Ransomware group fulcrumsec hits Stuf Storage
Stuf Storage — a consumer services target operating in US has been listed by the fulcrumsec ransomware group on 2026-05-08. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | Stuf Storage |
|---|---|
| Threat Group | fulcrumsec |
| Summary | [AI generated] Stuf Storage is a US-based company operating in the self-storage industry. It offers on-demand, flexible storage solutions primarily in urban markets, allowing customers to rent storage units without long-term commitments. The company focuses on converting underutilized urban spaces such as basements and parking structures into storage facilities. Stuf operates across several major US cities and targets city dwellers seeking convenient, accessible storage options. |
| Date of Breach | 2026-05-08 |
| Discovery Date | 2026-05-08 |
| Region | US |
| Target Domain | stufstorage.com |
| Business Sector | Consumer Services |
| Severity | MEDIUM |
Claim by fulcrumsec
[AI generated] Stuf Storage is a US-based company operating in the self-storage industry. It offers on-demand, flexible storage solutions primarily in urban markets, allowing customers to rent storage units without long-term commitments. The company focuses on converting underutilized urban spaces such as basements and parking structures into storage facilities. Stuf operates across several major US cities and targets city dwellers seeking convenient, accessible storage options.
Posted by the fulcrumsec threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Victim website
stufstorage.com
Leak post (onion / Tor)
http://4e3p3in2bl67hxchuwza7qvnpe7pyeloyztr5fnh257fxkovfhappjyd.onion/stuf/
Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

