New crew Storm goes after US clinics, banks and factories

A ransomware crew calling itself Storm posted its first victims on 7 August. Eighteen days later its leak site carries 35 entries, and the list reads like a directory of the businesses least able to absorb it: an 18-bed hospital in Crown Point, Indiana, three community banks, a South Dakota city government, a woman-owned defense contractor with a single office, and a run of tool-and-die shops and iron foundries.

None of it is confirmed. Every name on that page is an extortion claim the group published on its own leak site, and IntelFusions has verified none of them.

Fifth busiest, from a standing start

On our own incident tracker, Storm is the fifth most active extortion brand since 7 August, behind Qilin (96 listings), The Gentlemen (85), Cl0p (48) and Dire Wolf (38). It sits ahead of INC Ransom on 23, Akira on 12 and Play on 9, all of them crews with years of history behind them. Storm has posted on eight separate days in that window, in batches of two to seven, rather than dumping a backlog in one go. The cadence matters. A single large batch usually means an operation publishing old work, while a steady drip is a group that is still finding new victims.

Small firms, heavy on regulated data

27 of the 35 listings are American. The remainder are four Australian, three Canadian and one British. By sector the largest blocks are manufacturing (8), healthcare (7) and financial services (5), with two law firms, an insurance compliance business, a radiology practice and the Canadian Mental Health Association among the rest. The pattern is consistent rather than opportunistic: mid-market and smaller organizations, holding data that regulators care about, staffed by security teams of one or none. It is the same fragmentation we covered when 93 separate crews were counted active in a single quarter, arriving one new brand at a time.

Nobody has named the malware yet

WatchGuard's ransomware tracker classifies Storm as a data broker and ransomware-as-a-service operation running both direct and double extortion, first seen in August 2026, with one Tor leak site and a Tox address for negotiation. Its entry still records 10 known victims, all American, and says plainly that data will be added as it is discovered, so the gap against our 35 is tracker lag rather than a disagreement. Beyond the classification there is very little. No encryptor sample has been published, no initial access vector named, no CVE cited, no vendor cluster attribution offered. Anybody telling you how Storm gets in is guessing. One note on the name, because it collides badly: this is the group's own leak-site branding, and it is unrelated to Microsoft's Storm-numbered designations for unattributed activity clusters.

There is no patch, because there is nothing to patch

With no vulnerability and no tooling in public, there is no fix to apply and defensive work stays generic until somebody publishes analysis. WatchGuard records double extortion, which means restorable backups alone will not end a negotiation once data is already out the door. Organizations that match the victim profile, small US healthcare providers, community banks and manufacturers, are the ones worth pushing to the front of the queue this week for offline backup verification and outbound data monitoring. The group's leak site sits at yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd[.]onion, the one durable indicator published so far.

Storm's arc is the ordinary shape of this market now. A brand appears, posts hard for three weeks, and either builds enough reputation to get ransoms paid or disappears and returns under another name. What the 35 entries show is that reaching the top five takes no innovation whatsoever, only a steady supply of organizations too small to have anyone watching. The rest of that supply is visible in our running record of incident claims against United States organizations.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions