Storm — Ransomware Profile
Storm is an extortion operation that WatchGuard classifies as a data broker and ransomware-as-a-service outfit, first seen in August 2026. WatchGuard records 10 known victims and reports direct extortion and double extortion. The group runs a single Tor leak site and publishes a Tox identifier as its victim contact channel.IntelFusions coverage (6)
- New crew Storm goes after US clinics, banks and factories 2026-08-25 · Ransomware
- Russia's spies phish by asking you to link your WhatsApp 2026-08-20 · Nation-State
- Russian hackers hijack hotel Wi-Fi to bug travelers 2026-08-01 · Nation-State
- Phishing now starts most intrusions as attackers beat MFA 2026-07-29 · Cyber Incidents
- The Gentlemen ransomware lists Colombia's Ecopetrol and a US Navy command 2026-07-19 · Ransomware
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16 · Ransomware
Recent claimed victims
- City of Mitchell 2026-08-24
- Sharp Motor Group 2026-08-24
- AutoDie 2026-08-23
- Proveli 2026-08-23
- Pinnacle Hospital 2026-08-23
- Schardein Mechanical 2026-08-23
- Ruggles Sign Company 2026-08-23
- Phoenix Group of Companies 2026-08-23
- The Cecilian Bank 2026-08-23
- American Contractors Insurance Group 2026-08-19
- WindRose Health Network 2026-08-18
- Ramsey Bros 2026-08-18
- Valor Defense Solutions, Inc 2026-08-18
- Standard Tool & Die 2026-08-18
- Westco Motors Cairns 2026-08-18
- Penfold 2026-08-18
- Canadian Mental Health Association 2026-08-14
- Tapper Cuddy LLP 2026-08-14
- 3-point Australia 2026-08-14
- Southern Metals Company 2026-08-14
- Rood & Riddle Equine Hospital 2026-08-14
- Integra Castings 2026-08-14
- Hinman Straub 2026-08-14
- Southern Metals 2026-08-10
- TRP International 2026-08-10
Vendor research
- Storm Ransomware WatchGuard Technologies