Pear gang claims Texas urgent care operator Next Level Medical

The Pear ransomware group claimed data from Next Level Medical, operator of urgent care clinics across Texas.

MedRisk Staff
By
2 Min Read

The Pear ransomware group has claimed data stolen from Next Level Medical, the company behind Next Level Urgent Care clinics across Texas.

Ransomware.live recorded the listing on August 26, and RansomLook and GalaxyWarden logged the same claim the following day. The group’s post describes the victim as “affordable urgent care across Texas.”

Next Level Urgent Care operates walk-in clinics across Texas treating routine illnesses, minor injuries, and occupational health needs. The company has not issued a public statement or breach notification, and the claim remains unconfirmed.

Hudson Rock data tied to the company’s domain lists one compromised employee credential and 46 compromised users in infostealer logs, with RedLine, Lumma, Azorult, and generic stealer malware detected. Infostealer infections frequently precede ransomware intrusions, giving attackers the credentials they need to move into corporate networks.

The case follows a pattern of ransomware groups targeting urgent care chains, which handle high volumes of patient records but often rely on thin security operations. With claims circulating on leak sites before any official disclosure, urgent care operators should treat the listing as an incident trigger: reset credentials, review remote access logs, and check whether any data has appeared on public channels, while awaiting confirmation from the company.

Share This Article