B & B Trading, one of the largest independent food wholesale distributors in New England, may have had internal files stolen and published by the pear ransomware group on June 10, 2026. The breach affects anyone whose personal or financial information passed through the company’s systems, including customers, suppliers, and employees whose data may now sit in the hands of extortionists.
Watch B & B Trading
Get alerted the next time B & B Trading files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about B & B Trading’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that pear actors gained access to B & B Trading’s network, exfiltrated internal files, and later listed the victim on their leak site. The data includes unspecified internal documents; exact volume and full contents remain unclear because ransomware groups often withhold complete samples until payment demands are met or ignored. No confirmed victim count has been released, and the company has not issued a public statement detailing what specific records were taken. The listing appeared on the group’s onion site, which is tracked by ransomware-monitoring services such as ransomware.live.
Why This Matters for You and Your Family
When a regional food distributor is hit, the ripple effects reach ordinary households. Order histories, delivery addresses, payment details, and employee records can contain the exact information needed to impersonate you or open accounts in your name. Internal files from a wholesale operation frequently include spreadsheets with names, addresses, phone numbers, and sometimes dates of birth or Social Security numbers for tax and compliance purposes. Once that information leaves the company’s control, you and your family lose the ability to contain where it travels online.
The Doxxing and Identity-Chain Implications
Stolen internal files rarely stay isolated. Attackers or subsequent buyers can combine them with other leaked datasets to build detailed profiles. A delivery address from a wholesale order can link to your home, your children’s names, and even gaming accounts registered with the same email or phone. These identity chains allow doxxers to escalate from simple data sales to targeted harassment, account takeovers, and physical threats. Credential leaks like this one routinely cascade into gaming platforms, where children’s accounts become entry points for further compromise because parents often reuse passwords across work, shopping, and family entertainment services.