LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Practi-Cal Listed by Pear Ransomware Group

HIGH severityUnverified claimHow we verify

Practi-Cal Listed by Pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 20, 2026

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Practi-Cal Listed by Pear Ransomware Group

Reported August 20, 2026.

HIGH
Severity
August 20, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Practi-Cal was listed by the Pear ransomware group on August 20, 2026, after an undisclosed number of people had their personal data exposed. Individuals are urged to check whether their information was included and to take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to use public leak sites as pressure tools, posting company names and countdowns whether or not an intrusion is later verified by the organisation, a regulator, or independent researchers. In that climate, a listing is a claim that deserves careful reading, not automatic acceptance as a finished incident report.

On or about August 20, 2026, the group known as Pear listed Practi-Cal on its leak site. Public detail in the listing is thin: the number of people who might be affected is unknown, and the types of data allegedly involved are not disclosed. Practi-Cal has not publicly confirmed the claim as of writing. What follows treats Pear’s post as an unverified accusation and explains what such a listing does and does not establish for people who may have ties to the firm or its clients.

Inside the listing

According to the available record, Pear has named Practi-Cal on its leak site under a headline that frames the company as listed by the group. The reported date associated with that appearance is August 20, 2026. The listing-related summary describes Practi-Cal as a comprehensive platform to manage Medi-Cal billing, LEA BOP, and CRCS submissions efficiently. Beyond that framing, the public material does not set out a technical method of intrusion, a timeline of alleged access, a file inventory, or a count of affected individuals.

People affected are recorded as unknown. Data types named as exposed are not disclosed. No dollar figures, sample file names, or quoted threats beyond the fact of the listing itself appear in the facts provided for this article. In short, the public footprint is a named listing and a short business description, not a corroborated breach dossier. Until Practi-Cal or another authoritative source confirms or denies the claim, the responsible reading is that Pear asserts the company belongs on its site; independent confirmation is absent.

Who is Pear?

Pear is known publicly as a ransomware and extortion-style actor that, like other groups in this ecosystem, has used leak-site publication to increase pressure on organisations it says it has compromised. Established patterns among such crews include encrypting systems when they can, exfiltrating data when they claim to have done so, and threatening to publish or auction material if payment demands are not met. Listings are marketing and leverage as much as evidence: they can be timely, recycled, inflated, or wrong.

For this specific victim name, only what the facts state should be attributed to Pear: that the group has listed Practi-Cal and that the listing is associated with the reported date and the brief platform description above. No additional claims by Pear about file volumes, particular databases, or negotiation status are included in the material at hand, and none should be invented. Readers should separate general knowledge of how extortion groups operate from the narrow, unconfirmed assertion that this company is their current target.

About Practi-Cal

Practi-Cal is described in the listing-related summary as a platform oriented toward Medi-Cal billing and related education- and claims-adjacent submission workflows, including LEA BOP and CRCS. Medi-Cal is California’s Medicaid program; organisations and vendors in this niche typically sit between healthcare providers, local educational agencies, and public payers. That role often means handling administrative, billing, and identity-linked records that are sensitive even when they are not full clinical charts.

A leak-site claim against a firm in this sector matters because of that intermediary position. Schools, clinics, billing staff, and families can all touch the same pipelines. The consequence of an allegation is not proof that those pipelines were opened; it is that people who depend on accurate, private handling of eligibility and claims data have a reason to watch for official notices and to treat unsolicited messages about the incident with caution.

What was likely exposed

The facts do not name exposed data types; they state that those types are not disclosed. It is therefore not possible to say what, if anything, left Practi-Cal’s control. Asserting a specific inventory would repeat the attacker’s marketing as if it were an audit.

If files were taken from an organisation in this line of work, firms in the Medi-Cal billing and LEA-related submissions space typically hold some mix of provider and agency identifiers, member or student-related administrative fields, contact details, claim and billing artefacts, and credentials or logs used to operate submission systems. Those categories are sector norms, not a confirmed contents list for this claim. Exact contents remain unconfirmed, and the number of people who might be affected remains unknown.

Why it matters

For individuals and organisations that use or appear in Medi-Cal and LEA billing workflows, the practical risk is conditional. If administrative or billing data were copied, common follow-on harms include targeted phishing that references real program names, attempts to reset accounts with partial identity details, and fraud against benefits or reimbursement channels. Even when a listing is exaggerated or false, scammers often ride the news cycle and impersonate the named company or “incident response” teams.

For the organisation named on the site, a public extortion listing can disrupt client trust and force costly verification work whether or not the underlying claim is accurate. That pressure is why crews publish names. What a leak-site entry does establish is that a criminal group chose to single out Practi-Cal in public. What it does not establish is confirmed theft, a verified data set, negligence, or the quality of any particular security control. Those conclusions would require evidence that is not in the public record described here.

What to do now

If you work with Practi-Cal or appear in Medi-Cal, LEA BOP, or CRCS-related billing chains, treat the Pear listing as a prompt to prepare, not as proof that your records are already public. Prefer official channels from Practi-Cal or your own provider or agency for any incident notice. Be wary of emails, texts, or calls that urge urgent payment, password entry, or document uploads while citing this listing. If you are told that your data may have been involved, ask what categories and what support are actually being offered, and document the advice you receive.

Strengthen ordinary account hygiene on email and portals you use for healthcare or school billing: unique passwords, multi-factor authentication where available, and careful review of forwarding rules and new device logins. Monitor financial and benefits statements for unfamiliar activity. If you later receive a confirmed notice naming specific data, follow that notice’s steps for credit or fraud freezes as appropriate to your situation.

You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data sets, which is a useful baseline even when a new claim remains unverified. Stay with primary sources as this situation develops, and remember that Pear’s listing is an accusation until Practi-Cal or another authoritative body confirms otherwise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPracti-Cal security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Practi-Cal’s full breach history →

More recent breaches

Austin Plastic Surgery Institute Listed by Pear Ransomware GroupAugust 20, 2026Medical Arts Chemists and Surgicals Listed by Pear Ransomware GroupAugust 20, 2026Club One Casino Listed by Pear Ransomware GroupAugust 20, 2026Experts Entreprendre Listed by Everest Ransomware GroupAugust 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Practi-Cal Listed by Pear Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by pear — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram