Step By Step Data Breach

Alleged

Ransomware claim involving Step By Step USA

Published: Oct 3, 2026 Storm
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Step By Step USA
Industry
Business Services
Threat Actor
Storm
Date of Incident
Oct 3, 2026

Executive Summary

Step By Step USA, a company operating in the United States within the business services and technology sectors, has been targeted by the Storm ransomware group. The incident came to light on October 3, 2026, when Storm listed the company on its leak site. SOCRadar’s CTI division observed severe exposure of stealer-log data, compromising Microsoft Entra and Office 365 credentials belonging to 16 employees. This event highlights the growing trend of ransomware groups targeting cloud-based identity services and the potential for significant data exposure. The broad timeframe of the credential compromise suggests a patient approach by the threat actors to acquire and stage access before initiating a potential ransomware attack. The Storm ransomware group has been actively operating for at least 60 days, focusing on mid-market organizations in the U.S. and Europe across various sectors including industrial services, professional services, and technology. Storm employs a double extortion strategy, involving both data encryption and exfiltration, followed by the threat of public data release. Their affiliates consistently leverage Microsoft Entra and Office 365 for lateral movement after gaining initial access. This consistent reliance on the Microsoft ecosystem indicates that Storm’s affiliates possess specialized expertise in compromising cloud identity solutions, rather than being generalist attackers. The targeting of Step By Step USA aligns with Storm’s typical pattern of attacking companies with a significant cloud presence and valuable employee identity data.

Technical Analysis

Sixteen distinct employee credential records were identified within stealer datasets, encompassing authentication for Microsoft Entra, smtp.office365[.]com, and the organization’s corporate web portal (stepbystepusa[.]com:2096). These credentials were harvested over a ten-month period, from December 2025 through September 30, 2026, just three days prior to Storm’s public listing of the victim. Notably, three specific employee identities appeared multiple times within the dataset, with some information masked according to responsible disclosure standards. This extensive exposure window of nearly a year provides ample opportunity for threat actors to monitor, acquire, and prepare for access before deploying any ransomware payload. The observed credential exposure affects three primary authentication surfaces: Microsoft Entra tenant authentication, Microsoft 365 email relay services (smtp.office365[.]com), and the organization’s primary web management portal. The exposure of credentials for smtp.office365[.]com carries an independent risk of Business Email Compromise (BEC) that is not directly mitigated by addressing the ransomware event alone. The fact that stealer logs continued to be harvested up to September 30, 2026, suggests that compromised credentials may have been fed into the attack pipeline within the final 72 hours before the Storm group’s public announcement. Step By Step USA is advised to immediately force-rotate all 16 identified affected employee credentials. Furthermore, a thorough audit of Microsoft Entra sign-in logs dating back to December 2025 is crucial to identify and investigate any unauthorized sessions. Pulling Exchange email flow telemetry is also recommended to detect any potential interception of communications. Implementing Conditional Access policies, including Multi-Factor Authentication (MFA) and device compliance requirements for all cloud authentication, is essential to close the most direct re-entry paths for attackers. A comprehensive review of Microsoft Defender for Identity telemetry covering the entire exposure window is necessary before concluding that the scope of the compromise is contained.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.