# Storm group claims Indiana hospital breach

Published: 2026-08-23 · Severity: elevated · Sectors: healthcare
Canonical: https://vorant.io/reports/0d08f149-962a-5afb-84d0-2f238ca1abe9/storm-group-claims-indiana-hospital-breach

> An emerging ransomware group calling itself Storm claims to have compromised Pinnacle Healthcare, an 18-bed Indiana hospital.

Ransomware.live has indexed a claim from an emerging extortion group tracked as "Storm," alleging compromise of Pinnacle Healthcare (Pinnacle Hospital), a physician-owned 18-bed acute care facility in Crown Point, Indiana with 201-500 employees. The claim was discovered on 2026-08-23 with an estimated attack date of 2026-08-21. As Storm is a newly observed group, the claim has not been independently verified and should be treated with caution.

The listing includes only the victim's public-facing DNS/mail infrastructure details (Microsoft 365 hosting, SPF records) and no technical indicators of compromise, malware samples, or exfiltrated data have been disclosed or verified in the source. No specific TTPs, exploited vulnerabilities, or malware families were identified in the reporting. Defenders in the healthcare sector, particularly smaller regional hospitals using Microsoft 365, should monitor for further disclosure from this actor and treat the claim as an early-stage, unconfirmed extortion listing pending corroboration.

## Mentioned in this report

- Threat actors: Storm

Source reporting: https://www.ransomware.live/id/UGlubmFjbGUgSG9zcGl0YWxAU3Rvcm0=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0d08f149-962a-5afb-84d0-2f238ca1abe9/storm-group-claims-indiana-hospital-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
