Optimum First Mortgage (Pear’s acting group’s promotional blog) in the USA reported a ransomware claim by blacknevas involving the alleged theft and encryption of approximately 9.3TB of financials, HR, clients’ private data, PII/PHI, email correspondence/mailboxes, database exports, and OneDrive-stored data. The threat actor is said to have leveraged access via dark-web download links for optimumfirst.com. #UnitedStates
Incident Details
- Victim: Optimum First Mortgage (Pear’s acting group’s promotional blog)
- Sector: Financial Services
- Country:
- Actor: blacknevas
- Source: http://ctyfftrjgtwdjzlgqh4avbd35sqrs6tde4oyam2ufbjch6oqpqtkdtid.onion/d7ba2a3f-0d92-4bc9-b30d-6f0edbeaf54b
- Discovered: 2026-09-16T19:54:07.070553+00:00
- Published: 2026-09-16T19:41:31+00:00
Information
- Optimum First Mortgage is a U.S.-based wholesale lender specializing in mortgage solutions, home purchase loans, refinancing options, and debt restructuring.
- The organization operates in the finance, lending, and brokerage sector.
- The reported data exposure is 9.3 TB.
- Compromised data includes financial records, HR files, clients’ private data, financial details, PII and PHI records, mailboxes and email correspondence, database exports, and OneDrive-stored files.
- Related download links were provided for the leaked materials.

Disclaimer: This post is based on public claims made by the ransomware group "blacknevas". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.