PEAR Hacking Group Steals 16TB of Data from Monmouth University in Extortion Attack
The cybercriminal group PEAR (Pure Extraction and Ransom) has claimed responsibility for a major data breach at Monmouth University, infiltrating its servers earlier this month and exfiltrating 16 terabytes of sensitive data nearly 28 times larger than the average cyberattack. Unlike traditional ransomware operations, PEAR opted against encrypting the stolen data, citing advancements in decryption tools that reduce the effectiveness of such tactics. Instead, the group is leveraging data theft and extortion, threatening to release the information unless a ransom is paid.
University President Patrick Leahy confirmed the incident in a communication to students and staff, stating that law enforcement has been notified and an external cybersecurity firm has been engaged to investigate the breach. The attack was first reported by Comparitech, a UK-based technology research organization, which identified the shift toward "double extortion" where attackers steal data and demand payment to prevent its public release as an emerging trend in cybercrime.
Rebecca Moody, head of research at Comparitech, highlighted the severity of the breach, noting that the 16TB haul is among the largest observed. She also warned of the growing threat posed by AI-driven malware, which accelerates the development of sophisticated cyberattacks. PEAR claims to have targeted 64 organizations to date, though only 13 have publicly confirmed breaches, including two community colleges.
The incident underscores the evolving tactics of cybercriminals and the increasing challenges institutions face in protecting digital assets. Law enforcement agencies continue to advise against paying ransoms, emphasizing that reporting such incidents helps disrupt criminal operations before they escalate into larger threats.
Monmouth University Leon Hess Business Council cybersecurity rating report: https://www.rankiteo.com/company/monmouth-university-leon-hess-business-council
"id": "MON1774600278",
"linkid": "monmouth-university-leon-hess-business-council",
"type": "Cyber Attack",
"date": "3/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Students and Staff',
'industry': 'Education',
'name': 'Monmouth University',
'type': 'Educational Institution'}],
'customer_advisories': 'University President Patrick Leahy communicated the '
'incident to students and staff',
'data_breach': {'data_encryption': 'No',
'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Likely',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive data'},
'description': 'The cybercriminal group PEAR (Pure Extraction and Ransom) has '
'claimed responsibility for a major data breach at Monmouth '
'University, infiltrating its servers and exfiltrating 16 '
'terabytes of sensitive data. The group is leveraging data '
'theft and extortion, threatening to release the information '
'unless a ransom is paid. Unlike traditional ransomware '
'operations, PEAR did not encrypt the stolen data, citing '
'advancements in decryption tools.',
'impact': {'brand_reputation_impact': 'High',
'data_compromised': '16TB',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'lessons_learned': 'The incident underscores the evolving tactics of '
'cybercriminals and the increasing challenges institutions '
'face in protecting digital assets. The shift toward '
"'double extortion' and the use of AI-driven malware are "
'emerging trends in cybercrime.',
'motivation': 'Extortion',
'ransomware': {'data_encryption': 'No', 'data_exfiltration': 'Yes'},
'recommendations': 'Law enforcement agencies advise against paying ransoms '
'and emphasize reporting such incidents to disrupt '
'criminal operations.',
'references': [{'source': 'Comparitech'}],
'response': {'communication_strategy': 'University President Patrick Leahy '
'communicated the incident to students '
'and staff',
'law_enforcement_notified': 'Yes',
'third_party_assistance': 'External cybersecurity firm'},
'threat_actor': 'PEAR (Pure Extraction and Ransom)',
'title': 'PEAR Hacking Group Steals 16TB of Data from Monmouth University in '
'Extortion Attack',
'type': 'Data Breach and Extortion'}