ZeroHour

stormous

ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
21
All-time (tracked)
221since 2022-04-12
Last post
07-02 00:54UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.

Tactics & tooling
  • Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
  • Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
  • Double extortion: threatens data publication alongside or instead of encryption
  • Posts free full data dumps to pressure victims after stalled or failed negotiations
  • Targets small and mid-sized organizations perceived to have weaker defenses
  • Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
  • Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Targeted sectors
Logistics and transportationManufacturingConsumer goods and food and beverageRetail and e-commerceSoftware and IT servicesEducationEnergy
Notable public victims

Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Wizz Air Abu Dhabi · Mar 8, 2025
turbomp · Feb 6, 2025
cmr24 · Feb 6, 2025
biodimed · Dec 16, 2024
uatf · Dec 11, 2024
transak · Dec 11, 2024
lyra.officegroup · Dec 11, 2024
guardianhc · Dec 11, 2024
ascires · Dec 11, 2024
aosense · Dec 11, 2024
acuity/ · Dec 11, 2024
fractal · Dec 11, 2024
AOSense/NASA · Oct 5, 2024
NASA/AOSense · Oct 5, 2024
lyra.officegroup.it · Oct 5, 2024
Acuity Advisor · Oct 1, 2024
asobostudio · Oct 1, 2024
mivideo.club · Sep 13, 2024
jatelindo · Sep 12, 2024
TELECO · Aug 18, 2024
intrama-bg · Jul 27, 2024
HITC.VN · Jul 7, 2024
Barid soft · May 10, 2024
KAI · May 8, 2024
bombaygrills · May 3, 2024
everplast · May 3, 2024
tox.chat · May 3, 2024
airbogo · May 3, 2024
viadirectamarketing · May 3, 2024
www.loghmanpharma.com · May 3, 2024
www.duvel.com · May 3, 2024
mioa.gov · May 3, 2024
lostlb · May 3, 2024
education.eeb-lost · May 3, 2024
paginesi · May 3, 2024
casio india · May 3, 2024
sharik · May 3, 2024
tdra · May 3, 2024
fanr.gov.ae · May 3, 2024
Bayanat · May 3, 2024
kidx · May 3, 2024
delia.pl · Feb 16, 2024
bombaygrills.com · Feb 14, 2024
calcomp.co.th · Feb 14, 2024
Abelsantosyasoc.com.ar (FF) · Feb 2, 2024
Abelsantosyasoc.com.ar · Feb 2, 2024
uffs.edu.br · Jan 18, 2024
www.kai.id (FF · Jan 14, 2024
pcmarket.uz · Dec 25, 2023
zonesoft.pt · Dec 22, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .