Storm gang lists orthopedic implant contractor on leak site

Storm's newest healthcare-sector claim targets SITES Medical, a contract manufacturer building implants for orthopedic, spine, and dental device firms.

MedRisk Staff
By
2 Min Read

The Storm ransomware group, which has spent the past month claiming healthcare targets, added an orthopedic implant contract manufacturer to its leak site on September 3. Threat trackers logged the posting roughly two days after the group said it broke into the company’s systems.

SITES Medical builds implants and related technology for other device makers, handling research and development, regulatory filings, and contract production for the orthopedic, spine, and dental markets. Its flagship offering, OsteoSync Ti, is a titanium surface treatment integrated into client product lines. The company has not confirmed the intrusion, and the group’s statements remain unverified, with ransomware.live cautioning that Storm is a newly tracked operation.

Storm’s recent claims against Liberty Healthcare, OVP Health, and an Indiana hospice show a pattern of targeting smaller care-adjacent businesses that often lack mature incident response programs. For hospitals and device firms, the episode underscores how implant supply chains concentrate proprietary design data and patient-adjacent information in a handful of manufacturing partners.

Organizations that work with SITES Medical or comparable contract manufacturers should ask whether vendor notifications have been issued and confirm that business associate agreements spell out breach reporting timelines. Defenders should also watch for double-extortion tactics, where groups publish small data samples to pressure victims into paying.

Share This Article