Ransomware victim disclosure
← All victimsWyatt Insurance Agency
Claimed by pear · listed 2 months ago
Status timeline
- Listed
Mar 30, 2026
- Data leaked
At a glance
- Group
- pear
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 30, 2026
About the victim
AI dossier — public-source company profileWyatt Insurance Agency is a full-service independent insurance agency operating out of two locations in Ceres and Manteca, California. The agency offers a broad range of personal and commercial insurance products including auto, home, renters, motorcycle, boat, commercial, and life insurance, as well as DMV services. It serves customers across California's Central Valley and partners with carriers such as Mercury, Safeco, Nationwide, Progressive, and others.
- Industry
- Personal & Commercial Insurance Agency
- Address
- 3525 Mitchell Rd Ste A, Ceres, CA 95307
- Employees
- 1-10
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by the threat actor. As an insurance agency, the compromised data almost certainly includes customer PII (names, addresses, vehicle/property details, potentially financial and driver information), which constitutes regulated sensitive personal data at the scale of the agency's client base.The ransomware group 'pear' claims to have exfiltrated data from Wyatt Insurance Agency and has published the data. The leak post references insurance product lines consistent with the agency's offerings, suggesting client and policy-related records may be among the disclosed data.
Data the group says was taken
AI dossier — extracted from the leak post- Auto insurance records
- Home insurance records
- Renters insurance records
- Motorcycle insurance records
- Client personal information (likely)
What the group claims
Auto Insurance, Home Insurance, Renters Insurance, Motorcycle Insurance
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
