Skip to content

Storm

Ransomware Group1 claimLast activity:

Overview

Storm is an emerging operation tracked as a ransomware group through a public data-leak site. Ransomware.live first recorded Storm victim posts on Aug. 7, 2026, and monitored the Storm Blog as active in August. The generic name should not be assumed to identify a Microsoft numbered Storm tracking cluster or another actor that uses Storm in its name; no reviewed source links those identities.

Activity and targeting

Ransomware.live recorded 12 U.S. victim listings first discovered from Aug. 7 through Aug. 10, 2026. The monitored set included three financial-services organizations, three health-care organizations, two manufacturers and four organizations in other categories. The compressed publication window may reflect the launch or discovery of the leak site rather than the timing of the underlying activity.

The listings are actor claims, not 12 independently confirmed incidents, and the early sample is too small to establish a durable sector specialization. In the only claim linked to a published DysruptionHub incident, Storm listed Sawyer Savings Bank. The bank’s Aug. 6 update described a likely data security incident involving a vendor vulnerability but did not name Storm or confirm ransomware, encryption, a ransom demand or data theft.

Methods and operational characteristics

Public monitoring shows one Tor data-leak site branded Storm Blog. Naming organizations on a leak site is consistent with exposure-based pressure, but the reviewed evidence does not establish what Storm allegedly obtained, whether it contacted the listed organizations or whether it published victim data.

No reviewed source provides a Storm ransom note, negotiation transcript, malware sample, technical indicator or intrusion analysis. The public record does not establish initial access, persistence, lateral movement, privilege escalation, defense evasion, encryption, exfiltration, backup impact or destructive behavior. It also does not show whether Storm develops malware, buys access or works with affiliates.

What type of group is it?

Storm is best characterized provisionally as a ransomware-labeled leak-site operation. That classification reflects the monitored site and victim claims, not verified deployment of an encryptor or evidence of a ransomware-as-a-service program. The available record does not establish the operators, jurisdiction, organizational structure, financial model, state sponsorship or ideological motive. Incident-level responsibility requires corroboration beyond a Storm listing.

Incident claim

Sawyer Savings Bank Network and Branch Disruption

View public claim
Incident date: Source: ransomware.liveDiscovered:

Claim details

Ransomware.live recorded a Storm claim associated with Sawyer Savings Bank. The bank has not attributed the incident to Storm or confirmed ransomware, encryption, a ransom demand or data theft, and no independent authoritative source corroborates the claim.

Impacted organizations

Impacted locations

Sources