Quick Summary
AllegedExecutive Summary
Storm ransomware actors posted Star Aviation, Inc to their dark web leak portal on September 3, 2026. Star Aviation, Inc is a U.S.-based company providing aviation services and ground support, operating under the domain star-aviation[.]com. This listing was identified by SOCRadar Dark Web Monitoring. The company has not yet confirmed the claim. Aviation ground services companies often handle sensitive client data, such as airline contracts and passenger manifests, which can increase the leverage for extortion beyond the disruption of operations alone. In the 60 days preceding this listing, Storm claimed 41 victims. The group’s victim geography is dominated by the United States, followed by Australia and Canada. Key targeted sectors include manufacturing, healthcare, financial services, and transportation. Within the transportation sector, Storm has previously targeted entities like Sharp Motor Group in Australia. The ransomware group appears to lack a highly specialized vertical focus, instead targeting mid-market organizations across North America and Australia based on opportunity.
Technical Analysis
Aviation ground services companies typically utilize remote-access portals for dispatch and scheduling, and may expose RDP or VPN endpoints, alongside collaborative tools like Microsoft 365. Storm’s operational methodology commonly involves acquiring infostealer-sourced credentials from underground marketplaces, validating them, and then using them for authentication before deploying ransomware. SOCRadar’s stealer-log telemetry did not reveal any credentials associated with star-aviation[.]com within the queried dataset. It is important to note that the absence of stealer-log records for star-aviation[.]com does not definitively prove the company is unaffected. The query covered only a paginated sample, and credentials may exist under alternate corporate domains or staff personal email aliases. Furthermore, records might exist in feeds not included in the queried dataset, or credentials may have been used and rotated prior to indexing. The listing is consistent with Storm’s pattern of opportunistic targeting of mid-market U.S. companies. While the stealer-log data did not yield direct correlation, the risk to Star Aviation, Inc remains. The absence of evidence in this specific telemetry does not rule out a compromise. Continued dark web and stealer-log monitoring, along with proactive credential hygiene checks and password rotation, are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.