RANSOMWARE VICTIM⚠ DUPLICATE CLAIM
CTI & Coordinators
cticoordinators.com
pear📍 United States (US)📅 March 2, 2026
8
same group
Attack Intelligence
CTI & Coordinators was compromised in a ransomware attack attributed to pear in March 2026. The organization, operating in an undisclosed sector in United States, was added to the group's data leak site as part of an extortion campaign.
pear operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Freight transportation services throughout the United States and province of Ontario Canada
Additional Details
Status
announced
Revenue
$16M
Activity
Transportation Services
Other Victims — pear (8)
Sonitor Technologies
US · Healthcare
Jul 2026
Metropolitan Construction Systems
US · Manufacturing
Jul 2026
South Plains Rural Health Services, Inc.
US · Healthcare
Jul 2026
Carient Heart & Vascular
US · Healthcare
Jul 2026
Faro Products Inc.
CA · Manufacturing
Jul 2026
Tostrud & Temp, S.C.
US · Business Services
Jul 2026
CNW Electronics Pte Ltd
SG · Manufacturing
Jul 2026
AC Beverage, Inc.
US · Agriculture and Food Production
Jun 2026
Quick Facts
CountryUnited States (US)
Attack DateMar 2, 2026
Domaincticoordinators.com
Intel Sourceransomware.live
StatusDUPLICATE CLAIM
Threat Group
External Links
Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.