Three banks on a leak site are one banking group

Published

On 18 September the extortion crew Storm added five names to its leak site. Four were American financial firms, and three of those were Illinois community banks: First Secure Bank and Trust of Palos Hills, First Secure Community Bank of Sugar Grove, and an entry posted simply as "The State Bank".

They are not three banks. They are one.

None of this is confirmed. A leak-site listing is an accusation written by the people who profit from it, and IntelFusions has verified none of Storm's claims. What can be checked is who the named victims actually are, and there the public record is unambiguous.

One holding company, three charters

The Illinois Department of Financial and Professional Regulation's most recent public evaluation of First Secure Community Bank says it plainly. The Sugar Grove bank "is wholly owned by First Secure Bank Group, Inc., a three-bank holding company", and it is affiliated with First Secure Bank and Trust of Palos Hills, in Cook County, and First Secure State Bank of Wonder Lake, in McHenry County.

All three sit in the FDIC's institution directory as separately chartered, currently active banks: certificate 22536 in Palos Hills, 35223 in Sugar Grove and 22971 in Wonder Lake, holding roughly 396 million, 529 million and 306 million dollars in assets. That is about 1.2 billion dollars under one parent, modest nationally and substantial in northern Illinois.

A name the bank stopped using in 2024

The third listing is the giveaway. Storm posted it as "The State Bank", and the blurb attached to it advertises a "State Bank Group" made up of Wonder Lake, Johnsburg, Spring Grove, Lakemoor and Hebron offices. The FDIC's own change history for certificate 22971 records that the institution was renamed First Secure State Bank on 1 April 2024. Before that it traded as State Bank, and before 1990 as Wonder Lake State Bank.

The crew, in other words, appears to have lifted an about-page more than two years out of date and filed the result as a separate victim.

Counting charters instead of companies

This reaches past one bank group, because leak-site totals are the raw material for most public ransomware statistics. In our own tracking Storm has posted 61 claims across 13 separate days since 7 August, 44 of them American. Twelve are US financial firms, close to one in five of everything it has listed, against about five percent for the leak-site corpus as a whole since the start of August. Read at face value, Storm looks unusually fixed on finance. Take the duplicate charters out of the 18 September batch and the concentration is still real, just thinner than the raw count implies.

The crew is new. WatchGuard's tracker entry puts it as first seen in August 2026, still active, running both direct and double extortion, and records ten known victims, far short of the 61 our importer has logged. We covered its opening run against US clinics, banks and factories in August, when the sector mix was broader; the profile we keep on it is at Storm.

What a shared parent changes

For customers of the three banks there is nothing to act on yet beyond watching for a notification letter, since none of the institutions has published a statement and a listing is not a confirmed breach. For anyone defending a group built this way, the structural point stands alone. Multi-bank holding companies routinely consolidate core processing, email and helpdesk across their charters, so the blast radius of one intrusion is the group rather than the single bank. IntelFusions has no evidence of how Storm reached these institutions, and the listings offer none. What they do show is a crew treating one organization as three, and a defender reading that page should not repeat the error.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions