Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Storm Ransomware Claims a Century-Old Thunder Bay MSP, Raising Downstream Client Risk

What Happened

The Storm ransomware group added Lowerys to its extortion leak site on September 7, naming the Thunder Bay, Ontario company as its latest victim. Lowerys has operated for 100 years, supplying office and janitorial products, wide-format printing, bottled water, and managed IT services to businesses across Thunder Bay and Fort Frances. Storm’s listing has not been independently confirmed, and Lowerys has issued no public statement on the scope of any intrusion or whether client data was accessed. Ransomware groups regularly overstate claims to pressure payment, so the exact volume and sensitivity of exposed data remain unverified. Coverage is available from RedPacket Security.

Why This Matters for Canadian Organizations

Lowerys sits in a category security teams tend to underweight: the local managed service provider handling IT support for other small and mid-sized businesses. An MSP compromise carries risk well beyond the company itself, since attackers who gain a foothold in an MSP’s network sometimes pivot into client environments through remote-management tools, shared credentials, or help-desk access. Thunder Bay and Fort Frances businesses relying on Lowerys for IT support have reason to ask direct questions about what systems and credentials the provider touches on their networks. Under PIPEDA, any organization experiencing a breach involving personal information faces notification obligations once a real risk of significant harm is identified, and this duty extends to third-party processors handling client data on an MSP’s behalf. Ontario’s growing base of regional MSPs serving small businesses in smaller markets remains an attractive target precisely because security staffing and monitoring budgets tend to be thinner than at larger managed providers.

What to Do

Organizations using a third-party MSP should confirm what access the provider holds, request evidence of multi-factor authentication on remote-management tools, and ask directly whether the vendor has faced a security incident. MSPs themselves should segment client environments from each other and from internal corporate systems, rotate credentials tied to remote-access tools immediately after any suspected compromise, and store client backups offline or in immutable storage so encryption or deletion cannot reach them. Security teams at small and mid-sized organizations should treat vendor risk assessments as an ongoing practice rather than a one-time onboarding step, particularly for regional IT providers serving several businesses from a shared infrastructure. Updates on the Lowerys claim are available from RedPacket Security.

Enjoy this article? Don’t forget to share.