stormous
ransomware group · aka Stormous, STORMOUS · unknown; the group has self-described as Russian-speaking and claimed a pro-Russia motive for its 2022 attacks on Ukrainian organizations (per vendor reporting of the group's own statements) · active since early 2022 (some reporting traces initial activity to late 2021)
Stormous is a data-theft and extortion group first documented by vendors in early 2022, known primarily for double extortion: stealing victim data and threatening publication or sale, with encryption described inconsistently across incidents. The group publicly framed its early campaigns as pro-Russia, claiming attacks on Ukrainian logistics and manufacturing targets in 2022, and its most widely reported incident is a claimed 2022 breach of Coca-Cola involving roughly 161 GB of stolen data offered for sale. Vendor reporting has consistently described Stormous as focusing on small and mid-sized companies in logistics, manufacturing, consumer goods, retail, and software. Its leak site routinely publishes victim names and free full dumps of stolen data, matching the 22 victims this dashboard logged over the past 90 days, including several retail and e-commerce listings in mid-2026. No reliable public figures exist on the group's ransom revenue, and no specific CVE exploitation has been widely attributed to it.
- Initial access via phishing emails with malicious links or attachments (vendor reporting, 2022)
- Data exfiltration followed by leak-site publication and sale of stolen data when ransoms go unpaid
- Double extortion: threatens data publication alongside or instead of encryption
- Posts free full data dumps to pressure victims after stalled or failed negotiations
- Targets small and mid-sized organizations perceived to have weaker defenses
- Uses geopolitical framing in public statements (claimed pro-Russia motive for 2022 Ukraine targeting)
- Commodity credential-theft and remote-access tooling reported by some vendors; specifics not consistently documented
Coca-Cola (claimed 2022 breach, ~161 GB of data offered for sale; widely reported, details not officially confirmed), Ukrainian logistics and manufacturing targets (claimed by the group in 2022), Higuchi Inc. / HIGUCHI USA (leak-site listing, mid-2026, per this dashboard), Monoprix Tunisia (leak-site listing, per this dashboard), EOGB Energy (leak-site listing, per this dashboard), Palatine School (leak-site listing, per this dashboard), Multiple Italian e-commerce retailers including Lorenzoni, Montechiaro, Maglificio Liliana, and Impulso (leak-site listings with free data dumps, per this dashboard)
No public figure.
Leak-site victims221 posts · newest first
| Victim | Discovered | Details |
|---|---|---|
| SOCOMEC | · Mar 26, 2023 | — |
| FICHTNER | · Mar 26, 2023 | — |
| DAVINCI | · Mar 26, 2023 | — |
| ALKF+ | · Mar 26, 2023 | — |
| berjayaClubs | · Mar 26, 2023 | — |
| NOVELIS | · Mar 26, 2023 | — |
| CONFIDO | · Mar 26, 2023 | — |
| CESCE | · Mar 26, 2023 | — |
| la providence | · Mar 26, 2023 | — |
| DGCX | · Mar 26, 2023 | — |
| Epic Games Data Breach | · Apr 12, 2022 | — |
| Core Design | · Apr 12, 2022 | — |
| Satz Kontor GmbH data | · Apr 12, 2022 | — |
| 3S Standard Sharing Software | · Apr 12, 2022 | — |
| Smith Transport company | · Apr 12, 2022 | — |
| infotech ua | · Apr 12, 2022 | — |
| A message to France | · Apr 12, 2022 | — |
| National Rehabilitation Training Center | · Apr 12, 2022 | — |
| ALAM LMS | · Apr 12, 2022 | — |
| Delhi Heights School | · Apr 12, 2022 | — |
| Success Neeti | · Apr 12, 2022 | — |
In the newsAll →
No articles mention this group yet.