Ransomware victim disclosure
← All victimsK & E Distributing
Claimed by Pear · listed 3 days ago
Status timeline
- ListedJun 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Pear
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- Jun 10, 2026
About the victim
AI dossier — public-source company profileK & E Distributing is a geothermal and HVAC equipment distributor operating in the Midwest for over 40 years. Based in Iowa and Missouri, they supply ClimateMaster, GeoStar, EcoForest, and LG HVAC products to residential and commercial customers across the region.
- Industry
- HVAC Distribution & Geothermal Energy Systems
- Address
- 1501 Walnut Street, Dallas Center, IA; 2376 State Road MM, New Bloomfield, MO 65063
Attack summary
Severity: high — Confirmed exfiltration of sensitive business and personal data including financial records, customer/vendor PII, payment details, and email correspondence. No proof files evident in truncated post, but disclosure status is 'data_published'.The pear group claims to have exfiltrated financial records, HR data, customer and vendor information with payment details, project drawings, email correspondence, QuickBooks accounting data, and database exports from K & E Distributing.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- HR data
- Customer personal data
- Vendor personal data
- Payment details
- Projects & drawings
- Email correspondence
- QuickBooks accounting data
- Database exports
Original description
AI-summarised, not from the leak postN/A
The leak post
captured from the group's site| | | | | | Financials, HR, Customers’ & Vendors’ Private Data, Payment Details, Projects & Drawings, Mailboxes & Email Correspondence, QuickBooks Data, Database & Exports, etc. | | --- | | | | | |
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

