Data breach
Plexsupply Inc
- Records
- 936,468
- Breach date
- 26 May 2026Estimated
- Added
- 22 June 2026
What was exposed
9 types of data · 3 put you at serious risk
- Email addresses936,468
- Names86,999
- Street addresses48,848
- Phone numbers44,331
- Dates of birth496
- Social security numbers391
- Driving licence numbers105
- Licence plates28
- Passport numbers1
About this breach
More than 936,000 records tied to Plexsupply Inc, a wholesale and industrial distribution company based in New Jersey, surfaced online after the ransomware group Pear claimed an attack on the company. Ransomware.live, a service that tracks ransomware group leak sites, listed Plexsupply on Pear's victim page on May 30, 2026, with an estimated attack date of May 26, 2026. Pear, which calls itself "Pure Extraction and Ransom," threatened to publish sensitive business data unless its demands were met, according to reporting by dexpose. The dark web monitoring service Breachsense, which indexed the incident on June 1, 2026, lists the associated leak at roughly 800GB.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
May 26, 2026: Ransomware.live estimates this as the date of the attack on Plexsupply Inc, based on Pear's own listing.
May 30, 2026: Pear publicly named Plexsupply Inc as a victim on its leak site; Ransomware.live recorded the listing at 07:54 UTC the same day.
June 1, 2026: Breachsense indexed the breach, reporting a claimed leak size of 800GB.
What Information Was Compromised?
Our analysis found the following data types in this breach: 936,468 email addresses, 86,999 names, 48,848 street addresses, 44,331 phone numbers, 496 dates of birth, 391 Social Security numbers, 105 driver's license numbers, and 28 vehicle plate numbers. Passport numbers also appear in the dataset, though the investigation team could not determine how many.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of names, addresses, phone numbers, and email addresses is enough for convincing phishing messages, scam calls, and fraudulent invoices aimed at business customers of a wholesale supplier. The 391 exposed Social Security numbers and 496 dates of birth carry the highest stakes, since those details can support identity theft, fraudulent loan applications, and tax-related fraud. Driver's license and vehicle plate information can be misused for identity verification schemes as well. Breachsense has also indexed a small number of credentials for plexsupply.net accounts, though it notes these logins may belong to staff or customers and are not necessarily connected to the ransomware attack. Anyone who reused a plexsupply.net password elsewhere should treat that password as compromised.
What Should You Do If You Were Affected?
If your Social Security number or date of birth was exposed, review your credit reports at annualcreditreport.com and consider placing a fraud alert or credit freeze with the three major bureaus.
Watch for phishing emails, fake invoices, and phone calls that reference Plexsupply or your ordering history, and verify any payment requests through a known contact.
Change your plexsupply.net password and any other account where you used the same one, and turn on multi-factor authentication where it is offered.
Monitor bank and tax accounts for unusual activity, and report suspected identity theft to the Federal Trade Commission at identitytheft.gov.
