HackerFeeds
All ransomware incidents
G

Ransomware group Storm hits GSAC

MEDIUM
·Not Found·US·2026-09-01

GSAC — a not found target operating in US has been listed by the Storm ransomware group on 2026-09-01. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationGSAC
Threat Group
Storm
SummaryGSAC Auto Financing specializes in providing auto loans for individuals with challenged credit. They offer assistance in rebuilding credit while helping clients find suitable vehicles through their network of dealers. The company emphasizes that bad credit does not have to be a barrier to obtaining a car. GSAC is committed to accurately reporting payment histories to credit bureaus to aid in credit repair. The company headquarters is located in 1645 Ogden Avenue, Downers Grove, IL 60515, United States. 11-50 Employees
Date of Breach2026-09-01
Discovery Date2026-09-03
RegionUS
Target Domain
Business SectorNot Found
Severity
MEDIUM

Claim by Storm

GSAC Auto Financing specializes in providing auto loans for individuals with challenged credit. They offer assistance in rebuilding credit while helping clients find suitable vehicles through their network of dealers. The company emphasizes that bad credit does not have to be a barrier to obtaining a car. GSAC is committed to accurately reporting payment histories to credit bureaus to aid in credit repair. The company headquarters is located in 1645 Ogden Avenue, Downers Grove, IL 60515, United States. 11-50 Employees

Posted by the Storm threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Leak post (onion / Tor)

tor

http://yqhecvqtdvq6p7duqcgw2qca77spbgakxcoibtx6zpvfshltsbbbhfqd.onion/company/6a9732bb4cc2b2e7e76b5a94

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.