Quick Summary
AllegedExecutive Summary
Club One Casino, a hospitality and gaming organization based in the United States, has been identified as a victim on the dark web portal of the PEAR ransomware group. This listing, published on August 20, 2026, was detected by SOCRadar’s Dark Web Monitoring service. Club One Casino operates as a card-room gaming venue in Central California, offering gambling and entertainment. This incident marks a diversification for PEAR, as the group has historically focused more heavily on the healthcare sector, suggesting an opportunistic approach to targeting various industries. In the 60 days preceding this listing, PEAR claimed 14 other victims, primarily targeting the Healthcare, Business Services, and Manufacturing sectors. Geographically, their victims are most frequently located in the United States, Canada, and Singapore. Notable previous victims include Austin Plastic Surgery Institute, Practi-Cal, Medical Arts Chemists and Surgicals, and Sonitor Technologies. Club One Casino’s inclusion deviates from PEAR’s established victim profile, which tends to be healthcare-centric, indicating the group’s willingness to exploit available access in other sectors.
Technical Analysis
SOCRadar’s analysis of Club One Casino, specifically querying clubonecasino.com against stealer-log telemetry, yielded no matching records within the analyzed dataset. It is crucial to understand that a null result from this specific query does not definitively confirm the absence of a compromise. Such findings may arise if credentials appeared in data feeds not covered by this particular analysis, if compromised credentials were used and subsequently rotated before being indexed, or if they were harvested using personal email aliases instead of the primary corporate domain. For ransomware groups like PEAR, the exploitation of infostealer-harvested credentials is a recognized method for initial access. Threat actors or initial access brokers typically source current credential logs from underground marketplaces, validate the authenticity of corporate credentials, and then use these to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, paving the way for ransomware deployment. The lack of observed credentials in this specific query does not preclude such a scenario. It is possible that credentials exist in other datasets, were rotated prior to indexing, or were obtained through alternate means. Consequently, cybersecurity teams should prioritize ongoing dark web and stealer-log monitoring, alongside proactive credential hygiene practices. This includes regular password rotation and reviewing multi-factor authentication configurations. The absence of evidence from a single query should not be interpreted as definitive proof of no compromise; rather, it underscores the importance of continuous vigilance and security posture management.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.