EdgeChem Jamaica Limited Data Breach

Alleged

Ransomware claim involving EdgeChem Jamaica Limited

Published: Sep 5, 2026 Pear
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
EdgeChem Jamaica Limited
Industry
Healthcare
Threat Actor
Pear
Date of Incident
Sep 5, 2026

Executive Summary

pear ransomware targeted EdgeChem Jamaica Limited, a chemical manufacturer based in Jamaica, adding the company to its leak portal on September 5, 2026. This targeting aligns with pear’s typical victim profile: companies located in the Caribbean, operating within the manufacturing sector, and possessing operational data and supply-chain dependencies that provide significant extortion leverage. SOCRadar’s Dark Web Monitoring service identified this listing. The company’s industry and geographic location make it a plausible target for such attacks. In the preceding 60 days, pear has claimed 15 other victims, with a notable concentration in the Healthcare, Manufacturing, and Professional Services sectors. The ransomware group’s operations primarily target organizations in the United States, Jamaica, and Canada. Other recent victims attributed to pear include Clifton Architectural Glass & Metal, Faro Products Inc., Island Networks, and Kovo Healthtech Corp. EdgeChem Jamaica Limited’s inclusion appears consistent with pear’s established targeting patterns, particularly its focus on Jamaican entities within the manufacturing industry.

Technical Analysis

SOCRadar’s query using the stealer-log dataset for the domain edgechem[.]com returned no records within the sampled data. This absence of evidence does not confirm that the organization is unaffected by credential compromise. It is possible that credentials exist in data feeds outside the scope of this query or are associated with personal email aliases rather than the corporate domain. Furthermore, any identified credentials may have already been used and rotated by threat actors prior to their indexing in the queried datasets. The null result from the stealer-log query necessitates continued monitoring of the corporate domain. Organizations are advised to conduct proactive credential hygiene checks and review password rotation policies. The potential for infostealer-harvested credentials to support ransomware operations remains a significant concern. These compromised credentials can provide threat actors with initial access to corporate networks, enabling further lateral movement and the deployment of ransomware. Therefore, it is crucial to maintain vigilance and implement robust security measures.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.