Ransomware Group ‘Storm’ Claims Attack on Johnson Investment Counsel

A ransomware group operating under the name Storm has posted a claim on its dark web leak site stating that it obtained data from Johnson Investment Counsel, with the listing dated September 18, 2026. This is an allegation made by the criminal group itself, tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites, and it has not been independently verified by BreachLetter, by Johnson Investment Counsel, or by any regulatory body. At this stage, the claim should be treated as unconfirmed until further evidence emerges.

Details currently on record versus details still unconfirmed
  • Group behind the claim: Storm
  • Date the claim appeared on the group’s leak site: September 18, 2026
  • Target named in the posting: Johnson Investment Counsel, operating in the finance sector
  • The precise categories of data the group alleges to have accessed have not been disclosed in the posting reviewed, nor confirmed by any independent party
  • No public statement from Johnson Investment Counsel acknowledging or denying the claim has been located at this time
What clients and employees of a firm named in this kind of claim should consider doing
  • Update passwords tied to accounts held with the firm, particularly if credentials are reused elsewhere
  • Turn on two-factor authentication wherever it is offered for financial and investment-related accounts
  • Stay alert for phishing emails or phone calls that reference this incident, as such claims are often exploited by scammers seeking to impersonate legitimate outreach
  • Review recent account statements and login activity for anything unusual
  • Consider a service like a service like Aura or LifeLock for ongoing identity monitoring, since alleged data exposure incidents can lead to identity theft attempts well after the initial claim surfaces

BreachLetter will revisit and update this page should Johnson Investment Counsel issue a confirmation or denial, or if the matter is formally reported to a data protection or financial regulator.

Leave a Comment