Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Storm Ransomware Group Claims Saskatchewan Petroleum Contractor

What Happened

The Storm ransomware group added Petrocare Construction, a contractor headquartered in Saskatoon, Saskatchewan, to its extortion leak site on September 3. The posted message tells the company to make contact “via the channels provided” or face publication of a full data leak. Petrocare builds commercial, industrial, wholesale, and retail petroleum facilities across Western Canada and employs between 51 and 200 people. Petrocare has issued no public statement confirming the intrusion, and the exact volume or category of stolen data remains undisclosed. Details are available from DeXpose.

Why This Matters for Canadian Organizations

Petrocare sits inside the petroleum and energy construction supply chain, a sector the Canadian Centre for Cyber Security flags repeatedly in its threat outlooks as an attractive ransomware target because outages ripple into fuel storage, distribution, and industrial clients downstream. Western Canada carries a dense concentration of mid-sized energy and construction firms sharing vendors, subcontractors, and project data with larger operators, so a single compromised contractor exposes information belonging well beyond its own payroll. If names, financial records, or other personal data surface in a published leak, notification duties under provincial privacy law and PIPEDA follow regardless of company size. Ransomware operators increasingly target mid-market firms precisely because they carry valuable data with fewer resources dedicated to detection and response than larger enterprises.

What to Do

Security teams at construction, energy, and industrial contractors should confirm offline, immutable backups exist and are tested for fast restoration, since ransomware groups increasingly threaten publication rather than relying on encryption alone. Review third-party and subcontractor access to shared project systems, since supply-chain partners frequently inherit exposure from a compromised prime contractor. Enforce multi-factor authentication across remote access and email, monitor for company-domain credentials appearing in dark web markets, and put an incident response plan naming legal counsel and a ransomware negotiation advisor in place before an attack happens rather than during one. Ongoing coverage is available from DeXpose.

Enjoy this article? Don’t forget to share.