Austin Plastic Surgery Institute Data Breach

Alleged

Ransomware claim involving Austin Plastic Surgery Institute

Published: Aug 20, 2026 Pear
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Austin Plastic Surgery Institute
Industry
Business Services
Threat Actor
Pear
Date of Incident
Aug 20, 2026

Executive Summary

Austin Plastic Surgery Institute, a healthcare organization based in the United States, has been identified as a victim of the PEAR ransomware group. The listing appeared on the group’s dark web portal on August 20, 2026, as detected by SOCRadar’s Dark Web Monitoring service. This institute, specializing in plastic surgery and staffed by board-certified surgeons in Texas, joins a growing roster of U.S. healthcare entities targeted by PEAR. The healthcare sector’s reliance on sensitive patient data and interconnected systems often makes it an attractive target for ransomware operations. In the 60 days preceding this listing, PEAR claimed a total of 14 other victims. The group’s primary targets include the Healthcare, Business Services, and Manufacturing sectors, with a significant concentration of victims located in the United States, Canada, and Singapore. Notable recent victims with similar profiles to Austin Plastic Surgery Institute, specifically U.S.-based healthcare organizations, include Medical Arts Chemists and Surgicals, Sonitor Technologies, South Plains Rural Health Services, Inc., and Carient Heart & Vascular. The inclusion of Austin Plastic Surgery Institute aligns precisely with PEAR’s established pattern of targeting the U.S. healthcare industry.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry for the domain austinpsi.com returned no records within the queried dataset. It is crucial to understand that a null result does not definitively confirm that the organization is unaffected. The absence of evidence in this specific query does not rule out compromise, as credentials may exist in data feeds not included in this dataset, could have been used and subsequently rotated before indexing, or might have been harvested using personal email aliases instead of the primary corporate domain. Ransomware groups like PEAR frequently leverage infostealer-harvested credentials as an initial access vector. Threat actors or initial access brokers typically source these credentials from underground marketplaces, validate them, and then use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals. This access is then exploited to deploy ransomware. The lack of direct evidence in this query does not preclude such a scenario. Organizations are advised to consider continued monitoring and proactive credential hygiene measures, including password rotation and multi-factor authentication reviews, rather than interpreting a null query result as a clean bill of health.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.