Ransomware victim disclosure
← All victimsAlpha IT
Claimed by Pear · listed 3 days ago
Status timeline
- ListedJun 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Pear
- Status
- Data leaked
- Country
- Norway
- Sector
- Technology
- Listed on leak site
- Jun 10, 2026
About the victim
AI dossier — public-source company profileAlpha IT AS is a Norwegian ICT company offering ASP (Application Service Provider) services, IT consulting, and managed IT services to small and medium-sized businesses. They specialize in Microsoft-based solutions and manage accounting systems for clients including integrations with Visma, Agresso, and SuperOffice.
- Industry
- IT Services & Managed Services (ASP/MSP)
- Address
- Øvre Flatåsvei 4D, 924 04 900, Norway
Attack summary
Severity: high — Confirmed exfiltration of significant business data including client private data, financials, and email correspondence. As an MSP/ASP provider, compromised client data represents exposure of third-party sensitive information at scale.The pear ransomware group claims to have exfiltrated financials, HR records, client private data, personal records, email correspondence, and database exports from Alpha IT.
Data the group says was taken
AI dossier — extracted from the leak post- Company financials
- HR records
- Clients' private data
- Personal records
- Mailboxes & email correspondence
- Database exports
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's site| | | | | | IT Services & Software Testing Financials, HR, Clients’ Private Data, Personal Records, Mailboxes & Email Correspondence, Database & Exports, etc. | | --- | | | | | |
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

