Ransomware group Storm hits GSAC Auto Financing
GSAC Auto Financing — a financial services target operating in US has been listed by the Storm ransomware group on 2026-09-02. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | GSAC Auto Financing |
|---|---|
| Threat Group | Storm |
| Summary | GSAC Auto Financing specializes in providing auto loans for individuals with challenged credit. They offer assistance in rebuilding credit while helping clients find suitable vehicles through their network of dealers. The company emphasizes that bad credit does not have to be a barrier to obtaining a car. GSAC is committed to accurately reporting payment histories to credit bureaus to aid in credit repair. The company headquarters is located in 1645 Ogden Avenue, Downers Grove, IL 60515, United States. 11-50 Employees |
| Date of Breach | 2026-09-02 |
| Discovery Date | 2026-09-03 |
| Region | US |
| Target Domain | — |
| Business Sector | Financial Services |
| Severity | MEDIUM |
Claim by Storm
GSAC Auto Financing specializes in providing auto loans for individuals with challenged credit. They offer assistance in rebuilding credit while helping clients find suitable vehicles through their network of dealers. The company emphasizes that bad credit does not have to be a barrier to obtaining a car. GSAC is committed to accurately reporting payment histories to credit bureaus to aid in credit repair. The company headquarters is located in 1645 Ogden Avenue, Downers Grove, IL 60515, United States. 11-50 Employees
Posted by the Storm threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Leak post (onion / Tor)
http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion/company/6a9843bb4cc2b2e7e76b5a96
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

