Ransomware victim disclosure
← All victimsUnknown (Medi-Cal Billing Platform)
Claimed by Pear · listed 1 day ago
Status timeline
- ListedSep 12, 2026
Current state: Listed for ransom
At a glance
- Group
- Pear
- Status
- Listed for ransom
- Sector
- Healthcare
- Listed on leak site
- Sep 12, 2026
About the victim
AI dossier — public-source company profileA software platform provider that offers comprehensive Medi-Cal billing management, LEA BOP, and CRCS submission services for healthcare organizations in California. The company serves as a backend billing infrastructure provider for medical practices and health plans.
- Industry
- Healthcare / Medical Billing Software
Attack summary
Severity: medium — The victim is a healthcare billing platform that would handle sensitive patient billing and insurance submission data. However, the leak post provides no proof of actual data exfiltration or encryption, only a listing entry. The sensitivity is elevated due to healthcare sector and billing data, but lack of proof and operational impact details prevents higher classification.The pear group lists this victim alongside multiple other organizations in what appears to be a directory or portfolio listing. No specific claims of encryption, exfiltration, or data theft are stated in the leak post excerpt provided. The post shows only a descriptive entry for a Medi-Cal billing platform without operational details of the alleged attack.
Data the group says was taken
AI dossier — extracted from the leak post- Medi-Cal billing records
- LEA BOP submissions
- CRCS submissions
- Patient billing data
What the group claims
Comprehensive platform to manage Medi-Cal billing, LEA BOP, and CRCS submissions efficiently
The leak post
captured from the group's site| | | | | | | | --- | | | | | | | | Leading provider of installation, maintenance services to the energy industry | | --- | | | | | | | | Versatile technology company leading the Charge in AI process automation initiatives to drive Impact and innovation across diverse industries | | --- | | | | | | | | Manufacture Automotive, Industrial, Decorative and Furniture Coatings, and distribute associated products Paint, Coating, and Adhesive Manufacturing, Chemicals, Petrochemicals, Glass & Gases, Manufacturing | | --- | | | | | | | | Provider for Business-class Internet, Cybersecurity & Home Wi-Fi Internet Service Providers, Website Hosting & Internet-related Services | | --- | | | | | | | | **Mogren, Glessner & Ahrens, P.S. ** Law Firms & Legal Services | | --- | | | | | | | | Privately held real estate investment and development company Advertising Networks, Finance & Real Estate Business Services | | --- | | | | | | | | **Clifton Architectural Glass & Metal ** A company that …
Screenshot of the leak post

Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

