September 13, 2026

#1 Storm Ransomware Group

storm_map

Why Storm Ransomware Should Be on the Radar of New Zealand and Australian Businesses

It may seem odd to have a group take the number one spot which has yet to have a known New Zealand victim but the Storm ransomware group should be taken notice of.

A ransomware group that has only been observed since August 2026 is already showing a pattern that should concern businesses across Australia and New Zealand.

Storm Ransomware has claimed 50 victims in a relatively short period, with seven of those organisations based in Australia. That means approximately 14% of the group’s publicly listed victims are Australian.

For an emerging ransomware operation, that is a significant concentration.

The concern becomes greater when the remaining 43 victims are considered. The countries represented among those victims broadly share political alliances and foreign-policy positions with Australia and New Zealand. While this does not prove that Storm deliberately targets countries based on political alignment, the pattern is notable enough that Australasian organisations should not dismiss the group as simply another low-volume ransomware operation.  Nor should New Zealand organisations with the ease the rest of the world tends to confuse us with Australia.

A rapidly emerging threat

Storm Ransomware is an active ransomware and extortion actor that has been linked to claims against organisations in Australia, Canada, Germany and the United States during August and September 2026.

Its victim selection is broad.

Targets reported to date include organisations operating in:

  • Manufacturing
  • Financial services
  • Healthcare
  • Government
  • Construction
  • Technology
  • Education
  • Agriculture
  • Professional services
  • Automotive and agricultural machinery

The repeated targeting of automotive and agricultural machinery organisations is particularly interesting, although there is currently insufficient evidence to conclude that these sectors represent a deliberate strategic focus.

Recent reporting has associated Storm activity with organisations including Technology Dynamics, Macquarrie, Agrimac and Melitron.

That distinction is important when assessing a relatively new threat actor. Ransomware leak sites are operated by criminals, and a victim appearing on a leak site does not, by itself, establish that the organisation was successfully compromised.

Why Australia stands out

The strongest reason for Australasian organisations to pay attention is simple: Storm appears to have found Australia early in its operational life.

Seven Australian organisations appearing among 50 publicly listed victims is a disproportionately high number for a group that has only recently emerged.

This is particularly relevant for New Zealand organisations.

There is no evidence at this stage that New Zealand is specifically being targeted by Storm. However, the group’s existing victim geography provides a reason for New Zealand organisations to watch its activity closely.

The majority of the group’s other victims are located in countries with broadly similar political and strategic relationships to Australia and New Zealand. That does not establish a targeting criterion, but it creates a pattern worth monitoring.

For defenders, the important question is therefore not whether Storm has already compromised a New Zealand organisation.

It is whether New Zealand organisations should be prepared for the possibility that they become part of the group’s victim set.

Our view is yes.

The group is not relying on a single industry

Another reason Storm deserves attention is its broad victim selection.

Rather than concentrating exclusively on one sector, the group’s claims span industrial, commercial and public-sector organisations.

This matters because organisations sometimes assess ransomware risk through the lens of whether they are an obvious target.

Storm’s activity suggests that being outside a traditionally high-value sector should not be considered meaningful protection.  Couple this with the fact the organisations Storm targets would be considered small to medium adds to New Zealand being a logical target for the group.

A manufacturer, agricultural machinery company, healthcare provider, financial organisation or government entity can all potentially represent an attractive target.

For Australian and New Zealand businesses, this means Storm should be considered a cross-sector threat, rather than one that can be excluded through industry-based threat modelling.

MITRE ATT&CK Techniques

The available reporting associates Storm’s activity with two MITRE ATT&CK techniques:

T1213 – Data from Information Repositories

T1486 – Data Encrypted for Impact

T1195 – Supply Chain Compromise

Statements from affected companies suggest internal systems were impacted at those organisations as opposed to a cloud platform.

There is currently no established specific CVE association or consistent initial-access mechanism that can reliably be attributed to Storm. Organisations should therefore be cautious about assuming that defending against one particular vulnerability or access method will adequately address the threat.

Around 40 days to pay

Storm reportedly gives victims approximately 40 days to pay.

That relatively long window is important.

A ransomware deadline is not simply a countdown to encryption. It provides the threat actor with an extended period during which they can maintain pressure on the victim, negotiate, threaten publication and potentially use stolen information as leverage.

The group’s dedicated leak-site presence also provides another mechanism for applying pressure.

Victims can be publicly named, with evidence presented to support the claim and encourage the affected organisation to engage with the attacker.

Interestingly, Storm does not appear to routinely publish the amount of data allegedly stolen as part of its victim listings. Instead, the group typically provides evidence associated with its claims as a proof of record.

That makes independent validation particularly important.

 

Why Storm belongs on the Australasian threat radar

Storm is still a relatively new ransomware operation, and there is much that remains unknown about the group.

Its initial-access methods are not clearly established. Its long-term victim profile has yet to emerge. Some of its victim claims remain unconfirmed.

But those uncertainties should not obscure the most important observation.

Storm has demonstrated a surprisingly high level of activity against Australian organisations during a very short period of time.

With seven Australian victims among 50 publicly listed victims, Australia represents approximately 14% of Storm’s observed victim set.

For New Zealand organisations, the combination of Australia’s proximity, the group’s broader victim geography and the cross-sector nature of its targeting makes Storm a threat worth monitoring now rather than waiting for a confirmed New Zealand victim.

Storm may ultimately prove to be a short-lived ransomware operation.

It may also develop into a significantly larger threat.

At this stage, the available evidence suggests that Australasian organisations should assume Storm is relevant to their threat landscape and ensure their ransomware detection and response capabilities are ready accordingly.

Current assessment

Threat level for New Zealand organisations: HIGH

Threat level for Australian organisations: HIGH

This assessment is driven primarily by the group’s early concentration of Australian victims, broad sector targeting, extortion model and rapid appearance across multiple Western-aligned countries.

It is not based on evidence of confirmed New Zealand victims or a proven political targeting strategy.

As with all ransomware intelligence derived from leak sites, victim claims should continue to be independently validated.