Critical Unverified

Westside GI Ransomware Claim by pear - Sept 2026

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming Westside GI data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming Westside GI data breach - full size

Claim Summary

On or around September 22, 2026, a ransomware group operating under the name “pear” allegedly listed Westside GI, a US-based ambulatory endoscopy center, on its dark web leak site. According to the threat actor, the organization was added to the group’s victim roster, with the claimed data described only as belonging to an “ambulatory endoscopy center.” The group has not disclosed a data volume, sample files, or any proof-of-compromise artifacts in the information available to us.

This claim has NOT been independently verified by Yazoul Security. It remains a single-source assertion published by the threat actor itself. No confirmation has been issued by Westside GI, and no regulatory or law enforcement body has validated the claim as of this writing.

Threat Actor Profile

The group tracked here is pear. Our current intelligence holdings on pear are extremely limited. The group’s total number of known victims is unknown, its tooling has not been publicly documented, and there is no substantive open-source research available that profiles its operators, affiliates, or infrastructure.

Because pear lacks a documented track record, its credibility cannot be meaningfully assessed at this time. Some newly emerged or rebranded groups publish inflated or entirely fabricated claims to build notoriety and pressure victims into paying. Others are legitimate but simply under-researched. Without corroborating evidence, we treat this claim as unproven. We have no YARA rules, detection signatures, or TTP-specific guidance attributable to pear to share at this time. Organizations seeking general ransomware detection guidance can review our advisory library at /advisory/.

Alleged Data Exposure

The threat actor claims to hold data from Westside GI but has not specified a volume, format, or category. The only descriptor provided is “ambulatory endoscopy center,” which suggests the material, if genuine, could relate to clinical operations. Endoscopy centers typically process scheduling records, insurance and billing information, and procedure-related documentation.

We have not seen, and will not publish, any data samples, download links, credentials, or access instructions. No files have been made available to Yazoul Security for review, and we cannot confirm that any exfiltrated data exists. The absence of a published sample is notable: many groups release proof files to substantiate claims, and pear has not done so here.

Potential Impact

If the claim is accurate, a healthcare provider of this type could face exposure of patient scheduling and billing data, operational disruption, and regulatory scrutiny under HIPAA and applicable state laws. Healthcare remains a favored target for ransomware operators because of the sensitivity of records and the operational pressure to restore services quickly.

However, these are hypothetical consequences contingent on the claim being true. At present there is no confirmed evidence of data theft, encryption, or service interruption at Westside GI. Patients and partners should avoid assuming a breach has occurred based solely on a leak site posting.

What to Watch For

  • Any official statement from Westside GI confirming or denying the incident.
  • Publication of data samples by pear, which would raise the claim’s credibility.
  • Notification filings with regulators such as HHS OCR, if a breach is confirmed.
  • Emergence of additional pear victims, which would help establish the group’s pattern of behavior.
  • Independent research or vendor reporting that profiles pear’s tools and tactics.

We will update our tracking at /intel/ if corroborating information emerges.

Disclaimer

This report is based solely on an unverified claim published by a ransomware threat actor. Yazoul Security has NOT independently confirmed that Westside GI suffered a ransomware attack, that any data was exfiltrated, or that pear is responsible. Ransomware groups frequently exaggerate or fabricate claims to pressure victims. All statements here should be treated as allegations until verified by reliable sources.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.