# Storm ransomware claims Johnson Investment Counsel breach

Published: 2026-09-18 · Severity: high · Sectors: financial-services
Canonical: https://vorant.io/reports/fd53254d-5a55-5eb0-9d24-4175a78c4421/storm-ransomware-claims-johnson-investment-counsel-breach

> Ransomware group Storm listed Cincinnati wealth manager Johnson Investment Counsel as a victim on its leak site.

Ransomware.live has indexed a listing from a ransomware operation identified as "Storm" naming Johnson Investment Counsel, an employee-owned wealth management firm based in Cincinnati, Ohio, as a victim. The firm manages approximately $23 billion in assets and serves clients across all 50 U.S. states, making it a notable target within the financial-services sector. No technical details of the intrusion vector, exploited vulnerabilities, malware samples, or exfiltrated data have been disclosed in this listing.

The entry is sourced from a ransomware leak-site tracking service and provides no indicators of compromise, TTP detail, or confirmation of data theft beyond the claim itself. Defenders in the financial services and wealth management space, particularly RIAs handling high-net-worth client data, should treat this as a signal to review third-party risk exposure to Johnson Investment Counsel if applicable, and to monitor for further disclosure or data leaks from the Storm group's leak site. Without additional technical reporting, this should be tracked as an unconfirmed claim pending further verification or victim statement.

## Mentioned in this report

- Threat actors: Storm
- Malware: STORM

Source reporting: https://www.ransomware.live/id/Sm9obnNvbiBJbnZlc3RtZW50IENvdW5zZWxAU3Rvcm0=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fd53254d-5a55-5eb0-9d24-4175a78c4421/storm-ransomware-claims-johnson-investment-counsel-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
