ZeroHour

pear

ransomware group · aka unknown · unknown · active since 2026-06-18 (earliest post tracked by this dashboard; any earlier activity unknown)

Victims · 7d
1▼1
Victims · 30d
12active targets
Victims · 90d
27
All-time (tracked)
119since 2025-08-06
Last post
09-11 15:43UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Pear is a low-profile ransomware and data-extortion group tracked primarily through postings on its leak site. This dashboard has recorded 26 victims since 18 June 2026 (2 in the last 7 days), with the most recent post on 4 September 2026, indicating sustained but low-volume activity averaging roughly two named victims per week. Listed victim names suggest a focus on small and mid-sized organizations, with healthcare, healthcare billing services, legal, and other professional and industrial firms frequently represented. Public vendor research, law-enforcement reporting, and revenue estimates for Pear are limited or absent, so its origins, membership, affiliate links, and intrusion tradecraft remain largely unknown.

Tactics & tooling
  • Publishes stolen victim data on a dedicated leak site as extortion leverage (double-extortion pattern)
  • Victim set skews toward small and mid-sized organizations rather than large enterprises
  • Named victims span multiple countries, including the United States and Jamaica
  • Sustained but low posting cadence (about 2 victims per week on average per dashboard counts)
  • Whether the group conducts full ransomware deployment or primarily data theft and extortion is not clearly established in public reporting
  • Initial access, exfiltration, and encryption tradecraft not yet documented in public vendor research (unknown)
Targeted sectors
Healthcare and medical servicesHealthcare revenue-cycle and billing servicesLegal servicesArchitecture, construction, and building productsChemicalsHospitality and gamingTechnology and networking services
Notable public victims

Kovo Healthtech Corp, Club One Casino, Austin Plastic Surgery Institute, Sonitor Technologies, Mogren, Glessner & Ahrens, P.S., EdgeChem Jamaica Limited

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
ComTec Systems · Sep 26, 2025Specializing in business telecommunications and cost reduction consulting
U.S. Battery · Aug 6, 2025
Garrison Law Firm · Aug 6, 2025
Hankin & Mazel, PLLC · Aug 6, 2025
JWiz · Aug 6, 2025
Kalchschmid GmbH & Co. KG · Aug 6, 2025
The Danvers Law Offices · Aug 6, 2025
The Job Shop · Aug 6, 2025
Preferred Homes Realty · Aug 6, 2025
Alt Vision · Aug 6, 2025
Tas Nz Bay Limited · Aug 6, 2025
ThinkBig Health Care Solutions · Aug 6, 2025
Twin Oaks Presbyterian Church · Aug 6, 2025
Ail Hospitality Group · Aug 6, 2025
Bromack Manufacturing · Aug 6, 2025
Clarkston First Baptist Church · Aug 6, 2025
Brookside Homes · Aug 6, 2025
Hamilton Park · Aug 6, 2025
Neff Specialties · Aug 6, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .