Ransomware victim disclosure
← All victimsPracti-Cal
Claimed by Pear · listed 5 hours ago
Status timeline
- ListedAug 20, 2026
- Data leakeddate unknown
At a glance
- Group
- Pear
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Aug 20, 2026
About the victim
AI dossier — public-source company profilePracti-Cal appears to be a healthcare or medical practice management software/services company based on the domain and victim classification. The company serves educational and healthcare institutions, processing sensitive patient and student records.
- Industry
- Healthcare Technology & Medical Practice Management
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at scale including PHI (patient health information), PII (personally identifiable information), and educational records affecting millions of students and patients. This involves HIPAA-regulated healthcare data and FERPA-protected educational records.The pear group claims to have exfiltrated multiple categories of sensitive data including financial records, HR data, partner/vendor information, client data, PII, PHI records, student and patient records, email correspondence, and source code.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- HR data
- Partners' and vendors' data
- Clients' private data
- PII & PHI records
- Student records (millions)
- Patient records (millions)
- Email correspondence
- Dropbox stored data
- Database exports
- Source code
What the group claims
Comprehensive platform to manage Medi-Cal billing, LEA BOP, and CRCS submissions efficiently
The leak post
captured from the group's site| | | | | | Financials, HR, Partners’ & Vendors’ Data, Clients’ Private Data, PII & PHI Records, Millions of Students’ & Patients’ Records, Mailboxes & Email Correspondence, Dropbox Stored Data, Database Exports, Developments & Source Code, etc. | | --- | | | | | |
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

