Ransomware victim disclosure
← All victimsMartin Lawrence Galleries
Claimed by Pear · listed 2 hours ago
Status timeline
- ListedSep 24, 2026
- Data leakeddate unknown
At a glance
- Group
- Pear
- Status
- Data leaked
- Country
- United States
- Sector
- Retail & E-Commerce
- Listed on leak site
- Sep 24, 2026
About the victim
AI dossier — public-source company profileMartin Lawrence Galleries is an art retail business operating multiple physical locations across the United States (including Costa Mesa, Dallas, Lahaina, La Jolla, Maui, New Orleans, New York, San Francisco, and Schaumburg) and offering virtual appointments. They sell artwork and provide consultation services to clients.
- Industry
- Art Galleries & Retail
Attack summary
Severity: high — Confirmed exfiltration of sensitive business data including customer PII, financial records, payment details, and operational correspondence from a multi-location retail business. No proof files are advertised in the truncated leak post, but the breadth of data claimed (financials, customer records, payment details) constitutes significant business and customer data exposure.The pear group claims to have exfiltrated financial records, HR data, vendor and partner information, customer and client records, auction details, payment information, VIP guest data, and email correspondence from Martin Lawrence Galleries.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- HR data
- Vendor and partner information
- Customer and client records
- Auction details
- Payment information
- VIP guest data
- Email correspondence
What the group claims
Premier gallery of fine art in America
The leak post
captured from the group's site| | | | | | Financials, HR, Partners’ & Vendors’ Data, Customers’ & Clients’ Private Records, Auctions and Payment Details, VIP Guests’ Data, Mailboxes & Email Correspondence, etc. | | --- | | | | | |
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

