Quick Summary
AllegedExecutive Summary
Storm ransomware has claimed Lowerys, a Canadian retail and e-commerce company, as a victim, with the listing appearing on the threat actor’s leak site on September 9, 2026. This incident was identified via SOCRadar’s Dark Web Monitoring service. Lowerys operates through both commercial and online channels, making it a potential target for ransomware operations due to the sensitive customer data and transaction information it handles. In the preceding 60 days, Storm has targeted 52 other organizations, primarily within the Manufacturing, Healthcare, and Financial Services sectors across the United States, Canada, and Australia. The group’s recent activity indicates a broad targeting strategy. Lowerys’ inclusion aligns with Storm’s pattern of victimizing Canadian businesses, as evidenced by previous claims against Westco Motors Cairns, Melitron, Flexmaster, and Petrocare Construction.
Technical Analysis
SOCRadar’s stealer-log telemetry revealed a significant credential exposure associated with lowerys[.]com. The analysis identified a single corporate username present across four critical endpoints: Microsoft Entra ID, a WatchGuard network security appliance, cloud.lowerys[.]com, and an Autotask IT service management platform. This broad exposure across identity management, network perimeter access, and IT service management platforms is a significant concern. The captured credentials had a freshness range from November 2025 to August 2026, indicating at least nine months of unrotated access prior to the leak-site listing. This duration suggests a prolonged period of potential vulnerability. The breakdown of the exposed credentials includes five employee accounts on organizational systems, one linked to a customer or third-party user on organizational systems, and two corporate credentials on third-party services. This combination of exposed credentials, particularly on a network perimeter appliance and an IT management platform, is consistent with the typical tactics employed by Storm and similar ransomware groups to escalate from initial access to a full network compromise. While this telemetry does not definitively confirm that these specific credentials were used in the intrusion leading to the Storm listing, the severity of the exposure warrants immediate action. Organizations should prioritize the rotation of all identified credentials and conduct thorough audits of the affected endpoints to detect and mitigate any potential compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.