Storm is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.
observed victims (by country)
United StatesAustraliaGermanyCanada
observed sectors
ManufacturingHealthcareOtherFinancial Services
41 victims · last active 27 Aug 2026
recent activity · our intel
source: ransomware.live1 refs → FAQ2
Which countries does the Storm ransomware group primarily target?+
Storm primarily targets victims in the United States, Canada, and Australia.
What defensive measures are recommended against the Storm group?+
Defenders should prioritize network segmentation, robust offline backup strategies, and monitoring of public extortion leak sites.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.