Quick Summary
AllegedExecutive Summary
Storer Transportation and Storer Coachways, transportation companies based in the United States, have been listed as victims on the Dark Project ransomware group’s dark web portal, published on August 5, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The businesses operate in passenger transportation, a sector where scheduling and dispatch systems make downtime immediately visible to customers. Two related entities appear under a single portal entry, a pattern seen elsewhere in this batch. In the 60 days prior to this listing, Dark Project has claimed 17 other victims across its leak portal. The group has shown a strong targeting pattern in the manufacturing, healthcare, and transportation sectors. Geographically, its victims are concentrated in the United States, the United Kingdom, and the Philippines. Other recent Dark Project listings that overlap with Storer’s profile — US transportation organisations — include Thermo King, TSC Logistics, Mile Bluff Medical Center, and Reid Electric Service, Inc. Transportation is the group’s third vertical by volume in this window, and Storer sits within the US core that dominates the rest of the portal.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records for storerbus.com in the queried slice. A null result is not the same as a clean bill of health: the query covers a paginated sample rather than the complete corpus, alternate or subsidiary domains fall outside the lookup, and credentials harvested under personal email aliases would not surface against the corporate domain at all. That caveat has particular force here, since the listing names two legal entities and only one domain was available to query. For ransomware groups such as Dark Project, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. The absence of evidence in this query does not rule that scenario out — credentials may have surfaced in feeds outside this dataset, been used and rotated before indexing, or been harvested under personal email aliases. CTI teams should treat continued monitoring and proactive credential-hygiene checks as the appropriate response rather than reading a null query as exoneration.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.