ZeroHour

stormous

ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)

Victims · 7d
0flat
Victims · 30d
0active targets
Victims · 90d
21
All-time (tracked)
221since 2022-04-12
Last post
07-02 00:54UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.

Tactics & tooling
  • Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
  • Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
  • Double extortion: threatens data publication alongside or instead of encryption
  • Posts free full data dumps to pressure victims after stalled or failed negotiations
  • Targets small and mid-sized organizations perceived to have weaker defenses
  • Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
  • Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Targeted sectors
Logistics and transportationManufacturingConsumer goods and food and beverageRetail and e-commerceSoftware and IT servicesEducationEnergy
Notable public victims

Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
SOCOMEC · Mar 26, 2023
FICHTNER · Mar 26, 2023
DAVINCI · Mar 26, 2023
ALKF+ · Mar 26, 2023
berjayaClubs · Mar 26, 2023
NOVELIS · Mar 26, 2023
CONFIDO · Mar 26, 2023
CESCE · Mar 26, 2023
la providence · Mar 26, 2023
DGCX · Mar 26, 2023
Epic Games Data Breach · Apr 12, 2022
Core Design · Apr 12, 2022
Satz Kontor GmbH data · Apr 12, 2022
3S Standard Sharing Software · Apr 12, 2022
Smith Transport company · Apr 12, 2022
infotech ua · Apr 12, 2022
A message to France · Apr 12, 2022
National Rehabilitation Training Center · Apr 12, 2022
ALAM LMS · Apr 12, 2022
Delhi Heights School · Apr 12, 2022
Success Neeti · Apr 12, 2022

In the newsAll →

No articles mention this group yet.

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .