Cl0p Ransomware Group Claims Massive Data Theft From Shell and Philips Amid Ongoing Investigations

Cl0p publicly named Shell, Philips and other major companies as victims on its website on August 12, claiming they had stolen large amounts of data.
Shell's acknowledgement of the incident followed a Dutch media report from BNR, indicating the disclosure came after local media coverage.
Cybersecurity tracker GalaxyWarden notes that Cl0p’s data claims come directly from the hackers and have not been independently verified, highlighting the unverified nature of the data.
Cl0p has a history with Shell, including a 2023 MOVEit Transfer breach; Shell was placed at the top of Cl0p’s dark web leak site with the message 'SHELL.COM DO NOT WANT TO NEGOTIATE - DATA POSTED !!!'.
Ransomware group Cl0p has claimed to have broken into the networks of Shell and Philips, saying it stole large amounts of sensitive data from both companies. BigGo Finance reports the group is believed to have ties to Russia and publicly named the two companies — along with other major firms — as victims on August 12.
Shell confirmed it is investigating a "possible incident," while Philips described an attempted breach of a specific enterprise server. Head Topics notes both companies acknowledged the security issue after the claims went public.
Cl0p says it took about 89 gigabytes of data from Shell. That includes engineering drawings and project plans. AskTraders reports Shell confirmed it is looking into the claim but has not said whether the theft is real. The group posted a blunt message on its dark web site: "SHELL.COM DO NOT WANT TO NEGOTIATE - DATA POSTED !!!"
From Philips, Cl0p claims to have stolen roughly 13.5 gigabytes of data, including diagrams and blueprints. KFGO reports Philips said the breach was an attempted compromise of a single server. Philips stressed there was no impact on customer environments.
Shell's public acknowledgement came only after Dutch outlet BNR reported the incident first. WTVBAM notes that Cl0p is well known for finding and exploiting weaknesses in file transfer software. The group has a long track record of using stolen data as leverage to pressure companies into paying ransoms.
Neither company has confirmed the full scope of what was taken. Cybersecurity tracker GalaxyWarden points out that the data claims come directly from the hackers and have not been independently verified. No samples of the stolen data have been shared publicly.
This is not the first time Cl0p has targeted Shell. In 2023, the group exploited a flaw in a file transfer tool called MOVEit Transfer. That breach exposed Shell data along with hundreds of other organizations worldwide. The MOVEit attack was one of the largest data theft campaigns in recent memory.
The new claims fit a familiar Cl0p playbook. The group finds a weakness, pulls data, then publicly names victims to force negotiations. BigGo Finance reports Shell was placed at the top of Cl0p's leak site, a sign the group is applying maximum pressure on the energy giant.
Shell called the situation a "possible incident" and said it is working to understand what happened. Philips said the breach was limited to one enterprise server and that customer systems were not affected. Head Topics reports both firms are conducting ongoing investigations.
Neither company has confirmed data was actually taken. Until independent verification happens, the full extent of the breach remains unknown. Experts warn that even unverified claims can damage company reputations and shake investor confidence while investigations play out.
Publishers
11
Articles
70
Reach
81