ZeroHour

stormous

ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
21
All-time (tracked)
221since 2022-04-12
Last post
07-02 00:54UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.

Tactics & tooling
  • Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
  • Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
  • Double extortion: threatens data publication alongside or instead of encryption
  • Posts free full data dumps to pressure victims after stalled or failed negotiations
  • Targets small and mid-sized organizations perceived to have weaker defenses
  • Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
  • Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Targeted sectors
Logistics and transportationManufacturingConsumer goods and food and beverageRetail and e-commerceSoftware and IT servicesEducationEnergy
Notable public victims

Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
BN: higuchi-inc Report Error & Data Leak Warning⁠ · Jul 2, 2026www.higuchi-inc.co.jp/newsrelease/company/doc/unauthorized_access_incident.pdf // We have reviewed the report issued by HIGUCHI INC. To correct their mistake: the breach did not affect just one branch, but rather 3 different branches across various regions.Your data has not been leaked yet, as you are currently within an 8-day grace period. Before we publish any of your commercial or personal data, be aware that we possess 102 GB of Sage software backups, alongside numerous commercial documents.We await your reply to our messages. Follow the correct path to ensure nothing is leaked. We are waiting for you.
Notice · Jul 2, 2026We will soon terminate our operations and services. All hosted data is scheduled for complete erasure within 60 days, before this blog goes offline permanently.
maglificioliliana.com UPDATE-FULL DATA DUMP FREE PART1 · Jun 28, 2026Over +10GB GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more.
lorenzoni-store.com UPDATE-FULL DATA DUMP FREE PART1 · Jun 28, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
montechiaro-store.com UPDATE-FULL DATA DUMP FREE PART1 · Jun 28, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
impulso-store.com UPDATE-FULL DATA DUMP FREE PART1 · Jun 28, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
higuchi-inc.co.jp · Jun 28, 2026(Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the ⁠.ptb⁠ file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations.
HIGUCHI USA, INC · Jun 28, 2026(Dallas - HongKong - LosAngeles ) Comprehensive financial statements including Balance Sheets, Asset records, Liabilities, Capital, Accounts Receivable (A/R), and Accounts Payable (A/P) database backups from Sage 50 (formerly Peachtree Accounting software), indicated by the ⁠.ptb⁠ file extension Corporate data detailing domestic and international inventory tracking, trade checking, and business operations.
eogb.co.uk · Jun 28, 2026Deep access to Microsoft Dynamics GP containing complete corporate accounting, invoices, vendor details, and commercial transactions.Access to internal legal documents, partnership agreements, and customer contracts (such as CBIF OSMO agreements).Exfiltration of operational spreadsheets, financial reports, and executive documents via corporate
eshacloudqa.com · Jun 28, 2026We have breached ESHA Research / ESHA Cloud Services and compromised their core product development databases. The exfiltrated data includes highly confidential industry secrets and formulation data Complete intellectual property containing secret product designs, manufacturing blueprints, and recipes (⁠SupplementFormula⁠, ⁠PureFood⁠, ⁠FoodGroup⁠).Deep laboratory data, nutritional testing breakdowns, and allergen classification records (⁠SupplementIngredient⁠, ⁠Analysis⁠, ⁠AllergenGroup⁠, Sensitive registries containing client profiles, user metrics, and market consumer data (⁠Consumer⁠, ⁠Activity⁠).
monoprix.tn · Jun 28, 2026Data description: Pending update
Official Statement: Protecting palatineschool.org Infrastructure · Jun 28, 2026During our routine network security audits, our team discovered critical structural vulnerabilities within Palatine School, which granted us full, unrestricted access to their central server (PALDC2020). We had the technical capacity to access every directory, including pupil databases (⁠ StudentData NHS NO ) ⁠, ⁠Pupil Admin - Users -FocusIT⁠) and staff records ⁠Personnel⁠.We want to announce that we have locked down this operation and decided to leak absolutely nothing.This is an institution dedicated to children and special needs education. Unlike corporate thieves or ruthless threat actors, we operate with a strict code of ethics: we do not target children, schools, or healthcare facilities.Instead of destroying them, we have chosen to act as an uninvited security audit. We are using our platform to publicly invite the administration of Palatine School to contact us privately. We will provide them with the full technical details of the critical vulnerabilities we discovered and guide them on how to patch their system for free, ensuring they are protected from other ruthless cyber criminals.
Data Leak Update · Jun 26, 2026** Do ML IT and vspsolutions.com.au think they are smarter than us? They are reporting the links where the data was uploaded, and they are being disabled. Therefore, and officially, we are preparing a private server on the Tor network to dump all the data of these companies and the data of others. Which will be available to everyone 24/7 along with a clear view of the extracted data, employees
mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB · Jun 24, 2026FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases.
jaggroup.com UPDATE-FULL DATA DUMP NEW LINK · Jun 24, 2026Full database containing corporate emails (⁠@jaggroup.com⁠), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (⁠zBackups.zip⁠, ⁠wetransfer⁠ packages), SQL server connection data, and ⁠IM.mdb⁠ database files.Internal project management sheets (⁠Jag Project.xlsx⁠), user listings, purchasing, and sales import logs.
maglificioliliana.com · Jun 24, 2026Over 400 GB of data has been accessed and exfiltrated. This includes product designs, historical fashion lines, and technical specifications for garments. Furthermore, we have obtained customer databases from various parts of the world, financial records, commercial contracts, employee data, personal files for all staff members within the network, daily operational documents, and more.
lorenzoni-store.com · Jun 24, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
montechiaro-store.com · Jun 24, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
impulso-store.com · Jun 24, 2026Complete data belonging to customers and buyers has been accessed, along with designs, orders, and other assets. This includes all domains associated with the parent company: maglificioliliana.com/
jaggroup.com UPDATE-FULL DATA DUMP · Jun 22, 2026Full database containing corporate emails (⁠@jaggroup.com⁠), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (⁠zBackups.zip⁠, ⁠wetransfer⁠ packages), SQL server connection data, and ⁠IM.mdb⁠ database files.Internal project management sheets (⁠Jag Project.xlsx⁠), user listings, purchasing, and sales import logs.
mlit.com.my UPDATE-FULL DATA DUMP 10GB · Jun 19, 2026FULL DATA DUMP . The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases.
mlit.com.my · Jun 12, 2026We have successfully breached the internal servers and network infrastructure of MLIT, gaining full unauthorized access to their active Microsoft Dynamics Management Reporter environment and local storage volumes.The compromised data includes highly sensitive internal operations and financial records. Among the leaked files are complete individual Campaign Profit and Loss (PnL) statements, detailed revenue sheets, clawbacks, and general ledger accounts for several linked entities, including Salesworks Pte Ltd Taiwan Branch and Shaves2u HK Limited. Additionally, we have extracted complete directory trees and file structures from the internal network shares and remote desktop sessions, revealing thousands of corporate folders such as JAG Group, SWGP Excel Import, and various financial databases.
katholiekamersfoort.nl UPDATE-FOR SALE · Jun 9, 2026The church website
sa2000.com UPDATE-FULL DATA DUMP · Jun 9, 2026150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES ACHAT / FACTURES À PAYER / FACTURES MODIFIÉES - Banking Informations SA2000 - PAIEMENTS CLIENTS - CLIENTS / PO CLIENTS - FOURNISSEUR / TRANSPORTEURS - EMPLOYÉS / EMBAUCHE - ACTIONNAIRES - COURRIEL / DOCUMENTS COURRIELS.There is still an opportunity to communicate and resolve this situation. We are currently awaiting the company
SA2000.COM · Jun 4, 2026150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES ACHAT / FACTURES À PAYER / FACTURES MODIFIÉES - Banking Informations SA2000 - PAIEMENTS CLIENTS - CLIENTS / PO CLIENTS - FOURNISSEUR / TRANSPORTEURS - EMPLOYÉS / EMBAUCHE - ACTIONNAIRES - COURRIEL / DOCUMENTS COURRIELS.There is still an opportunity to communicate and resolve this situation. We are currently awaiting the company
katholiekamersfoort.nl · Jun 2, 2026The church website
vspsolutions.com.au FULL DATA DUMP · May 24, 2026+40G Full Financial Backups (Quickbooks & Reckon)-Email Archives & Staff Personal Folders-Customer/Client Databases (Installers & Integrators nationwide)-Shipment & Order Tracking for major brands like Hikvision & Axis.
www.kai.id (FF) · May 17, 2026PT Kereta Api Indonesia is the national railway company in Indonesia, also known as Kereta Api. It is responsible for operating train services throughout the country.
Important Announcement · May 17, 2026
VPN Access Sale · May 17, 2026
FANASA.COM UPDATE-FULL DATA DUMP · May 17, 2026
arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMP · May 17, 2026
ttt.vn UPDATE-FULL DATA DUMP · May 17, 2026
cgcsa.co.za UPDATE-FULL DATA DUMP · May 17, 2026
ams-group.co.uk FULL DATA DUMP 33GB · May 17, 2026
vspsolutions.com.au SAMPLE-FREE 20GB · May 17, 2026
clarochile.cl · Jan 22, 2026
GOODMANMFG · Dec 9, 2025
futureal · Dec 9, 2025
bkcolombia · Dec 9, 2025
holidaypalace · Dec 9, 2025
! · Nov 10, 2025
www.wilmar.co.id · Nov 7, 2025
www.danareksa.com · Nov 7, 2025
www.marjane.ma · Nov 7, 2025
French Government · Oct 28, 2025
acuity · Oct 28, 2025
enersolcr · Oct 28, 2025
regencytorviscas · Oct 28, 2025
regencycountryclub · Oct 28, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .