Full Breakdown
Shell and Philips Targeted in Cl0p Ransomware Data-Theft Claims
8/15/2026, 12:35:23 AM
Incident Overview
On August 12, the ransomware group Cl0p posted the names of several major firms, including energy giant Shell and healthcare-technology company Philips, on its public leak site. The group alleged that it had exfiltrated roughly 89 gigabytes of data from Shell and about 13.5 gigabytes from Philips. The purported material includes engineering drawings, facility photographs, test-report scans and internal project plans for Shell, and diagrams and blueprints for Philips.
Company Responses
Shell confirmed that it is aware of a “possible incident” and has launched an investigation with its security teams and external experts. The company has not verified whether any data was actually taken. Philips described the event as an attempted cyberattack that was contained to a specific internal server and stated that its customer-facing systems were unaffected. Both firms emphasized that the extent of any damage remains unclear.
Cl0p’s Modus Operandi and Prior Activity
Cl0p is known for exploiting vulnerabilities in file-transfer software, notably the MOVEit Transfer platform. The group previously targeted Shell in 2023, exploiting a MOVEit vulnerability that led to a public data leak after Shell refused to pay a ransom. In the current case, Cl0p appears to be using data theft as leverage, a tactic that complements traditional ransomware encryption by threatening disclosure of sensitive corporate information.
Potential Impact
If the claimed data were verified, the exposure of technical schematics and internal plans could pose operational and competitive risks for the affected companies. However, both Shell and Philips have indicated that no customer environments were compromised, and investigations are ongoing to determine the actual scope of the breach.
Next Steps
Shell and Philips will continue their investigations, working with cybersecurity experts to assess any data loss and to strengthen defenses against further exploitation. No additional public statements or timelines have been provided by either company at this stage.
