Quick Summary
AllegedExecutive Summary
Pear ransomware group listed Sonitor Technologies as a victim on its leak site on July 30, 2026. Sonitor Technologies, a company operating in the healthcare sector within the United States, aligns with the ransomware group’s typical targeting profile. This identification was made by SOCRadar’s Dark Web Monitoring service, which observed the listing. While a shallow sample of two records from sonitor[.]com revealed credential exposure, the limited scope suggests this is not a comprehensive view of any potential compromise. In the 60 days preceding this listing, Pear claimed 17 other victims, predominantly in the Healthcare, Business Services, and Manufacturing industries, with a significant concentration in the United States, Canada, and Singapore. Sonitor Technologies’ inclusion fits this pattern, particularly given the recent targeting of other healthcare organizations such as South Plains Rural Health Services, Inc., Carient Heart & Vascular, National Health Fund, and Tostrud & Temp, S.C.
Technical Analysis
SOCRadar’s analysis identified two records associated with corporate @sonitor[.]com usernames. These records were found in third-party services, not Sonitor-owned infrastructure, indicating credentials likely lifted from infected employee workstations. The freshness window for these credentials spans from December 2025 to February 2026, pointing to a potential workstation compromise as the primary risk. The limited number of records (two) means the exposure might be understated. It is important to note that other corporate domains or alternate email aliases could exist, and credentials might have been used and rotated before indexing. This telemetry does not exclude the possibility of further compromise on Sonitor’s direct infrastructure or other systems. Infostealer-harvested credentials are a common initial access vector for groups like Pear. Threat actors or access brokers acquire these credentials from underground markets, validate them, and use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals to deploy ransomware. While this specific telemetry does not confirm that these credentials were used by Pear to gain access to Sonitor Technologies, it highlights a prevalent method for such incidents. The identified accounts should be rotated immediately, the associated workstations reimaged, and the scope of the stealer-log query expanded to include internal and identity systems for a more comprehensive security posture assessment.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.