stormous
ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)
Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.
- Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
- Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
- Double extortion: threatens data publication alongside or instead of encryption
- Posts free full data dumps to pressure victims after stalled or failed negotiations
- Targets small and mid-sized organizations perceived to have weaker defenses
- Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
- Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)
No public figure.
Leak-site victims221 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| BN: higuchi-inc Report Error & Data Leak Warning | · Jul 2, 2026 | www.higuchi-inc.co.jp/newsrelease/company/doc/unauthorized_access_incident.pdf // We have reviewed the report issued by HIGUCHI INC. To correct their mistake: the breach did not affect just one branch, but rather 3 different branches across various regions.Your data has not been leaked yet, as you are currently within an 8-day grace period. Before we publish any of your commercial or personal data, be aware that we possess 102 GB of Sage software backups, alongside numerous commercial documents.We await your reply to our messages. Follow the correct path to ensure nothing is leaked. We are waiting for you. |
| Notice | · Jul 2, 2026 | We will soon terminate our operations and services. All hosted data is scheduled for complete erasure within 60 days, before this blog goes offline permanently. |
| maglificioliliana.com UPDATE-FULL DATA DUMP FREE PART1 | · Jun 28, 2026 | Over +10GB GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more. |
| lorenzoni-store.com UPDATE-FULL DATA DUMP FREE PART1 | · Jun 28, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
| montechiaro-store.com UPDATE-FULL DATA DUMP FREE PART1 | · Jun 28, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
| impulso-store.com UPDATE-FULL DATA DUMP FREE PART1 | · Jun 28, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
| higuchi-inc.co.jp | · Jun 28, 2026 | (Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the .ptb file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations. |
| HIGUCHI USA, INC | · Jun 28, 2026 | (Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the .ptb file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations. |
| eogb.co.uk | · Jun 28, 2026 | Deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and commercial transactions.Access to internal legal documents, partnership agreements, and customer contracts (such as CBIF OSMO agreements).Exfiltration of operational spreadsheets, financial reports, and executive documents via corporate |
| eshacloudqa.com | · Jun 28, 2026 | We have breached ESHA Research / ESHA Cloud Services and compromised their core product development databases. The exfiltrated data includes highly confidential industry secrets and formulation data Complete intellectual property containing secret product designs, manufacturing blueprints, and recipes (SupplementFormula, PureFood, FoodGroup).Deep laboratory data, nutritional testing breakdowns, and allergen classification records (SupplementIngredient, Analysis, AllergenGroup, Sensitive registries containing client profiles, user metrics, and market consumer data (Consumer, Activity). |
| monoprix.tn | · Jun 28, 2026 | Data description: Pending update |
| Official Statement: Protecting palatineschool.org Infrastructure | · Jun 28, 2026 | During our routine network security audits, our team discovered critical structural vulnerabilities within Palatine School, which granted us full, unrestricted access to their central server (PALDC2020). We had the technical capacity to access every directory, including pupil databases ( StudentData NHS NO ) , Pupil Admin - Users -FocusIT) and staff records Personnel.We want to announce that we have locked down this operation and decided to leak absolutely nothing.This is an institution dedicated to children and special needs education. Unlike corporate thieves or ruthless threat actors, we operate with a strict code of ethics: we do not target children, schools, or healthcare facilities.Instead of destroying them, we have chosen to act as an uninvited security audit. We are using our platform to publicly invite the administration of Palatine School to contact us privately. We will provide them with the full technical details of the critical vulnerabilities we discovered and guide them on how to patch their system for free, ensuring they are protected from other ruthless cyber criminals. |
