Quick Summary
AllegedExecutive Summary
Carient Heart & Vascular, a healthcare entity operating within the United States, was recently identified on the dark web portal of the pear ransomware group on July 15, 2026. This discovery was made via SOCRadar’s Dark Web Monitoring service. The organization’s presence in the healthcare sector, coupled with its US location, aligns with pear’s established targeting patterns, particularly its focus on smaller American entities. In the 60 days preceding this listing, pear claimed 21 other victims. The group frequently targets the business services, healthcare, and manufacturing sectors, with a significant concentration of victims in the United States, Canada, and Singapore. Notably, other recent victims with similar profiles to Carient, such as US healthcare providers South Plains Rural Health Services, Inc., National Health Fund, Tostrud & Temp, S.C., and AC Beverage, Inc., further highlight pear’s tendency to group similar victims. Carient’s listing on the same day as South Plains emphasizes this operational approach.
Technical Analysis
SOCRadar’s analysis of initial access vectors, correlated with stealer-log telemetry, revealed limited exposure for the carient.com domain. Specifically, a single corporate username was observed on a third-party service without any credentials being found on organization-owned systems. There were no flagged high-value identity, mail, or VPN endpoints. This isolated record, dated December 9, 2025, primarily suggests a risk of workstation compromise, where a corporate email surfacing in an external log typically indicates a stealer-infected endpoint rather than a direct compromise of Carient’s core systems. Due to this thin sample, determining the scope of exposure with certainty is not possible. For ransomware operations like pear’s, credentials harvested by infostealers serve as a common initial access method. Threat actors or initial access brokers frequently acquire recent logs from illicit marketplaces, validate the contained corporate credentials, and then use them to access platforms like Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the single exposed credential does not conclusively prove its use by pear in this specific incident, the presence of a corporate identity in stealer logs represents a potential pathway for intrusion. Given the limited data, CTI teams should consider the affected endpoint and account as points of interest for further investigation. It is recommended that CTI teams treat the affected endpoint and account as worth investigating and prioritize credential rotation and MFA review. Continued monitoring for additional exposure that may not be reflected in this specific data slice is also advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.