Quick Summary
AllegedExecutive Summary
Kovo Healthtech Corp, a US-based digital health provider, has been targeted by the ‘pear’ ransomware group. The listing was reported on September 5, 2026. As a company handling protected health information (PHI), Kovo Healthtech faces not only the typical pressures of data extortion but also potential regulatory consequences under HIPAA due to the sensitive nature of the data it manages. This targeting aligns with the ‘pear’ group’s ongoing activity in the digital health sector. The ‘pear’ ransomware group has claimed 15 victims in the past 60 days, with a primary focus on the Healthcare, Manufacturing, and Professional Services sectors. Geographically, their operations predominantly target organizations in the United States, Jamaica, and Canada. Recent healthcare victims attributed to ‘pear’ include NEXT LEVEL MEDICAL, LLC; Austin Plastic Surgery Institute; Medical Arts Chemists and Surgicals; and Sonitor Technologies. The inclusion of Kovo Healthtech Corp continues the pattern of ‘pear’ targeting US-based digital health firms.
Technical Analysis
A query for stealer-log records associated with the domain `kovoplus[.]com` returned no results. However, this null finding does not definitively clear Kovo Healthtech Corp. It is possible that credentials may exist in data feeds not covered by this specific query, or they might be associated with personal email aliases rather than the main corporate domain. The absence of immediate stealer-log records also does not rule out a potential compromise. Credentials could have been used and subsequently rotated before being indexed in the queried datasets. Continuous monitoring of the corporate domain and related threat intelligence feeds is recommended to detect any emerging threats or further activity. Given that infostealer-harvested credentials can significantly aid ransomware operations, ongoing vigilance is crucial. This includes monitoring for any exposure of corporate account access, particularly concerning Microsoft 365, VPNs, or other remote-access portals that could serve as initial entry points for threat actors.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.