← All ransomware groups
Pear logo

Ransomware group profile · #59 by claimed victims

Pear ransomwarealso Pure Extraction And Ransom

Pure Extraction And Ransom (PEAR) Team is the community of highly responsible and strictly disciplined members. We are a private team and have nothing common with any other threat actors. We've been monitoring this field for a long-long time. So, we understand all the processes and know well how it all works.

Active First seen Aug 2025
120Victims claimed on leak sites
13Victims in the last 30 days
25Victims in the last 90 days
11Countries hit
13Leak-site URLs tracked, 4 online
11 Sep 2026Latest claim recorded

Victimology

Who Pear claims to have breached, from 120 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 7OctNov 2025: 5Dec 2025: 3Jan 2026: 4JanFeb 2026: 6Mar 2026: 6Apr 2026: 8AprMay 2026: 13Jun 2026: 11Jul 2026: 8JulAug 2026: 9Sep 2026: 4

Top sectors

Professional Services37
Healthcare25
Manufacturing12
Financial Services9
Technology7
Retail & E-Commerce7
Government & Defense6
Hospitality4

Top countries

United States105
Jamaica3
Canada3
Egypt1
Switzerland1
New Zealand1
Singapore1
Australia1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Foss Inc. 11 Sep 2026
Foss Inc. fossinc.com Not Found US 11 Sep 2026
EdgeChem Jamaica Limited edgechem.com Manufacturing JM 5 Sep 2026
Kovo Healthtech Corp kovoplus.com Healthcare US 5 Sep 2026
NEXT LEVEL MEDICAL, LLC nextlevelurgentcare.com Healthcare US 26 Aug 2026
Island Networks islandnetjm.com Technology JM 22 Aug 2026
Mogren, Glessner & Ahrens, P.S. mgrlaw.com Professional Services US 22 Aug 2026
Clifton Architectural Glass & Metal cliftonglass.com Manufacturing US 21 Aug 2026
First Commerce LLC firstcommercellc.com Financial Services US 21 Aug 2026
Medical Arts Chemists and Surgicals medarts.net Healthcare US 20 Aug 2026
Club One Casino clubonecasino.com Hospitality US 20 Aug 2026
Practi-Cal practi-cal.com Other US 20 Aug 2026

All 120 Pear victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Pear is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Pear ransomware still active?
Pear is tracked as active. The most recent leak-site claim VULONE recorded is dated 11 September 2026. 13 victims were claimed in the last 30 days.
How many victims has Pear claimed?
VULONE has recorded 120 leak-site victim claims attributed to Pear since August 2025, across 11 countries and 14 sectors.
Which industries does Pear target?
The sectors most often named on the Pear leak site are Professional Services, Healthcare, Manufacturing.
Which countries are most affected by Pear?
Most Pear victims recorded by VULONE are located in United States, Jamaica, Canada.
Where does VULONE get Pear victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

VULONE research mentioning Pear

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].