Ransomware victim disclosure
← All victimsKovo Healthtech Corp
Claimed by Pear · listed 6 hours ago
Status timeline
- ListedSep 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Pear
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Sep 5, 2026
About the victim
AI dossier — public-source company profileKovo Healthtech Corp (operating as Kovo+) is a Vancouver-based technology company specializing in AI-driven process automation for the healthcare sector, with a focus on medical billing optimization through its Kovo RCM subsidiary. The company operates an acquisition-focused business model targeting mid-market medical billing firms and broader healthcare sector entities.
- Industry
- Healthcare IT & Medical Billing Process Automation
- Address
- 925 West Georgia Street, Suite 1600, Vancouver, BC V6C 3L2, Canada
Attack summary
Severity: critical — Confirmed exfiltration of regulated healthcare data at scale—millions of patient PII and PHI records represent protected health information under HIPAA and equivalent regulations. Exposure of healthcare provider data, financial records, and operational details compounds the breach severity.The pear ransomware group claims to have exfiltrated multiple categories of sensitive data including company and partner business operations records, financial details, provider data, email correspondence, and database exports containing millions of patient personally identifiable information (PII) and protected health information (PHI) records.
Data the group says was taken
AI dossier — extracted from the leak post- Business operations and financial records (company and partners)
- Client and customer details
- Provider data
- Email mailboxes and correspondence
- Database exports with patient PII/PHI records
- Patients' medical information
What the group claims
Versatile technology company leading the Charge in AI process automation initiatives to drive Impact and innovation across diverse industries
The leak post
captured from the group's site| | | | | | Company's and Its Partners’, Clients’ & Customers’ Business Operations and Financial Details, Multiple Providers’ Data, Mailboxes & Email Correspondence, Database Exports With Millions of Patients’ PII & PHI Records, etc. | | --- | | | | | |
Sources
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

