Kellys Home Center Listed by Pear Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Kellys Home Center was listed by the Pear ransomware group on September 28, 2026. The group claims to hold data belonging to an undisclosed number of people; customers and employees should check their accounts for unusual activity and change passwords as a precaution.
On September 28, 2026, the ransomware group Pear listed Kellys Home Center on its leak site. That listing is an unverified claim by the group. Kellys Home Center has not publicly confirmed the claim as of writing. Public detail on what, if anything, left the company’s control is limited.
For customers, employees, and suppliers, the practical stakes are straightforward: if personal or account information were ever taken and later published or traded, people could face phishing, account takeover attempts, or misuse of contact and purchase-related details. Until a company, regulator, or independent index confirms otherwise, the listing itself does not prove that outcome. It does mean people who deal with a home-goods retailer may want to treat the claim as a prompt to tighten ordinary account hygiene—conditionally, and without assuming their records are already exposed.
What the listing says
According to the listing attributed to Pear, Kellys Home Center appears on the group’s leak site. The reported date associated with that appearance is September 28, 2026. The number of people affected is unknown. The types of data the group claims to hold are not disclosed in the available record. Method of access, whether any files were copied, whether a ransom demand was made, and whether any deadline or sample material was posted are likewise undisclosed in the facts at hand.
A leak-site entry is a form of pressure and marketing used by extortion crews. It is not the same as a confirmed inventory of stolen records, a regulator notice, or a company disclosure. Readers should treat every specific about this case as coming from the claimant unless and until it is corroborated elsewhere. As of writing, Kellys Home Center has not publicly confirmed the claim.
Who is Pear?
Pear is known publicly as a ransomware and extortion-style actor that, like other groups in this category, typically seeks access to an organization’s systems, encrypts or threatens data, and uses dedicated leak sites to name alleged victims and pressure payment. Public reporting on such groups generally describes double-extortion patterns: encryption paired with a threat to publish or sell claimed data if demands are not met. Tactics often associated with this ecosystem include phishing, exploitation of remote access, and use of affiliate or partner models, though the exact path—if any—in any single named case is not established by a listing alone.
For this article, only the group’s claim that Kellys Home Center is listed matters as a fact about the listing. No additional statements by Pear about file counts, sample contents, or internal systems at this company are provided in the record, and none should be invented. The group claims a listing; that claim remains unverified by the company in public sources referenced here.
About Kellys Home Center
Kellys Home Center is described as a business that specializes in selling high-quality home appliances, mattresses, and furniture. Retailers in this sector commonly operate showrooms or e-commerce channels, take orders, schedule deliveries and installations, process payments, and maintain customer service records. They may also hold supplier contacts, employee payroll and HR files, and marketing lists.
A claimed incident involving a home-center retailer is consequential because the customer base often includes households who share delivery addresses, phone numbers, financing or warranty details, and purchase histories. Even when a breach is unconfirmed, the sector’s normal data footprint explains why people pay attention to leak-site names: the same categories of information that make retail operations work are the categories criminals misuse if they ever obtain them. That is a statement about sector norms, not a finding that any particular dataset from Kellys Home Center was taken.
The information in question
The available facts state that data types named as exposed are not disclosed. The listing does not, in the record provided, supply a verified inventory. It would be improper to assert that specific fields—names, cards, Social Security numbers, or otherwise—were stolen.
If files were taken from a firm in this sector, organizations of this kind typically hold some mix of customer contact details, delivery and order information, payment or financing references (often tokenized or handled via processors), warranty and service records, employee information, and vendor data. Those are conditional, typical holdings—not a confirmed description of this case. Exact contents remain unconfirmed. People affected, if any, are unknown.
Why it matters
Leak-site listings matter because they can be a precursor to publication, sale, or targeted scams that reference a real business name people trust. They also matter because they create uncertainty: customers cannot know from the listing alone whether their row in a database is involved, while the named organization faces reputational and operational pressure regardless of what is later proven.
For individuals, real-world risk—if data were involved—usually looks like convincing phishing that cites a recent appliance or furniture purchase, password-reset attempts on email accounts tied to retail logins, or fraud that reuses addresses and phone numbers. For the organization, a public claim can disrupt trust and require investigation and customer communication even when the claim is incomplete or false. None of that establishes negligence or confirms theft; it describes why unverified extortion listings still affect ordinary people and named businesses.
What a leak-site listing does establish is narrow: a group has chosen to name a company in a public pressure channel. What it does not establish is scope, accuracy, method, or confirmation by the company or any authority.
If your data was involved
Because involvement is unconfirmed, treat the following as steps to take if you believe your information may be at risk—not as notice that your data is already out.
- Watch for unexpected messages that reference Kellys Home Center, deliveries, warranties, or unpaid invoices; verify through official channels you already trust, not links in the message.
- Change passwords on email and retail accounts you reuse, and turn on multi-factor authentication where available.
- Review bank and card statements for charges you do not recognize if you have paid the retailer directly.
- Be cautious with unsolicited calls or texts asking for payment details, one-time codes, or remote access to your devices.
- Consider placing fraud alerts or credit freezes with major bureaus if you later learn sensitive identity data was involved—only after reliable confirmation, not solely because of a leak-site name.
- You can run a free exposure scan of your email to check whether your information has surfaced in known breach data, which may help you prioritize further monitoring without treating Pear’s listing as proof about this company.
Public detail remains limited. The Pear listing of Kellys Home Center is a claim dated in reporting to September 28, 2026; people affected and data types are undisclosed; and Kellys Home Center has not publicly stated the incident as of writing. Stay alert to official notices from the company or regulators, and adjust your response if What's Publicly Reported emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Kovo Healthtech Listed by Pear Ransomware GroupNext Level Medical, Llc Listed by Pear Ransomware GroupIndroj Medical Group Inc. Listed by Pear Ransomware GroupWestside GI Listed by Pear Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Kellys Home Center Listed by Pear Ransomware Group →
Publicly posted by pear — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.