US Graphite Listed by pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
US Graphite was listed by the pear ransomware group on August 19, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone connected to the company should check for notices and change passwords or monitor accounts as a precaution.
Ransomware groups continue to target industrial and engineering firms as part of a broader pattern of double-extortion attacks that combine system encryption with data theft and public leak-site pressure. In this landscape, even specialised manufacturers can find themselves listed without prior public notice, leaving employees, partners and customers to assess potential exposure from limited available details.
On 19 August 2025, the organisation US Graphite appeared on a listing attributed to the pear ransomware group. Public reporting indicates that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and further operational specifics have not been disclosed. The incident matters because it involves a firm that handles engineering data and business records typical of the advanced materials sector, raising concrete questions about what may have left the organisation’s control.
Inside the incident
According to the available record, US Graphite was listed by the pear ransomware group on 19 August 2025. The reported summary states that internal files were exfiltrated in a ransomware attack. No confirmed figures for the volume of data, the precise date of initial access, the encryption status of systems, or the number of individuals affected have been made public. Method of intrusion, ransom demands and any subsequent negotiations are undisclosed. The listing itself constitutes a claim by the group rather than independent verification of every asserted detail.
Specialists monitoring ransomware activity noted the entry as part of pear’s public leak-site activity. Beyond the statement that internal files were taken, no further technical indicators or timelines have been released in the source material. As a result, the full scope of the event remains limited to what the group has asserted and what the organisation has not yet publicly expanded upon.
Who is pear?
Pear operates as a ransomware group that follows the now-common double-extortion model: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if payment is not made. Like other groups in this category, it typically advertises victims with brief descriptions of the organisation and claims about the volume or type of material obtained. Public documentation of pear’s activity shows a pattern of targeting mid-sized enterprises across manufacturing, engineering and related industrial sectors, using the leak site as leverage rather than relying solely on operational disruption.
The group’s listings are claims. In this case, the appearance of US Graphite on pear’s site is presented by the actors as evidence of a successful intrusion and data theft; independent confirmation of every element of that claim has not been supplied in the public record. Prior activity attributed to pear has involved similar postings of internal documents and business files, consistent with the tactics of contemporary ransomware operations that prioritise both encryption and exfiltration.
US Graphite and its sector
US Graphite specialises in carbon and graphite engineering solutions. Organisations of this type design, manufacture and supply high-performance carbon and graphite materials used in industrial processes, energy applications, metallurgy and specialised engineering components. They typically maintain technical drawings, material specifications, customer contracts, supplier records, employee information and proprietary process data.
A breach at such a firm is consequential because the sector sits at the intersection of manufacturing supply chains and specialised materials science. Compromised engineering files can affect production partners, while business records can expose commercial relationships. Even when the exact contents remain unconfirmed, the nature of the work means that both operational continuity and the confidentiality of technical know-how are at stake. Public detail on the company’s size, locations or specific customer base is limited in the incident record, so the assessment rests on the general profile of carbon and graphite engineering specialists.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown of file types, volumes or categories has been disclosed. Organisations in the carbon and graphite engineering field commonly hold design documents, material test data, purchase orders, employee records, financial information and correspondence with suppliers and clients. Whether any of those categories were among the files taken in this incident is unconfirmed.
Because the public summary stops at “internal files,” it is not possible to state with certainty what personal or commercial data may have been involved. The absence of a confirmed count of affected individuals further limits precise risk statements. Readers should treat the exposure as involving organisational internal material whose exact composition remains unknown outside the group’s claim and the organisation’s own knowledge.
Why it matters
For people connected to US Graphite—employees, contractors, customers or suppliers—the primary concern is that internal files can contain names, contact details, contractual terms or technical information that could be misused for fraud, social engineering or competitive intelligence. Even without confirmation of personal data, the presence of business records creates opportunities for targeted phishing or impersonation.
For the organisation itself, the incident carries operational and reputational consequences. Ransomware events often disrupt production systems, and the public listing can affect partner confidence. Recovery costs, potential regulatory notifications and the need to review access controls are typical follow-on effects, though no specific financial figures or regulatory actions have been reported in the available facts. The unknown scale of the exfiltration means residual risk cannot yet be fully quantified.
What to do if you're exposed
If you have a relationship with US Graphite or believe your information may have been among the internal files, take the following practical steps:
- Monitor financial and email accounts for unusual activity and enable multi-factor authentication where available.
- Treat unsolicited messages that reference the company or engineering projects with caution; verify requests through known channels.
- Change passwords on any accounts that may have been reused in work-related systems.
- Request a free exposure scan of your email address to check whether it has appeared in known breach data sets.
- Keep records of any suspicious contact and report confirmed fraud to the relevant authorities.
Public detail on this incident remains limited. Further information, if released by the organisation or confirmed by independent researchers, will clarify the precise contents and scale. Until then, measured vigilance is the most useful response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Angstrom Automotive Group Listed by pear Ransomware GroupU.S. Battery Listed by pear Ransomware GroupBromack Manufacturing Listed by pear Ransomware GroupOffice Furniture Group Listed by pear Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the US Graphite Listed by pear Ransomware Group →
Publicly posted by pear — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.