Quick Summary
AllegedExecutive Summary
Storm has claimed The Money Store, a United States-based residential mortgage lender, as a victim, listing the company on its dark web portal on September 21, 2026. SOCRadar’s Dark Web Monitoring service identified this listing. The Money Store’s operational focus on financial services aligns with Storm’s typical targeting patterns, as the ransomware group has claimed 63 other victims in the past 60 days, with the financial sector being its primary focus. Storm’s recent activity predominantly targets organizations in the United States, Canada, and Australia, with a strong emphasis on financial institutions. Recent US-based financial victims claimed by Storm include First Secure Bank and Trust, The State Bank, First Secure Community Bank, and Johnson Investment Counsel. The Money Store’s inclusion in this pattern further reinforces the group’s ongoing focus on the financial services industry.
Technical Analysis
Stealer-log telemetry identified 25 records associated with the domain themoneystore[.]com. These records comprise several types of credentials: 6 employee credentials found on organization-owned systems, including an Outlook subdomain for corporate email and an endpoint used for mortgage onboarding and password resets. Additionally, 14 external-user records were found on customer-facing portals, and 5 records had unclear attribution. The employee credentials related to the Outlook subdomain are of particular concern, as they provide potential access to sensitive internal communications, customer Personally Identifiable Information (PII), and operational workflows. The presence of credentials for an onboarding and password-reset endpoint indicates a potential provisioning vector that could be exploited for account takeover beyond simple credential theft. Immediate actions should include rotating all identified employee credentials, auditing Outlook access logs for suspicious activity, and reviewing the onboarding endpoint for any unusual provisioning events. Continued monitoring of the dark web and stealer logs is also recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.