Wyatt Insurance Agency Listed by Pear Ransomware Group
If you are a client of Wyatt Insurance Agency, here’s what is being claimed, and what it would mean for you.
Auto Insurance, Home Insurance, Renters Insurance, Motorcycle Insurance
— from Pear’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Wyatt Insurance Agency client?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On March 26, 2026, the Wyatt Insurance Agency appeared on the leak site of the pear ransomware group. The California-based agency, which sells auto, home, renters, and motorcycle insurance, may have had internal files stolen during a ransomware attack. Public reporting indicates that customer and employee records may have been among the exfiltrated data, although the exact number of people affected remains unknown.
Reported Details of the Breach
The pear ransomware group posted the Wyatt Insurance Agency on its dark-web leak site, listing the company under its public shaming page. Available reporting describes the incident as a classic ransomware operation in which the attackers first gained access, exfiltrated files, and then demanded payment to prevent publication. The exposed materials consist of internal files rather than a structured database dump, but these files are understood to contain sensitive business records typical of an insurance agency. No precise count of impacted individuals has been released, and the agency has not yet issued a public statement detailing the scope.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
- Every indexed leak tied to your address — all of them, named and dated
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why This Matters for You and Your Family
When an insurance agency is breached, the personal information you provided to obtain a quote or policy can end up in criminal hands. Names, addresses, dates of birth, Social Security numbers, driver’s license details, and policy information are the exact building blocks criminals need to open accounts in your name, file fraudulent tax returns, or sell your identity on underground markets. For families, a single breach can expose every member listed on a joint policy or added as a driver. Even if you never shopped at Wyatt Insurance Agency, credential-stuffing attacks mean that any password you reuse across sites could give attackers a path into your email, banking, or social media accounts.
The Doxxing and Identity-Chain Risks
Stolen insurance files often contain enough personal details to link your real identity to online handles, email addresses, phone numbers, and even children’s gaming accounts. Once attackers map these connections, they can launch doxxing campaigns that publish your home address, family photos, or children’s usernames. Credential leaks like this one frequently cascade into account takeovers because insurance portals sometimes store or transmit login details for payment systems. Public reporting indicates that such chains can move from a single breach to full identity compromise within weeks if no one is watching for new exposures.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, with cleanup of exposed records.
- Rotate any password you ever used on the Wyatt Insurance Agency website and enable two-factor authentication through an authenticator app everywhere that password was reused.
- Enable continuous DoxxScan monitoring across 13.1 billion+ breach records and more than 100 platforms so the next leak exposing you is caught in hours rather than months.
- Cover the entire household with DoxxScan family protection that extends to dependents and children’s gaming accounts that can chain back to the same address or identity details.
- Let remediation specialists handle takedown requests across data brokers and exposed records while you focus on securing your own accounts.
The Wyatt Insurance Agency breach is a reminder that your data can surface on a ransomware leak site without any warning. Acting quickly on exposed credentials and mapping your full identity chain can limit the damage before criminals turn stolen files into long-term fraud or harassment. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and household coverage that includes children’s gaming accounts—making it an effective tool for protecting both your family’s personal information and their online identities after incidents like this one.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Pittsrad Listed by Spirals Ransomware Group
Pittsrad was listed on the Spirals ransomware leak site. The group claims to have stolen internal da…
Accela.com Listed by EndZone Ransomware Group
Revenue: $144.4 million Accela is a comprehensive cloud based software platform used by state and l…
AT&T Listed by EndZone Ransomware Group
Revenue: $125.6 billion Initial access was via a CX contractor doing business with AT&T. Access ori…