Austin Plastic Surgery Institute, a cosmetic and reconstructive surgery practice based in Austin, Texas, is reportedly the target of a ransomware attack claimed by a cybercriminal group known as Pear. As of this writing, the practice has not publicly confirmed the incident or issued a formal notification describing what patient information, if any, was accessed. Companies entrusted with sensitive medical and financial information have a legal and ethical responsibility to protect that data and to promptly notify anyone whose information may have been compromised.
Austin Plastic Surgery Institute’s Data Breach Investigation
According to a posting reviewed by cybersecurity researchers, the threat group Pear claimed responsibility for a cyberattack on Austin Plastic Surgery Institute, with the claim surfacing on a dark web leak site in August 2026. Cybersecurity outlets tracking ransomware activity reported the claimed intrusion date as August 18, 2026, with the listing itself discovered roughly two days later. At this stage, Austin Plastic Surgery Institute has not released its own public statement confirming a breach, and no regulatory filing describing the categories of exposed data has been located. This pattern, where a ransomware group’s dark web claim surfaces before an official company notification, is common in the current threat landscape. Ransomware gangs often post evidence of a successful intrusion, including a purported volume of exfiltrated data, to pressure a victim into paying a ransom before the organization has completed its own forensic investigation or legal review.
Plastic surgery and cosmetic medicine practices, like other healthcare providers, are attractive targets for ransomware operators because they routinely store some of the most sensitive categories of personal information a patient can provide, including full names, contact details, insurance information, financial records, and detailed medical and treatment histories. That combination of financial and medical data makes healthcare providers a particularly lucrative target: stolen records can be used not only for identity theft and fraudulent credit applications but also for medical identity theft, insurance fraud, and highly personalized phishing schemes that reference a patient’s actual treatment history to appear legitimate.
Notification laws in most states require a company to investigate a suspected breach, determine which categories of data were involved, and notify affected individuals within a legally defined window once that determination is made. Because Austin Plastic Surgery Institute has not yet issued a public notification, it is not yet possible to say with certainty which specific data elements, such as Social Security numbers, financial account information, or protected health information, may have been exposed. Regulatory investigations and forensic reviews following a ransomware claim like this one commonly take weeks to months to complete, and affected individuals are often not notified until that process concludes. In the meantime, individuals who have received care from Austin Plastic Surgery Institute should remain alert for any official communication from the practice, since that notification would be the authoritative source for what, if any, of their personal information was involved.
Ransomware attacks against smaller, specialty medical practices have grown increasingly common as attackers recognize that these organizations frequently maintain smaller in-house cybersecurity teams than large hospital systems, while still holding equally sensitive patient records. Should Austin Plastic Surgery Institute confirm that patient data was accessed or exfiltrated, affected individuals may have legal options to pursue compensation for the time, expense, and risk created by the incident, regardless of how quickly or slowly the practice’s own investigation concludes.
When Did This Breach Occur?
Cybersecurity researchers tracking the threat group Pear identified a claim of compromise referencing Austin Plastic Surgery Institute, with the underlying incident reportedly occurring on or around August 18, 2026, and the dark web posting itself surfacing around August 20, 2026. Austin Plastic Surgery Institute has not publicly confirmed this date, and an official timeline, including when the practice itself first detected any unauthorized activity, has not yet been released.
What Information Was Breached?
The specific categories of information potentially exposed in this incident have not been publicly confirmed by Austin Plastic Surgery Institute or verified through an official notification. Patients of cosmetic and reconstructive surgery practices typically provide sensitive information including full names, contact and billing details, insurance information, and detailed medical and treatment records, any of which could be at risk if this claimed attack is confirmed. This page will be updated if and when Austin Plastic Surgery Institute discloses further detail.
What You Can Do
If you have received care from Austin Plastic Surgery Institute, consider taking the following precautions while more information becomes available:
- Monitor your bank and credit card statements closely for any unfamiliar charges
- Check your credit reports for accounts or inquiries you do not recognize
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Watch for phishing emails, texts, or calls that reference Austin Plastic Surgery Institute or claim to be a follow-up to this incident
- Save any notification letter or official communication you receive from the practice for your records
File a Data Breach Lawsuit Against Austin Plastic Surgery Institute
If it is confirmed that your personal information was exposed in this incident, you may have legal options to pursue compensation for the risk, time, and expense this breach has caused. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.