Were you recently affected by a data breach?

Austin Plastic Surgery Institute Data Breach

Austin Plastic Surgery Institute, an Austin, Texas cosmetic and reconstructive surgery practice, was reportedly targeted in a ransomware attack claimed by the group Pear. The scope of any exposed patient data has not yet been publicly confirmed.

Austin Plastic Surgery Institute
Date of Breach: Claimed August 18, 2026 (unconfirmed by the practice)
CAU logo

Who was affected:

Clients of Austin Plastic Surgery Institute

Impacted Data:

Not publicly disclosed at this time

Austin Plastic Surgery Institute, a cosmetic and reconstructive surgery practice based in Austin, Texas, is reportedly the target of a ransomware attack claimed by a cybercriminal group known as Pear. As of this writing, the practice has not publicly confirmed the incident or issued a formal notification describing what patient information, if any, was accessed. Companies entrusted with sensitive medical and financial information have a legal and ethical responsibility to protect that data and to promptly notify anyone whose information may have been compromised.

Austin Plastic Surgery Institute’s Data Breach Investigation

According to a posting reviewed by cybersecurity researchers, the threat group Pear claimed responsibility for a cyberattack on Austin Plastic Surgery Institute, with the claim surfacing on a dark web leak site in August 2026. Cybersecurity outlets tracking ransomware activity reported the claimed intrusion date as August 18, 2026, with the listing itself discovered roughly two days later. At this stage, Austin Plastic Surgery Institute has not released its own public statement confirming a breach, and no regulatory filing describing the categories of exposed data has been located. This pattern, where a ransomware group’s dark web claim surfaces before an official company notification, is common in the current threat landscape. Ransomware gangs often post evidence of a successful intrusion, including a purported volume of exfiltrated data, to pressure a victim into paying a ransom before the organization has completed its own forensic investigation or legal review.

Plastic surgery and cosmetic medicine practices, like other healthcare providers, are attractive targets for ransomware operators because they routinely store some of the most sensitive categories of personal information a patient can provide, including full names, contact details, insurance information, financial records, and detailed medical and treatment histories. That combination of financial and medical data makes healthcare providers a particularly lucrative target: stolen records can be used not only for identity theft and fraudulent credit applications but also for medical identity theft, insurance fraud, and highly personalized phishing schemes that reference a patient’s actual treatment history to appear legitimate.

Notification laws in most states require a company to investigate a suspected breach, determine which categories of data were involved, and notify affected individuals within a legally defined window once that determination is made. Because Austin Plastic Surgery Institute has not yet issued a public notification, it is not yet possible to say with certainty which specific data elements, such as Social Security numbers, financial account information, or protected health information, may have been exposed. Regulatory investigations and forensic reviews following a ransomware claim like this one commonly take weeks to months to complete, and affected individuals are often not notified until that process concludes. In the meantime, individuals who have received care from Austin Plastic Surgery Institute should remain alert for any official communication from the practice, since that notification would be the authoritative source for what, if any, of their personal information was involved.

Ransomware attacks against smaller, specialty medical practices have grown increasingly common as attackers recognize that these organizations frequently maintain smaller in-house cybersecurity teams than large hospital systems, while still holding equally sensitive patient records. Should Austin Plastic Surgery Institute confirm that patient data was accessed or exfiltrated, affected individuals may have legal options to pursue compensation for the time, expense, and risk created by the incident, regardless of how quickly or slowly the practice’s own investigation concludes.

When Did This Breach Occur?

Cybersecurity researchers tracking the threat group Pear identified a claim of compromise referencing Austin Plastic Surgery Institute, with the underlying incident reportedly occurring on or around August 18, 2026, and the dark web posting itself surfacing around August 20, 2026. Austin Plastic Surgery Institute has not publicly confirmed this date, and an official timeline, including when the practice itself first detected any unauthorized activity, has not yet been released.

What Information Was Breached?

The specific categories of information potentially exposed in this incident have not been publicly confirmed by Austin Plastic Surgery Institute or verified through an official notification. Patients of cosmetic and reconstructive surgery practices typically provide sensitive information including full names, contact and billing details, insurance information, and detailed medical and treatment records, any of which could be at risk if this claimed attack is confirmed. This page will be updated if and when Austin Plastic Surgery Institute discloses further detail.

What You Can Do

If you have received care from Austin Plastic Surgery Institute, consider taking the following precautions while more information becomes available:

  • Monitor your bank and credit card statements closely for any unfamiliar charges
  • Check your credit reports for accounts or inquiries you do not recognize
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus
  • Watch for phishing emails, texts, or calls that reference Austin Plastic Surgery Institute or claim to be a follow-up to this incident
  • Save any notification letter or official communication you receive from the practice for your records

File a Data Breach Lawsuit Against Austin Plastic Surgery Institute

If it is confirmed that your personal information was exposed in this incident, you may have legal options to pursue compensation for the risk, time, and expense this breach has caused. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Claimed August 18, 2026 (unconfirmed by the practice)
Date of Breach: December 18, 2025 (discovered by vendor Aesto, LLC)
Date of Breach: June 22, 2026 (discovered)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.