Incident response · Storm data extortion
Listed by the Storm group? In Australia, the way in has been your IT provider.
Storm's leak site went live in August 2026, and within six weeks it had listed seven Australian businesses: car dealers, a farm machinery dealer, a machinery management firm, a project consultancy. Every one that has spoken publicly says the same thing. Their own network was not breached. An external IT or software provider was, and the data was taken from there. Samples have included passports, licences and payroll files.
Recognise it
How to confirm it is Storm.
Keep the listing screenshots, any sample files and your provider's incident notice. Then ask one question before anything else: which external provider had access to this data, and what remote-management tool do they run?
- File extension
- Often none. The Australian victims describe data taken from a provider, not locked systems. If your files have been renamed .encrypted and a note called !!!README_FIRST!!!.txt has appeared, that is the StormEncryptor payload some researchers link to this group
- The listing
- A leak-site post with a dozen or more sample documents and a countdown. Storm's deadlines run from about two weeks to two months, unusually long for this kind of group. Contact is through Tor or Tox
- First seen
- The first victim was posted on 3 August 2026. The site recruits affiliates and rules out targets in the former Soviet states. A link to Storm-1175, a former Medusa affiliate tracked by Microsoft, is suggested by the timing and method but has not been confirmed
- Typical entry
- Managed service provider tooling. The N-able N-central authentication bypass, CVE-2026-18577, was exploited from 1 August 2026 and was the subject of an ACSC alert on 19 August. From there, remote-control sessions reach every endpoint the provider manages
Behaviour
What Storm does to your systems.
The provider is the way in
One compromised remote-management platform reaches every client on it. That is why the Australian victims are unrelated businesses in different states with the same story, and why the first question is which provider had access to your data.
Tunnels and look-alike services
Reported tradecraft includes a Cloudflare tunnel for persistence, sometimes renamed svchost.exe and hidden in a user's Documents folder, new accounts named after backup software, administrator password resets and antivirus switched off.
Fast once inside
The linked operator has moved from initial access to impact within a few days, and as quickly as one. There is little time between the provider being compromised and client data leaving.
Long countdowns
Listings carry genuine documents and a publication date weeks away. The gap lets pressure build from the outside, and Storm never states how much it took.
May or may not encrypt
StormEncryptor appends .encrypted, drops !!!README_FIRST!!!.txt in every folder and gives three days to make contact. No Australian victim has confirmed encryption so far, and no public decryptor exists for it.
Australia is a focus
Of roughly fifty victims worldwide by early September 2026, six or seven were Australian, behind only the United States and Canada. Dealerships and regional businesses that rely on an outsourced IT provider are the common thread.
The honest answer
Is there anything to recover?
In the Australian cases so far, no. Nothing was locked, so there is no decryptor to look for and no partial recovery to run. The work is scoping and containment: which provider was compromised, what tool they run, what data of yours sat on their systems or was reachable through their access, and which customers and staff are in it.
If the StormEncryptor payload was run inside your network, treat it like any new strain. There is no public decryptor, and because the encryptor only appeared in August 2026 nobody can yet say whether it leaves large files partially intact the way older families do. Keep every encrypted file and every note in place; a sample tells us within hours whether a recovery is worth attempting.
Keep the listing, the sample files and your provider's incident notice exactly as received, and get your own copies of the provider's logs while they still exist. If files are encrypted, do not rebuild anything before an assessment.
Common questions
Storm, in plain terms.
Mid-incident and need a straight answer? Call 1300 004 766. A person answers, 24 hours a day.
Our IT provider says they were the ones breached. Is the incident still ours?
Yes. Under the Notifiable Data Breaches scheme the obligation follows the personal information, and if the data is about your customers and staff you are responsible for assessing and notifying, whoever held it. Your provider has obligations too, and you will need their logs and their account of what happened, but you cannot delegate the decision or the clock.
Is Storm the same as StormEncryptor and Storm-1175?
Probably connected. It has not been proven. StormEncryptor was first seen on 2 August 2026, deployed by a former Medusa affiliate that Microsoft tracks as Storm-1175 through the N-central vulnerability. The Storm leak site posted its first victim a day later and the Australian victims fit the provider-compromise pattern exactly. Only secondary sources make the link explicit. It changes little in practice: the response is the same either way.
Does Storm encrypt files?
Not in any Australian case that has been made public. Victims describe data taken through a provider while their own systems kept running. If the linked encryptor is used, files are renamed .encrypted and a note named !!!README_FIRST!!!.txt appears with a three-day deadline. There is no public decryptor for it.
Why are the deadlines so long?
Storm's countdowns run from around two weeks to two months, where most groups give days. A long window lets the listing do the work, as customers find it and journalists write it up. Do not read the distant date as breathing room. The data has already left, and the notification obligations run from when you become aware, not from the countdown.
What should we ask our IT provider today?
Whether they run N-able N-central and which version, when it was patched to the August 2026 hotfix level, whether they have found a Cloudflare tunnel service or unexpected remote-control sessions, which of their accounts touched your systems, and for a copy of their logs. If they cannot answer in a day, treat their access to your environment as compromised and suspend it.
What should we do in the first hour?
Preserve the listing and samples, suspend the provider's remote access, reset the credentials that access used and enforce multi-factor authentication on everything reachable from outside, export your own gateway and firewall logs, and start a timeline. If files are encrypted, isolate the machines and leave them powered on. Do not reply to the group. Our First-Response Guide covers this on one page, and 1300 004 766 is answered around the clock.
Not Storm?
The extension on your files names the strain.
If the note or extension does not match what is on this page, one of these may fit. If none of them do, call anyway: the strain shapes the recovery, but identifying it is our job, not yours.
.akira
Akira →
Consistently among the most active strains in Australia. Partial encryption by design.
random extension
Qilin →
The most active operation of 2026. Every victim gets a unique file extension.
.inc
INC Ransom →
Subject of a 2026 ACSC joint advisory. Heavy targeting of Australian healthcare.
.LYNX
Lynx →
Built on the INC Ransom code. Encrypts 5, 15 or 25 percent of each file, so most of a large file survives.
.fog / .flocked
Fog →
Education-focused, enters via VPN credentials, attacks backups first.
.safepay
SafePay →
Encryption depth is a setting, and operators pick shallow. Enters on valid VPN and RDP credentials.
.dragonforce_encrypted
DragonForce →
Full, partial or header-only per file. Dedicated ESXi builds hit whole virtual estates.
no extension (theft only)
Kairos →
Never encrypts. Steals data and runs a seven-day clock. Nine Australian victims since 2024.
Or start from ransomware recovery, which covers the method whatever the strain turns out to be.
Right now
The first hours decide what can be saved.
Confirm which provider was hit, cut its remote access until it can show containment, preserve the logs, start the notification clock, and call before anyone replies. Australian incident response, answered by a real person.