Practi-Cal Data Breach

Alleged

Ransomware claim involving Practi-Cal.

Published: Aug 20, 2026 Pear
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Practi-Cal
Industry
Business Services
Threat Actor
Pear
Date of Incident
Aug 20, 2026

Executive Summary

Practi-Cal, a company operating within the United States, has been identified as a victim by the PEAR ransomware group. The listing, published on August 20, 2026, was detected by SOCRadar’s Dark Web Monitoring service. Practi-Cal functions as a software platform crucial for managing Medi-Cal billing, LEA BOP, and CRCS submissions for healthcare providers in California. Its position as a central entity for billing and compliance processes makes it a significant target due to the substantial volume of sensitive healthcare data it handles on behalf of its clients. In the 60 days leading up to this listing, the PEAR ransomware group has claimed responsibility for 14 other victims, demonstrating consistent activity. The group primarily targets the Healthcare, Business Services, and Manufacturing sectors, with a strong geographical focus on the United States, Canada, and Singapore. Recent victims of PEAR that share similarities with Practi-Cal, such as U.S.-based organizations within the healthcare and services domain, include Austin Plastic Surgery Institute, Club One Casino, Medical Arts Chemists and Surgicals, and Sonitor Technologies. This pattern indicates that Practi-Cal aligns with PEAR’s established targeting preferences for healthcare-adjacent businesses located in the U.S.

Technical Analysis

SOCRadar’s analysis of infostealer-harvested credentials against the domain practi-cal.com yielded no records within the queried data slice. It is important to note that a lack of records in this specific dataset does not definitively confirm that the organization is unaffected. Credentials may exist in threat feeds outside of the one queried, could have been used and subsequently rotated before indexing, or might have been harvested using personal email aliases instead of the official corporate domain. For ransomware groups like PEAR, compromised credentials obtained through infostealers are a recognized initial access vector. Threat actors or initial access brokers frequently source fresh credential logs from underground marketplaces. They then validate these corporate credentials to gain access to platforms such as Microsoft 365, VPNs, or remote-access portals, which subsequently enables them to deploy ransomware. The absence of correlative evidence in this particular query does not eliminate this possibility; credentials might exist in other datasets, have been rotated prior to indexing, or were harvested via alternative means. Consequently, CTI teams should continue to monitor for further threat actor activity and perform proactive credential hygiene checks, rather than interpreting a null query result as a confirmation of no compromise.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.