Quick Summary
AllegedExecutive Summary
Tostrud & Temp, S.C., a US-based firm specializing in business services, was listed as a victim by the Pear ransomware group on July 8, 2026. This information was identified via SOCRadar’s Dark Web Monitoring service. The Pear ransomware group has shown a pattern of targeting various sectors, with a recent concentration in business services, agriculture and food production, and financial services. The geographic focus of their attacks has predominantly been the United States, with occasional listings in Singapore and France.
Technical Analysis
The analysis of stealer logs queried against the domain tntcpas[.]com returned no direct records in the sampled data. However, this does not conclusively rule out a breach. The dataset is a sample, and credentials could be exposed through legacy domains or staff personal email aliases used on corporate systems. The lack of immediate findings indicates that further monitoring is warranted. Initial access for ransomware groups like Pear often involves credentials harvested by infostealers, which are then used to access systems via Microsoft 365, VPNs, or remote access portals. While the sampled data was clean, it’s crucial to perform credential hygiene checks and maintain ongoing domain monitoring to identify any potential exposures.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.