ZeroHour

stormous

ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
21
All-time (tracked)
221since 2022-04-12
Last post
07-02 00:54UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.

Tactics & tooling
  • Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
  • Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
  • Double extortion: threatens data publication alongside or instead of encryption
  • Posts free full data dumps to pressure victims after stalled or failed negotiations
  • Targets small and mid-sized organizations perceived to have weaker defenses
  • Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
  • Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Targeted sectors
Logistics and transportationManufacturingConsumer goods and food and beverageRetail and e-commerceSoftware and IT servicesEducationEnergy
Notable public victims

Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
Warning to Zonesoft · Dec 22, 2023
comtrade.com · Dec 22, 2023
zewailcity.edu.eg · Dec 22, 2023
evn.com.vn · Dec 22, 2023
inwi.ma · Dec 22, 2023
rmutto.ac.th · Dec 22, 2023
trabzon.edu.tr · Dec 22, 2023
epson · Sep 25, 2023
interep · Sep 23, 2023
enpos · Sep 13, 2023
pvc-ms · Sep 8, 2023
mambo · Sep 3, 2023
nipun · Sep 3, 2023
jasper · Sep 3, 2023
econocom · Sep 3, 2023
vivtok · Sep 3, 2023
dynamite · Jul 24, 2023
Senior · Jul 17, 2023
jasperpictures · Jul 15, 2023
Ministry of Energy and Mines (Cuba) - STORMOUS + GhostSec · Jul 15, 2023
Ministerio de Cultura de la Republica de Cuba - STORMOUS + GhostSec · Jul 13, 2023
Ministry of Foreign Trade - STORMOUS + GhostSec · Jul 13, 2023
Ministry of Energy and Mines (Cuba) " STORMOUS + GhostSec " · Jul 13, 2023
berjaya · Jul 12, 2023
Ingersoll Rand · Jul 12, 2023
Arrowall · Jul 12, 2023
OKS · Jul 12, 2023
Matrix · Jul 12, 2023
treenovum.es · Jul 12, 2023
archiplusinter.com · Jul 12, 2023
marehotels · Jul 12, 2023
mamboafricaadventure · Jul 12, 2023
Nipun Consultancy · Jul 12, 2023
TWHOUSE · Apr 3, 2023
METALWORK · Apr 3, 2023
OCEAN · Apr 3, 2023
TREENOVUM · Apr 3, 2023
ARCHI+ · Apr 3, 2023
SAGE · Apr 3, 2023
GOV.PL · Mar 30, 2023
matrixtelecoms · Mar 30, 2023
ieseco · Mar 30, 2023
MELCO · Mar 30, 2023
LINX · Mar 27, 2023
FURUNO · Mar 27, 2023
IRCO · Mar 27, 2023
ARROWAL · Mar 27, 2023
OKSGROUP · Mar 27, 2023
turvatehnika · Mar 26, 2023
KONICA · Mar 26, 2023

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .