ST

Stormous Ransomware

Active

Threat actor group tracked in the global ransomware database ยท Last disclosure: May 13, 2026

Ransomware-as-a-Service (RaaS) Double Extortion Target: Business Services
95
Total Victims
0.5% of all tracked
35
Countries Targeted
2
Sectors Targeted
2026
First Seen

Threat Actor Analysis

Stormous is a ransomware threat group that has disclosed 95 victims in publicly accessible leak site data, representing 0.5% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Stormous in our dataset dates to May 2026.

Geographically, Stormous has targeted organisations in 35 countries. The most frequently targeted nation is United States with 11 victim organisations. Other heavily targeted nations include France, Spain, UAE.

Industry-wise, Stormous shows a concentration in the Business Services, Financial Services sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime โ€” conditions that increase ransom payment likelihood.

Like most modern ransomware operations, Stormous likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.

Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The victim table below shows the 4 most recent cached victims; the total victim count (95) reflects the complete database.

Recent Victim Disclosures (4 cached of 95 total)

# Organization Country Sector Date
1
ttt.vn UPDATE-FULL DATA DUMP
ttt.vn
๐Ÿ‡ป๐Ÿ‡ณ Vietnam โ€” May 13, 2026
2
vspsolutions.com.au SAMPLE-FREE 20GB
vspsolutions.com.au
๐Ÿ‡ฆ๐Ÿ‡บ Australia Business Services May 13, 2026
3
arc-reins.com + fidelityunited.ae UPDATE-FULL DATA DUMP
fidelityunited.ae
๐Ÿ‡ฆ๐Ÿ‡ช UAE Financial Services May 11, 2026
4
ams-group.co.uk FULL DATA DUMP 33GB
ams-group.co.uk
๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom Business Services May 10, 2026

Frequently Asked Questions

What is Stormous ransomware?

Stormous is a ransomware threat group that has claimed 95 victims since its first known activity in May 2026. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Stormous attacked?

Stormous has claimed 95 victims in our database, representing 0.5% of all tracked ransomware attacks. The most targeted countries are United States, France, Spain, UAE.

Which countries does Stormous target?

Stormous has attacked organizations in 35 countries. The top targeted countries are: United States, France, Spain, UAE.

Which industries does Stormous target?

Stormous most frequently targets the Business Services, Financial Services sectors based on victim disclosures in our database.

Is Stormous still active?

Stormous's most recent victim disclosure in our database was on May 13, 2026. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.