Kellys Home Center Data Breach

Alleged

Ransomware claim involving Kellys Home Center

Published: Sep 28, 2026 Pear
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Kellys Home Center
Industry
Retail
Threat Actor
Pear
Date of Incident
Sep 28, 2026

Executive Summary

Pear ransomware has listed Kellys Home Center, a US-based organization operating within the home furnishings and retail sector, as a victim on September 28, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring capabilities. It is important to note that the domain referenced in the available data appears to be a third-party business profile aggregator rather than Kellys Home Center’s primary corporate domain. This distinction potentially limits the scope of stealer-log queries that can be accurately performed, impacting the depth of technical analysis. The Pear ransomware group has demonstrated significant activity, claiming 16 other victims within the past 60 days, indicating a focused operational tempo. Analysis of their targeting trends reveals a strong concentration in the Healthcare sector, accounting for approximately 40% of their claimed victims. Other frequently targeted industries include Retail & E-Commerce and Manufacturing. Geographically, Pear exhibits an overwhelming focus on the United States. Recent victims with overlapping retail profiles or US-based operations include Martin Lawrence Galleries, Indroj Medical Group Inc., Westside GI, and Foss Inc. Kellys Home Center’s profile as a US retail entity aligns directly with Pear’s established targeting patterns.

Technical Analysis

A stealer-log query was performed against the available domain reference, which was identified as a third-party aggregator rather than Kellys Home Center’s primary corporate domain. This query yielded no returned records. It is critical to understand that this specific query has limited coverage of Kellys Home Center’s actual credential infrastructure. A comprehensive analysis would require a query directly against the organization’s primary corporate domain to provide a more meaningful signal. Therefore, the null result from this limited query should be treated with additional caution and does not confirm the absence of compromised credentials. The domain data gap significantly limits the ability to correlate this listing with specific credential exposure events. The observed listing is consistent with opportunistic initial access broker (IAB)-sourced access, where threat actors leverage compromised credentials obtained through various means. The lack of directly queryable data for Kellys Home Center’s primary online presence means that the extent of potential credential exposure supporting this listing remains unconfirmed. Assessment: The strong alignment between Kellys Home Center’s sector (US retail) and the Pear ransomware group’s core targeting profile (US-retail focus) suggests a high degree of relevance for this listing. The limitations in accessing and querying primary corporate domain data mean that the full scope of potential credential exposure cannot be definitively assessed. This situation is consistent with threat actors leveraging information or credentials acquired through initial access brokers. Next Steps: Identify and query Kellys Home Center’s primary corporate domain for stealer-log coverage to improve visibility. Continue monitoring for Pear activity. Standard credential hygiene practices, including regular password rotation and robust multi-factor authentication enforcement, are recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.