On May 13, 2026, professional accounting and consulting firms operating in Manitoba appeared on the leak site of the pear ransomware group. The listing indicates that internal files were exfiltrated during a ransomware attack, although the exact number of people whose data was exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Exchange Group
Get alerted the next time Exchange Group files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Exchange Group’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on the pear leak site describes the victim as Exchange Group, a collection of accounting and consulting businesses based in the province of Manitoba. The entry states that internal files were taken. No specific count of affected individuals has been published, and details about the precise data types—such as client tax records, financial statements, or personal identifiers—have not been disclosed in available reporting. The listing appeared on May 13, 2026.
Why This Matters for You and Your Family
When an accounting firm’s internal files are stolen, the personal and financial information of its clients is often included. If you or anyone in your family has used a Manitoba-based accounting or consulting service in recent years, your tax returns, social insurance numbers, bank details, or home address may now sit in an attacker’s hands. Client data from accounting firms frequently contains enough detail to file fraudulent tax returns, open accounts in your name, or pressure you for payment. Children’s information can also be exposed when family tax filings or education-related consulting records are taken.
The Doxxing and Identity-Chain Risks
Stolen accounting documents rarely stay isolated. A single leaked email or phone number can be linked to your online handles, gaming accounts, and social profiles. Attackers follow these connections to build a complete picture of your household. Credential leaks like this one regularly cascade into account takeovers on email, banking, and gaming platforms. Once an attacker controls a child’s gaming account tied to a family email, further personal details can be extracted and sold or published. This identity-chain effect turns one breach into repeated harassment or identity theft that can last for years.