ThinkBig Health Care Solutions Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ThinkBig Health Care Solutions was listed by the pear ransomware group on June 24, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; individuals should check whether their information was involved and take appropriate protective steps.
ThinkBig Health Care Solutions has been listed by the ransomware group known as pear, according to a report dated June 24, 2025. Public detail remains limited: the number of people affected is unknown, and the only confirmed description of the exposure is that internal files were allegedly exfiltrated in a ransomware attack. The listing itself is a claim by the group rather than an independently verified confirmation of the full scope.
Because the organisation works with medical practices on billing, collections and practice management, any compromise of its systems raises practical questions for the practices it serves and the patients whose information those practices handle. Exact contents of the files and the method of intrusion have not been disclosed.
What happened
On or around June 24, 2025, ThinkBig Health Care Solutions appeared on the leak site associated with the pear ransomware group. The available summary states that internal files were exfiltrated during a ransomware attack. No further technical details—such as the initial access vector, the duration of the intrusion, the volume of data taken, or any ransom demand—have been made public. The number of individuals whose information may have been involved is listed as unknown. At present the incident is known primarily through the group’s claim of the listing rather than through detailed statements from the organisation or independent forensic reports.
The group behind it: pear
Pear is a ransomware operation that follows the double-extortion model common among contemporary groups: data is stolen before systems are encrypted, and the threat of public release is used to pressure victims. Groups of this type typically maintain dedicated leak sites where they post victim names, sample files and countdown timers. They often target mid-sized organisations in sectors that hold sensitive operational or personal data, including healthcare-related services. Public reporting on pear has described the use of standard ransomware tooling, affiliate models and opportunistic targeting rather than highly customised campaigns against single high-profile entities. In this case the group claims to have listed ThinkBig Health Care Solutions; no additional statements attributed specifically to this victim beyond the listing itself have been released in the public record.
About ThinkBig Health Care Solutions
ThinkBig Health Care Solutions specialises in providing comprehensive services to medical practices. These services include contract acquisition, billing, collections and practice management. Organisations of this type sit between clinical providers and the administrative and financial systems that keep practices running. They routinely process claims data, patient demographic information, insurance details, provider contracts and operational records. Because they act as a hub for multiple practices, a single compromise can affect data belonging to many independent medical offices and the patients those offices serve. Healthcare-adjacent service providers are frequent targets precisely because the data they hold is both sensitive and operationally critical.
What data was at risk
The only data type named in the available facts is “internal files” said to have been exfiltrated in the ransomware attack. No inventory of those files, no sample documents and no confirmation of specific categories such as patient records, billing ledgers or employee information have been published. Organisations that manage billing, collections and practice operations for medical practices typically hold protected health information, insurance identifiers, financial account details, provider credentials and internal business documents. Whether any of those categories were present among the exfiltrated files remains unconfirmed. The precise contents of the stolen material are therefore unknown at this time.
The real-world impact
For individuals whose information may have been among the internal files, the primary risks are identity theft, medical identity fraud and targeted phishing that uses accurate personal or insurance details. Even limited administrative data can be combined with other breaches to create convincing social-engineering attempts. For the medical practices that rely on ThinkBig Health Care Solutions, operational disruption is possible if billing or collections systems were encrypted or if trust in the service provider is damaged. The organisation itself faces the usual consequences of a ransomware incident: potential regulatory scrutiny under healthcare privacy rules, contractual obligations to notify clients, and the cost of investigation and remediation. Because the scale of the exposure is still listed as unknown, the full extent of these effects cannot yet be measured.
If your data was in this claimed breach
If you are a patient, provider or employee connected to a practice that uses ThinkBig Health Care Solutions, treat the incident as a possible exposure of internal records until more detail emerges. Practical first steps include:
- Monitor bank, credit-card and insurance statements for unexpected activity and place a free fraud alert with the major credit bureaus if you notice anything unusual.
- Be cautious of unsolicited emails, calls or texts that reference medical bills, insurance claims or practice-management issues; verify any such contact through official channels.
- Request a copy of your medical and billing records from your own provider so you have a baseline against which to check future statements.
- Consider freezing your credit if you believe sensitive identifiers may have been involved, and review any free annual credit reports carefully.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets. This does not confirm or rule out involvement in the present incident, but it provides a quick way to see whether personal information is circulating more widely. Continue to watch for official notices from ThinkBig Health Care Solutions or from the practices you deal with, as further Reported Details may still be released.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Iroquois Memorial Hospital Listed by pear Ransomware GroupMedical Center, LLP Listed by pear Ransomware GroupWestern Orthopaedics Listed by pear Ransomware GroupBrevard Skin Listed by pear Ransomware GroupLatest breaches
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.