Ransomware Group Storm Hits: TheraCare
Summary
In the latest cybersecurity news, TheraCare — an organization based in US — has fallen victim to a ransomware attack conducted by the group Storm. This data breach, discovered on 2026-10-08T05:25:26.782110+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | TheraCare |
| Threat Group | Storm |
| Summary | TheraCare is a multi-service healthcare, rehabilitation, developmental, and educational organization founded in 1991 and headquartered in New York. The company provides clinical and educational services for children, families, and clients of different ages across New York, New Jersey, Connecticut, and Maryland. Its key services include early intervention, autism services, preschool and school-age programs, speech-language therapy, occupational therapy, physical therapy, special education, behavioral services, and school district staffing. TheraCare focuses on helping children reach their developmental and educational potential through individualized clinical and educational programs. The organization emphasizes quality assurance, continuous improvement, regulatory compliance, and measurable service outcomes. The company headquarters is located in 1133 Westchester Avenue, Suite N-230, White Plains, NY 10604, United States. 201-500 Employees |
| Date of Breach | 2026-10-06T05:31:31+00:00 |
| Discovery Date | 2026-10-08T05:25:26.782110+00:00 |
| Region | US |
| Business Sector | Healthcare |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- phishing simulation — close the gap attackers exploit.
- security awareness training — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
