Ransom! Optimum First Mortgage (Pear’s acting group’s promotional blog) (SEP-2026)

Ransom! Optimum First Mortgage (Pear’s acting group’s promotional blog) (SEP-2026)

Optimum First Mortgage (Pear’s acting group’s promotional blog) in the USA reported a ransomware claim by blacknevas involving the alleged theft and encryption of approximately 9.3TB of financials, HR, clients’ private data, PII/PHI, email correspondence/mailboxes, database exports, and OneDrive-stored data. The threat actor is said to have leveraged access via dark-web download links for optimumfirst.com. #UnitedStates

Incident Details

Information

  • Optimum First Mortgage is a U.S.-based wholesale lender specializing in mortgage solutions, home purchase loans, refinancing options, and debt restructuring.
  • The organization operates in the finance, lending, and brokerage sector.
  • The reported data exposure is 9.3 TB.
  • Compromised data includes financial records, HR files, clients’ private data, financial details, PII and PHI records, mailboxes and email correspondence, database exports, and OneDrive-stored files.
  • Related download links were provided for the leaked materials.

Disclaimer: This post is based on public claims made by the ransomware group "blacknevas". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live