A group tracked under the name Storm surfaced on our radar on August 6, 2026 and has claimed 12 victims in the four days since, all within the current 30-day window, indicating a fast, high-tempo entry rather than a slow build. The victim list spans a mix of manufacturing, metals, insurance, banking, security services, and healthcare-adjacent radiology targets, suggesting opportunistic rather than sector-specific targeting at this stage. No sector or country breakdowns are available from the tracker, and no ATT&CK techniques have been catalogued for this group yet, leaving its intrusion and encryption methods unconfirmed. No group self-description is on file, so any claims of scale or capability would come solely from the actor itself and cannot be verified. Given the compressed timeline of first appearance to a dozen claims, Storm warrants continued observation as a newly active, broadly targeting operation rather than a defined, sector-focused threat.