdiction, and the operational cost of investigating and responding—whether or not the underlying claim is ultimately substantiated. A leak-site post does not, by itself, establish negligence, poor engineering, or failed detection. It establishes only that a crew has chosen to name the firm in public as part of its pressure tactics.

Because the count of people affected is unknown and data types are not disclosed, there is no sound basis to tell any specific reader that their information is already out. The responsible framing is conditional: if your data were among materials an attacker obtained, the usual fraud and privacy risks would apply; if the claim is hollow or unrelated to your records, those particular harms would not follow from this listing.

Steps worth taking either way

Treat unsolicited messages that mention legal cases, settlements, or “stolen files” with caution. Verify unexpected requests for money, passwords, or documents through a channel you already trust. Prefer unique passwords and multi-factor authentication on email and financial accounts so that a single exposed credential is less useful. If you are a client and you are concerned, contact the firm through official published channels and ask what, if anything, they are prepared to say publicly; do not rely on screenshots from criminal sites.

Monitor bank and credit activity for unfamiliar accounts or applications, and follow your local guidance on fraud alerts if you see something wrong. Keep copies of important personal documents in a safe place you control so that you are not dependent on a third party if you later need to prove identity or dispute a transaction. These steps are sensible whether or not Pear’s claim about Mogren is ever confirmed.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets unrelated to this allegation. That kind of check does not prove or disprove the Pear listing, but it can show whether your email is circulating in older, documented dumps and help you decide where to tighten account security first.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMogren security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Mogren’s full breach history →

More recent breaches

Island Networks Listed by Pear Ransomware GroupAugust 22, 2026Clifton Architectural Glass & Metal Listed by Pear Ransomware GroupAugust 21, 2026First Commerce LLC Listed by Pear Ransomware GroupAugust 21, 2026Medical Arts Chemists and Surgicals Listed by Pear Ransomware GroupAugust 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Mogren Listed by Pear Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by pear — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram