ZeroHour

stormous

ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
21
All-time (tracked)
221since 2022-04-12
Last post
07-02 00:54UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.

Tactics & tooling
  • Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
  • Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
  • Double extortion: threatens data publication alongside or instead of encryption
  • Posts free full data dumps to pressure victims after stalled or failed negotiations
  • Targets small and mid-sized organizations perceived to have weaker defenses
  • Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
  • Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Targeted sectors
Logistics and transportationManufacturingConsumer goods and food and beverageRetail and e-commerceSoftware and IT servicesEducationEnergy
Notable public victims

Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
regencyrestors · Oct 28, 2025
jparkislandresort · Oct 28, 2025
crystalhotels · Oct 28, 2025
Hy-Vee · Oct 28, 2025
atolon-parkhotel · Oct 28, 2025
thewatermansarms · Oct 28, 2025
rinaldi · Oct 28, 2025
Volkswagen · Oct 28, 2025
bulentklise · Oct 28, 2025
usbmemorydirect.com · Oct 28, 2025
Important Announcement Regarding Our Operations · Oct 28, 2025
Sincroslab Sas · Oct 28, 2025
visioninksltd · Oct 28, 2025
americanadecolchones · Oct 28, 2025
FRANCE TRAVAIL DATA BREACH - 2025 · Oct 28, 2025
North Country HealthCare · Jul 13, 2025
hy-vee.com · Jun 24, 2025
bulentklise.com.tr · Jun 15, 2025
education.gouv.fr · Jun 10, 2025
rinaldi.com.br · Jun 6, 2025
French Gov 2025 · May 23, 2025
French Gov · May 23, 2025
www.seashoremotel.com · May 21, 2025
www.wirebangkok.com · May 21, 2025
www.axxoshotels.com · May 21, 2025
crystalhotels.com.tr · May 21, 2025
nirvanahotels.com.tr · May 21, 2025
thewatermansarms.net · May 21, 2025
www.atolon-parkhotel.com · May 18, 2025
www.jparkislandresort.com · May 15, 2025
www.regencytorviscas.com · May 11, 2025
www.regencycountryclub.com · May 11, 2025
www.regencyrestors.com · May 11, 2025
Wizz Air · May 2, 2025
Welcome to phish.pw · Mar 28, 2025
KYC UK · Mar 19, 2025
Details of bank card data for over 50,000 Moroccan · Mar 19, 2025
vouch.co.uk + KYC UK · Mar 17, 2025
vouch.co.uk · Mar 17, 2025
Transak.com · Mar 17, 2025
uatf.edu.bo · Mar 17, 2025
guardianhc.com · Mar 17, 2025
ascires.com · Mar 17, 2025
fractal.id · Mar 17, 2025
aosense.com · Mar 17, 2025
acuity.co.uk · Mar 17, 2025
biodimed.com · Mar 17, 2025
turbomp.com · Mar 17, 2025
cmr24.by · Mar 17, 2025
enersolcr.com · Mar 15, 2025

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .