Ransomware Group Storm Hits: First Secure Bank Group
Summary
In the latest cybersecurity news, First Secure Bank Group — an organization based in US — has fallen victim to a ransomware attack conducted by the group Storm. This data breach, discovered on 2026-09-27T17:53:23.053212+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | First Secure Bank Group |
| Threat Group | Storm |
| Summary | First Secure Bank Group is a U.S.-based financial services organization focused on providing community-oriented banking solutions to individuals, families, and businesses. The group operates through affiliated banking institutions, including First Secure Bank and The State Bank Group. Its services include personal and business checking and savings accounts, commercial and consumer lending, mortgages, online banking, treasury services, and other financial products. First Secure Bank Group emphasizes personalized customer service, long-term relationships, and supporting the financial growth of the communities it serves. Through its network of banking institutions, the group provides accessible financial solutions while maintaining a strong focus on local businesses, community development, and responsible banking practices. The company headquarters is located in 2175 Oneida St, Joliet, IL 60435, USA. 51-200 Employees |
| Date of Breach | 2026-09-27T05:26:29+00:00 |
| Discovery Date | 2026-09-27T17:53:23.053212+00:00 |
| Region | US |
| Business Sector | Financial Services |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- realistic phishing tests — close the gap attackers exploit.
- train staff to spot attacks — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
