TrueCore Behavioral Solutions Data Breach

Alleged

Storm Ransomware Claim Involving TrueCore Behavioral Solutions

Published: Sep 21, 2026 Storm
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
TrueCore Behavioral Solutions
Industry
Healthcare
Threat Actor
Storm
Date of Incident
Sep 21, 2026

Executive Summary

Storm listed TrueCore Behavioral Solutions on its dark web portal on September 21, 2026. SOCRadar’s Dark Web Monitoring identified this listing. TrueCore Behavioral Solutions provides behavioral health and residential treatment services. This subspecialty within healthcare is known for holding particularly sensitive patient data, including mental health records, which are subject to stringent regulatory protections. The nature of this data makes such organizations attractive targets for ransomware and extortion activities. In the preceding 60 days, Storm claimed 63 other victims. The ransomware group’s activity is heavily concentrated in Financial Services, Manufacturing, and Healthcare sectors, primarily targeting organizations in the United States, Canada, and Australia. Recent US healthcare victims listed by Storm include PANTHERx Rare, SITES Medical, Our Hospice of South Central Indiana, and Pinnacle Hospital. The inclusion of TrueCore Behavioral Solutions, a behavioral health provider, signifies a recent expansion in Storm’s targeting patterns, moving into a more specific subsector beyond its historically broader clinical services focus.

Technical Analysis

Stealer-log telemetry data revealed 25 records associated with the domain truecorebehavioral[.]com, covering a six-month period from March 2026 to September 2026. These records are categorized into two types: 16 employee credentials found on organization-owned systems and 9 corporate username records identified on third-party platforms. The identified key endpoints include the SmarterU-hosted LMS with a truecorebehavioral subdomain, a Zoom tenant, and Microsoft account recovery information, all linked by corporate usernames. This credential exposure suggests potential compromise of workstations or persistent active devices over an extended duration. The presence of Microsoft account recovery records is particularly critical, as it may indicate potential exposure of the organization’s Microsoft 365 tenant. This could grant an adversary access to sensitive resources such as emails, SharePoint files, and Teams communications. Additionally, the exposure of Zoom credentials introduces a secondary risk related to communication channels. The six-month window of data, from March to September 2026, points to a prolonged period of potential vulnerability. Given the identified credential exposure, it is recommended to rotate all affected accounts immediately. A thorough audit of Microsoft 365 sign-in logs for the March–September 2026 window is crucial to identify any unauthorized access. Furthermore, an assessment of the truecorebehavioral subdomain for the Learning Management System (LMS) should be conducted to detect any signs of unauthorized access or malicious activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.