
Rhysida and Pear Ransomware Groups Strike Educational and Legal Sectors in Global Weekend Extortion Surge
Threat actors Rhysida and Pear have claimed new victims including Battle Creek Public Schools and Mogren, Glessner & Ahrens. These attacks highlight a persistent focus on high-pressure extortion targets.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- North America
- Confidence:
- High Confidence
- Source:
- CrowdStrike Falcon Intelligence
- Read Time:
- 4 min
Executive Summary
On August 22, 2026, Encrygma threat intelligence identified a significant escalation in ransomware operations, with multiple high-profile organizations added to cybercriminal leak sites within a single 24-hour window. The Rhysida ransomware group officially claimed responsibility for a disruptive breach at Battle Creek Public Schools, while the emerging "Pear" ransomware collective targeted the legal firm Mogren, Glessner & Ahrens. Additionally, the DireWolf group listed Aztec Software, indicating a focused weekend surge against the educational and professional services sectors. These incidents demonstrate the persistent efficacy of the Ransomware-as-a-Service (RaaS) model and the aggressive application of double-extortion tactics designed to maximize financial leverage over victims.
Threat Analysis
The current threat landscape is defined by a rapid diversification of RaaS affiliates and the emergence of specialized extortion groups. While established actors like Rhysida continue to exploit public sector vulnerabilities, newer groups like Pear and KryBit are scaling their operations with alarming speed. The attack on Battle Creek Public Schools aligns with a broader trend observed throughout mid-2026, where educational institutions have seen a 275% increase in ransomware incidents. These groups prioritize targets with high operational sensitivity and low downtime tolerance, such as schools and law firms, to increase the psychological pressure of the extortion clock. The use of "leak timers" has become a standard psychological warfare tactic to force rapid negotiations.
Technical Details
Recent telemetry from these incidents indicates a heavy reliance on initial access gained through the exploitation of unpatched VPN vulnerabilities and sophisticated credential harvesting techniques. In the Rhysida campaign, threat actors likely utilized compromised administrative credentials to gain an initial foothold before deploying Cobalt Strike beacons for lateral movement and internal reconnaissance. The Pear group has been observed utilizing a custom C++ based encryptor that specifically targets file extensions associated with legal, financial, and proprietary documentation. Both groups employ a double-extortion strategy: exfiltrating massive volumes of sensitive data using legitimate tools like Rclone, WinSCP, or MegaSync before initiating the final encryption phase. This ensures that even if the victim successfully restores from offline backups, the threat of a public data leak remains a potent lever for the attackers.
Attribution Assessment
Rhysida is a well-documented RaaS operation that first appeared in May 2023 and has maintained a high tempo of operations through 2026. They are characterized by their opportunistic "smash and grab" style, often targeting organizations with legacy systems or weaker perimeter defenses. The Pear group is a more recent emergence, first identified in early 2026. While their specific origins are still under investigation, their TTPs share significant overlap with older Slavic-speaking cybercriminal collectives, suggesting they may be a rebranding of a defunct operation or a spin-off from established groups like LockBit or Black Basta. The Gentlemen group, also active this weekend, appears to be a financially motivated splinter group focusing on high-net-worth investment firms.
Implications
The breach of educational and legal entities carries severe risks that extend far beyond immediate financial extortion. For Battle Creek Public Schools, the exposure of student and staff PII (Personally Identifiable Information) could lead to long-term identity theft risks and significant legal liabilities for the district. For professional services firms like Mogren, Glessner & Ahrens, the breach of attorney-client privilege and the potential leak of sensitive litigation data could result in irreparable reputational damage and severe regulatory sanctions. These attacks highlight the systemic risk posed to public infrastructure and the critical need for enhanced data protection standards across all sectors.
Recommendations
Encrygma strongly recommends that organizations immediately audit all internet-facing assets, with a specific focus on VPN, RDP, and other remote access gateways. Implementing phishing-resistant Multi-Factor Authentication (MFA) is the single most effective control to prevent credential-based access. Furthermore, organizations must maintain immutable, air-gapped backups and conduct regular incident response tabletop exercises to ensure operational readiness against double-extortion scenarios. Continuous monitoring of dark web leak sites and Telegram-based threat channels for early indicators of compromise is also advised to provide an early warning of impending data disclosures.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