| Data Leak Update | · Jun 26, 2026 | ** Do ML IT and vspsolutions.com.au think they are smarter than us? They are reporting the links where the data was uploaded, and they are being disabled. Therefore, and officially, we are preparing a private server on the Tor network to dump all the data of these companies and the data of others. Which will be available to everyone 24/7 along with a clear view of the extracted data, employees |
| mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB | · Jun 24, 2026 | FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases. |
| jaggroup.com UPDATE-FULL DATA DUMP NEW LINK | · Jun 24, 2026 | Full database containing corporate emails (@jaggroup.com), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (zBackups.zip, wetransfer packages), SQL server connection data, and IM.mdb database files.Internal project management sheets (Jag Project.xlsx), user listings, purchasing, and sales import logs. |
| maglificioliliana.com | · Jun 24, 2026 | Over 400 GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more. |
| lorenzoni-store.com | · Jun 24, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
| montechiaro-store.com | · Jun 24, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
| impulso-store.com | · Jun 24, 2026 | Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/ |
| jaggroup.com UPDATE-FULL DATA DUMP | · Jun 22, 2026 | Full database containing corporate emails (@jaggroup.com), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (zBackups.zip, wetransfer packages), SQL server connection data, and IM.mdb database files.Internal project management sheets (Jag Project.xlsx), user listings, purchasing, and sales import logs. |
| mlit.com.my UPDATE-FULL DATA DUMP 10GB | · Jun 19, 2026 | FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases. |
| mlit.com.my | · Jun 12, 2026 | We have successfully breached the internal servers and network infrastructure of MLIT, gaining full unauthorized access to their active Microsoft Dynamics Management Reporter environment and local storage volumes.The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases. |
| katholiekamersfoort.nl UPDATE-FOR SALE | · Jun 9, 2026 | The church website |
| sa2000.com UPDATE-FULL DATA DUMP | · Jun 9, 2026 | 150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES ACHAT / FACTURES À PAYER / FACTURES MODIFIÉES - Banking Informations SA2000 - PAIEMENTS CLIENTS - CLIENTS / PO CLIENTS - FOURNISSEUR / TRANSPORTEURS - EMPLOYÉS / EMBAUCHE - ACTIONNAIRES - COURRIEL / DOCUMENTS COURRIELS.There is still an opportunity to communicate and resolve this situation. We are currently awaiting the company |
| SA2000.COM | · Jun 4, 2026 | 150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES ACHAT / FACTURES À PAYER / FACTURES MODIFIÉES - Banking Informations SA2000 - PAIEMENTS CLIENTS - CLIENTS / PO CLIENTS - FOURNISSEUR / TRANSPORTEURS - EMPLOYÉS / EMBAUCHE - ACTIONNAIRES - COURRIEL / DOCUMENTS COURRIELS.There is still an opportunity to communicate and resolve this situation. We are currently awaiting the company |
| katholiekamersfoort.nl | · Jun 2, 2026 | The church website |
| vspsolutions.com.au FULL DATA DUMP | · May 24, 2026 | +40G Full Financial Backups (Quickbooks & Reckon)-Email Archives & Staff Personal Folders-Customer/Client Databases (Installers & Integrators nationwide)-Shipment & Order Tracking for major brands like Hikvision & Axis. |
| www.kai.id (FF) | · May 17, 2026 | PT Kereta Api Indonesia is the national railway company in Indonesia, also known as Kereta Api. It is responsible for operating train services throughout the country. |
| Important Announcement | · May 17, 2026 | — |
| VPN Access Sale | · May 17, 2026 | — |
| FANASA.COM UPDATE-FULL DATA DUMP | · May 17, 2026 | — |
| arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMP | · May 17, 2026 | — |
| ttt.vn UPDATE-FULL DATA DUMP | · May 17, 2026 | — |
| cgcsa.co.za UPDATE-FULL DATA DUMP | · May 17, 2026 | — |
| ams-group.co.uk FULL DATA DUMP 33GB | · May 17, 2026 | — |
| vspsolutions.com.au SAMPLE-FREE 20GB | · May 17, 2026 | — |
| clarochile.cl | · Jan 22, 2026 | — |
| GOODMANMFG | · Dec 9, 2025 | — |
| futureal | · Dec 9, 2025 | — |
| bkcolombia | · Dec 9, 2025 | — |
| holidaypalace | · Dec 9, 2025 | — |
| ! | · Nov 10, 2025 | — |
| www.wilmar.co.id | · Nov 7, 2025 | — |
| www.danareksa.com | · Nov 7, 2025 | — |
| www.marjane.ma | · Nov 7, 2025 | — |
| French Government | · Oct 28, 2025 | — |
| acuity | · Oct 28, 2025 | — |
| enersolcr | · Oct 28, 2025 | — |
| regencytorviscas | · Oct 28, 2025 | — |
| regencycountryclub | · Oct 28, 2025 | — |
In the newsAll →
No articles mention this group yet.