Medical Arts Chemists and Surgicals Data Breach

Alleged

Ransomware claim involving Medical Arts Chemists and Surgicals

Published: Aug 20, 2026 Pear
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Medical Arts Chemists and Surgicals
Industry
Business Services
Threat Actor
Pear
Date of Incident
Aug 20, 2026

Executive Summary

Medical Arts Chemists and Surgicals, a healthcare company based in the United States, was recently identified as a victim on the PEAR ransomware group’s dark web portal, with the listing published on August 20, 2026. This discovery was made through SOCRadar’s Dark Web Monitoring service. The company, which provides prescription pharmaceutical and surgical supply services within the U.S. healthcare market, was listed in a manner consistent with PEAR’s known focus on the healthcare sector. In the 60 days preceding this listing, PEAR claimed 14 other victims on its leak portal. The group has consistently targeted the Healthcare, Business Services, and Manufacturing sectors, with a primary geographic focus on the United States, Canada, and Singapore. Other U.S. healthcare organizations similar to Medical Arts Chemists and Surgicals that have recently been listed by PEAR include Austin Plastic Surgery Institute, Sonitor Technologies, South Plains Rural Health Services, Inc., and Carient Heart & Vascular. This incident further underscores PEAR’s ongoing pattern of targeting U.S. healthcare providers across various segments of the industry.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure related to the medarts.net domain. The query returned three credentials associated with corporate @medarts.net email accounts, indicating access to Rackspace cloud identity infrastructure and WordPress administration endpoints. These logs, dated around May 2026, suggest that these compromised credentials were in circulation via infostealer datasets several months before PEAR’s listing of Medical Arts Chemists and Surgicals. This profile is highly indicative of corporate intrusion risks. For ransomware groups like PEAR, the exfiltration of credentials through infostealers represents a common initial access method. Operators or initial access brokers typically acquire fresh credential logs from underground marketplaces, validate their corporate relevance, and then utilize them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Although the stealer-log data does not definitively confirm that these specific credentials were used by PEAR in an attack against Medical Arts Chemists and Surgicals, the observed pattern—corporate email credentials exposed against cloud identity and web administration infrastructure months prior to the leak-site listing—is consistent with the typical attack chain for such incidents. The connection between credential exposure and potential intrusion pathways highlights the importance of proactive security measures. CTI teams should consider credential rotation on cloud identity services as an immediate priority. This includes continuous dark web and stealer-log monitoring, proactive credential hygiene checks, and regular password rotation. Reviewing multi-factor authentication settings and monitoring activity across Microsoft 365, VPNs, and remote-access portals are also critical steps to mitigate risk.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.