Quick Summary
AllegedExecutive Summary
pear ransomware targeted EdgeChem Jamaica Limited, a chemical manufacturer based in Jamaica, adding the company to its leak portal on September 5, 2026. This targeting aligns with pear’s typical victim profile: companies located in the Caribbean, operating within the manufacturing sector, and possessing operational data and supply-chain dependencies that provide significant extortion leverage. SOCRadar’s Dark Web Monitoring service identified this listing. The company’s industry and geographic location make it a plausible target for such attacks. In the preceding 60 days, pear has claimed 15 other victims, with a notable concentration in the Healthcare, Manufacturing, and Professional Services sectors. The ransomware group’s operations primarily target organizations in the United States, Jamaica, and Canada. Other recent victims attributed to pear include Clifton Architectural Glass & Metal, Faro Products Inc., Island Networks, and Kovo Healthtech Corp. EdgeChem Jamaica Limited’s inclusion appears consistent with pear’s established targeting patterns, particularly its focus on Jamaican entities within the manufacturing industry.
Technical Analysis
SOCRadar’s query using the stealer-log dataset for the domain edgechem[.]com returned no records within the sampled data. This absence of evidence does not confirm that the organization is unaffected by credential compromise. It is possible that credentials exist in data feeds outside the scope of this query or are associated with personal email aliases rather than the corporate domain. Furthermore, any identified credentials may have already been used and rotated by threat actors prior to their indexing in the queried datasets. The null result from the stealer-log query necessitates continued monitoring of the corporate domain. Organizations are advised to conduct proactive credential hygiene checks and review password rotation policies. The potential for infostealer-harvested credentials to support ransomware operations remains a significant concern. These compromised credentials can provide threat actors with initial access to corporate networks, enabling further lateral movement and the deployment of ransomware. Therefore, it is crucial to maintain vigilance and implement robust security measures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.