THREAT ACTOR
STORMOUS_
DormantSTORMOUS is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of STORMOUS, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 37
- 2025 68
- 2024 46
- 2023 73
- 2022 11
Leak site mirrors
6 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
3slz4povugieoi3tw7sblxoowxhbzxeju427cffsst5fo2tizepwatid.onionStormous-ransomware snapshot · 2022-05-09 23:16 -
h3reihqb2y7woqdary2g3bmk3apgtxuyhx4j2ftovbhe3l5svev7bdyd.onion...... snapshot · 2023-10-01 00:04 -
h3reihqb2y7woqdary2g3bmk3apgtxuyhx4j2ftovbhe3l5svev7bdyd.onionStormous _ official Site snapshot · 2023-10-01 00:04 -
pdcizqzjitsgfcgqeyhuee5u6uki6zy5slzioinlhx6xjnsw25irdgqd.onionStormous.Leak snapshot · 2026-07-02 22:00 -
6sf5xa7eso3e3vk46i5tpcqhnlayczztj7zjktzaztlotyy75zs6j7qd.onionIndex of / snapshot · 2026-02-15 20:15 -
zib7duoiglvzvnpjs5faly6bio4xhwiby2lupsnxrkjnx46gmwdfyrid.onionIndex of / snapshot · 2025-12-11 22:15
Recent victims
The 50 most recent victims claimed by STORMOUS. Total in the index: 235.
| Date listed | Victim | Description |
|---|---|---|
| 2026-07-02 | BN: higuchi-inc Report Error & Data Leak Warning | www.higuchi-inc.co.jp/newsrelease/company/doc/unauthorized_access_inci… |
| 2026-07-02 | Notice | We will soon terminate our operations and services. All hosted data is… |
| 2026-06-28 | maglificioliliana.com UPDATE-FULL DATA DUMP FREE PART1 | Over +10GB GB of data has been accessed and exfiltrated. This includes… |
| 2026-06-28 | lorenzoni-store.com UPDATE-FULL DATA DUMP FREE PART1 | Complete data belonging to customers and buyers has been accessed, alo… |
| 2026-06-28 | montechiaro-store.com UPDATE-FULL DATA DUMP FREE PART1 | Complete data belonging to customers and buyers has been accessed, alo… |
| 2026-06-28 | impulso-store.com UPDATE-FULL DATA DUMP FREE PART1 | Complete data belonging to customers and buyers has been accessed, alo… |
| 2026-06-28 | higuchi-inc.co.jp | (Dallas - HongKong - LosAngeles ) Comprehensive financial statements i… |
| 2026-06-28 | HIGUCHI USA, INC | (Dallas - HongKong - LosAngeles ) Comprehensive financial statements i… |
| 2026-06-28 | eogb.co.uk | Deep access to Microsoft Dynamics GP containing complete corporate acc… |
| 2026-06-28 | eshacloudqa.com | We have breached ESHA Research / ESHA Cloud Services and compromised t… |
| 2026-06-28 | monoprix.tn | Data description: Pending update |
| 2026-06-28 | Official Statement: Protecting palatineschool.org Infrastructure | During our routine network security audits, our team discovered critic… |
| 2026-06-26 | Data Leak Update | ** Do ML IT and vspsolutions.com.au think they are smarter than us? Th… |
| 2026-06-24 | mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB | FULL DATA DUMP . The compromised data includes highly sensitive intern… |
| 2026-06-24 | jaggroup.com UPDATE-FULL DATA DUMP NEW LINK | Full database containing corporate emails (@jaggroup.com), Active Di… |
| 2026-06-24 | maglificioliliana.com | Over 400 GB of data has been accessed and exfiltrated. This includes p… |
| 2026-06-24 | lorenzoni-store.com | Complete data belonging to customers and buyers has been accessed, alo… |
| 2026-06-24 | montechiaro-store.com | Complete data belonging to customers and buyers has been accessed, alo… |
| 2026-06-24 | impulso-store.com | Complete data belonging to customers and buyers has been accessed, alo… |
| 2026-06-22 | jaggroup.com UPDATE-FULL DATA DUMP | Full database containing corporate emails (@jaggroup.com), Active Di… |
