CiberLATAMbywhalemate

Sears Mexico Appears on Space Bears List

Sears (Grupo Sanborns) was listed as a suspected Space Bears victim on a leak site and in aggregators, with no official confirmation.

Whalemate Labs · AI-assisted researchAug 16, 20262 min read

Sears (Grupo Sanborns) was registered by ransomware.live as a victim attributed to Space Bears and, in parallel, HookPhish and GalaxyWarden echoed the alert for Mexico, with sears.com.mx and the August 15, 2026 date. No public confirmation from the company or a Mexican authority appears in the available material.

Sears (Grupo Sanborns) appeared on a list attributed to the Space Bears group and was then echoed by several threat intelligence aggregators, although the alleged intrusion remains unconfirmed.

What the records show

ransomware.live listed "SEARS (Grupo Sanborns)" as a victim attributed to Space Bears and marked it as discovered on August 15, 2026, at 15:30 UTC. At the same time, HookPhish added the case to its alert dashboard as "Ransomware Group spacebears Hits: SEARS (Grupo Sanborns)," with the sears.com.mx domain, the August 15, 2026 date, and Mexico as the country, framed as a ransomware alert based on the group's listing.

HookPhish also reused that same alert block in other entries, always with the same domain, date, and country data. That repetition suggests the site is treating the Sears Mexico case as a signal derived from the Space Bears leak, but its posts did not add technical proof or official confirmation from the company or from authorities.

What GalaxyWarden said

GalaxyWarden reported that "SEARS (Grupo Sanborns)" was listed by the Space Bears group and clarified that this is a claim made by the group itself, not independently verified. In an expanded version of the report published for users in Latin America, the outlet repeated that Space Bears says it obtained customer records that include at least one password field.

That same update says the incident remains marked as "Affected: Unconfirmed" and that the organization has not confirmed the alleged intrusion. The report also includes password hygiene recommendations, consistent with the data the group claims to have taken, but it does not provide new evidence of the claimed access.

Based on the available material, Sears Mexico is currently listed as a presumed victim on a leak site and in an intelligence aggregator, but there is no public independent validation from the company or a Mexican authority.

Sources

View all