Ransomware Group Storm Hits: Johnson Investment Counsel
Summary
In the latest cybersecurity news, Johnson Investment Counsel — an organization based in US — has fallen victim to a ransomware attack conducted by the group Storm. This data breach, discovered on 2026-09-18T07:51:22.892150+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | Johnson Investment Counsel |
| Threat Group | Storm |
| Summary | Johnson Investment Counsel is an independent, employee-owned wealth management firm founded in 1965 and headquartered in Cincinnati, Ohio. The company provides comprehensive financial services to individuals, families, businesses, corporations, retirement plans, foundations, and nonprofit organizations. Its services include investment management, financial planning, retirement and cash-flow planning, estate planning, trust services, charitable planning, and business solutions. Johnson Investment Counsel operates as a fee-only Registered Investment Advisor and emphasizes fiduciary responsibility, long-term relationships, and customized financial strategies. As of June 30, 2026, the firm manages approximately $23 billion in assets and has 159 employees, serving clients across all 50 U.S. states. The company headquarters is located in 7755 Montgomery Road, Suite 180, Cincinnati, OH 45236, United States.51-200 Employees |
| Date of Breach | 2026-09-18T05:38:09+00:00 |
| Discovery Date | 2026-09-18T07:51:22.892150+00:00 |
| Region | US |
| Target Domain | johnsoninv.com |
| Business Sector | Financial Services |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- data breach monitoring — close the gap attackers exploit.
- phishing simulation — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
