Ransomware group
Stormous ransomware: victims and leak site activity
The Stormous ransomware group has listed 188 victims on its leak site since March 2022; its latest post is from 28 June 2026. Most affected countries: United States, Spain and United Arab Emirates. Most targeted sector: Technology.
Total posts
188
First seen
2022-03-22
Latest post
2026-06-28
Countries hit
44
About Stormous
Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024.
On 1st July 2026 the group has annonced the end of their operations & ervices
Most targeted countries
- United States 14
- Spain 11
- United Arab Emirates 10
- France 10
- Brazil 7
- United Kingdom 7
- Germany 6
- Indonesia 6
- Italy 6
- Vietnam 5
Most targeted sectors
- Technology 32
- Professional Services 25
- Hospitality 18
- Manufacturing 18
- Education 14
- Government & Defense 14
- Retail & E-Commerce 11
- Healthcare 10
- Financial Services 9
- Transportation 8