| 2026-06-19 | mlit.com.my UPDATE-FULL DATA DUMP 10GB | FULL DATA DUMP . The compromised data includes highly sensitive intern… |
| 2026-06-12 | mlit.com.my | We have successfully breached the internal servers and network infrast… |
| 2026-06-09 | katholiekamersfoort.nl UPDATE-FOR SALE | The church website |
| 2026-06-09 | sa2000.com UPDATE-FULL DATA DUMP | 150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES … |
| 2026-06-04 | SA2000.COM | 150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES … |
| 2026-06-02 | katholiekamersfoort.nl | The church website |
| 2026-05-24 | vspsolutions.com.au FULL DATA DUMP | +40G Full Financial Backups (Quickbooks & Reckon)-Email Archives & Sta… |
| 2026-05-17 | www.kai.id (FF) | PT Kereta Api Indonesia is the national railway company in Indonesia, … |
| 2026-05-17 | Important Announcement | |
| 2026-05-17 | VPN Access Sale | |
| 2026-05-17 | FANASA.COM UPDATE-FULL DATA DUMP | |
| 2026-05-17 | arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMP | |
| 2026-05-17 | ttt.vn UPDATE-FULL DATA DUMP | |
| 2026-05-17 | cgcsa.co.za UPDATE-FULL DATA DUMP | |
| 2026-05-17 | ams-group.co.uk FULL DATA DUMP 33GB | |
| 2026-05-17 | vspsolutions.com.au SAMPLE-FREE 20GB | |
| 2026-01-22 | clarochile.cl | |
| 2025-12-09 | Important Announcement Regarding Our Operations | |
| 2025-12-09 | GOODMANMFG | |
| 2025-12-09 | futureal | |
| 2025-12-09 | bkcolombia | |
| 2025-12-09 | holidaypalace | |
| 2025-11-10 | ! | |
| 2025-11-07 | www.wilmar.co.id | |
| 2025-11-07 | www.danareksa.com | |
| 2025-11-07 | www.marjane.ma | |
| 2025-10-28 | French Government | |
| 2025-10-28 | acuity | |
| 2025-10-28 | enersolcr | |
| 2025-10-28 | regencytorviscas |
CONFIRMED ATTACKS
Stormous confirmed attacks: 9 verified incidents
Ransomnews has verified 9 Stormous incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from September 2022 to June 2026. United States accounts for 2 of them (22%), with victims recorded in 7 countries in total. The most affected sector is retail, at 2 confirmed victims. A ransom payment was publicly confirmed in 0 cases and publicly refused in 1; the outcome is unrecorded in the remaining 8. Where a figure was disclosed (3 cases), these incidents account for 434,138 exposed records.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Stormous incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| June 2026 | Palatine Primary School | Education | Worthing, United Kingdom | — | Unknown | Source |
| June 2026 | Higuchi Inc. (subsidiary) | Retail | Tokyo, Japan | — | Unknown | Source |
| May 2026 | VSP Security Wholesale | Retail | St Peters, Australia | — | Unknown | Source |
| July 2025 | France Travail | Government | Paris, France | 340,000 | Unknown | Source |
| October 2024 | Guardian Healthcare | Healthcare | Pennsylvania, United States | — | Unknown | Source |
| September 2024 | Transak | Finance | Florida, United States | 92,554 | No | Source |
| March 2024 | Duvel Moortgat Brewery | Food and Beverage | Puurs-Sint-Amands, Belgium | 1,584 | Unknown | Source |
| August 2023 | Econocom BeLux | Technology | Zaventem, Belgium | — | Unknown | Source |
| September 2022 | Universidade de Roma Tor Vergata (University of Rome) | Education | Rome, Italy | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Stormous's own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.