IBOV 182,991.13 ▼ 0.26% IPSA 11,137.59 ▼ 1.06% IPC MEX 64,737.82 ▼ 0.39% MERVAL 2,798,925 ▼ 3.28% COLCAP 2,579.33 ▼ 0.21% BVL PERÚ 60,698.35 ▼ 0.79% USD/BRL5.22▲ 0.80% USD/MXN17.99▲ 1.73% USD/CLP965.70▲ 0.43% USD/COP3,363▲ 2.28% USD/PEN3.44▲ 1.32% USD/ARS1,525▼ 0.02% USD/UYU40.39▲ 0.44% USD/PYG5,843▼ 0.46% USD/BOB11.98▼ 1.56% USD/DOP59.28▼ 0.02% USD/CRC450.38▼ 0.11% USD/GTQ7.63▼ 0.07% USD/HNL26.86▲ 0.03% USD/NIO36.62— 0.00% USD/VES855.74▼ 0.02% USD/PAB1.00— 0.00% USD/BZD2.00— 0.00% USD/JMD 157.28 — 0.00% USD/TTD6.72▼ 0.73% EUR/BRL5.94▲ 0.48% BRENT 88.88 ▼ 0.03% WTI 83.11 ▼ 0.11% IRON ORE 161.91 — — COPPER 6.61 ▲ 0.03% GOLD 4,461 ▲ 1.78% SILVER 65.59 ▲ 1.26% SOY 1,184 ▲ 3.20% CORN 480.50 ▲ 10.02% WHEAT 655.00 ▲ 3.93% COFFEE 317.25 ▼ 5.51% SUGAR 16.43 ▼ 1.79% ORANGE JUICE 138.55 ▼ 0.47% COTTON 85.03 ▲ 2.33% COCOA 5,719 ▲ 3.18% BEEF 223.60 ▼ 3.93% CATTLE 339.10 ▼ 3.16% LITHIUM 75.20 ▲ 1.47% PETR4 41.64 ▼ 0.05% VALE3 72.97 ▲ 0.83% ITUB4 38.60 ▼ 1.03% BBDC4 16.85 ▲ 0.36% ABEV3 14.89 ▼ 0.80% BBAS3 19.37 ▲ 0.47% B3SA3 14.26 ▼ 0.21% WEGE3 47.59 ▲ 0.49% PRIO3 59.14 ▼ 0.19% SUZB3 41.33 ▲ 2.35% RENT3 34.68 ▼ 0.09% AZZA3 15.89 ▼ 2.63% CSAN3 3.22 ▼ 1.83% RAIZ4 0.25 — 0.00% PCAR3 2.75 ▼ 0.36% GMAT3 3.65 ▼ 1.08% PSSA3 48.13 ▼ 0.54% CVCB3 1.33 ▼ 2.92% POSI3 3.36 ▲ 2.44% SLCE3 13.34 ▲ 0.30% NATU3 8.14 ▼ 0.73% IBOV 182,991.13 ▼ 0.26% IPSA 11,137.59 ▼ 1.06% IPC MEX 64,737.82 ▼ 0.39% MERVAL 2,798,925 ▼ 3.28% COLCAP 2,579.33 ▼ 0.21% BVL PERÚ 60,698.35 ▼ 0.79% USD/BRL 5.16 ▲ 0.01% USD/MXN 17.06 ▼ 0.24% USD/CLP 913.98 ▲ 0.04% USD/COP 3,140 ▲ 0.03% USD/PEN 3.36 ▼ 0.66% USD/ARS 1,493 ▲ 0.10% USD/UYU 40.27 ▲ 1.24% USD/PYG 5,939 ▲ 1.68% USD/BOB 11.64 ▼ 0.76% USD/DOP 58.34 ▲ 1.25% USD/CRC 445.92 ▲ 0.89% USD/GTQ 7.62 ▲ 2.21% USD/HNL 26.79 ▲ 1.57% USD/NIO 36.62 ▲ 0.69% USD/VES 762.44 ▼ 0.13% USD/PAB 1.00 — 0.00% USD/BZD 2.00 — 0.00% USD/JMD 157.28 — 0.00% USD/TTD 6.70 ▲ 0.61% EUR/BRL 5.95 ▲ 1.01% BRENT 88.88 ▼ 0.03% WTI 83.11 ▼ 0.11% IRON ORE 161.91 — — COPPER 6.61 ▲ 0.03% GOLD 4,461 ▲ 1.78% SILVER 65.59 ▲ 1.26% SOY 1,184 ▲ 3.20% CORN 480.50 ▲ 10.02% WHEAT 655.00 ▲ 3.93% COFFEE 317.25 ▼ 5.51% SUGAR 16.43 ▼ 1.79% ORANGE JUICE 138.55 ▼ 0.47% COTTON 85.03 ▲ 2.33% COCOA 5,719 ▲ 3.18% BEEF 223.60 ▼ 3.93% CATTLE 339.10 ▼ 3.16% LITHIUM 75.20 ▲ 1.47% PETR4 41.64 ▼ 0.05% VALE3 72.97 ▲ 0.83% ITUB4 38.60 ▼ 1.03% BBDC4 16.85 ▲ 0.36% ABEV3 14.89 ▼ 0.80% BBAS3 19.37 ▲ 0.47% B3SA3 14.26 ▼ 0.21% WEGE3 47.59 ▲ 0.49% PRIO3 59.14 ▼ 0.19% SUZB3 41.33 ▲ 2.35% RENT3 34.68 ▼ 0.09% AZZA3 15.89 ▼ 2.63% CSAN3 3.22 ▼ 1.83% RAIZ4 0.25 — 0.00% PCAR3 2.75 ▼ 0.36% GMAT3 3.65 ▼ 1.08% PSSA3 48.13 ▼ 0.54% CVCB3 1.33 ▼ 2.92% POSI3 3.36 ▲ 2.44% SLCE3 13.34 ▲ 0.30% NATU3 8.14 ▼ 0.73%
since 2009
Tuesday, September 29, 2026

Business Markets

Cl0p Hacking Group Claims Data Theft From Shell, Philips, GE and Fiserv

By · August 14, 2026 · 6 min read

The LatAm Brief

One email, every weekday morning. What moved in Latin American markets, politics and expat life.

Yesterday’s subject line: “Brazil votes Sunday. The courts are deciding.”

Free. We send a confirmation link first — nothing arrives until you click it. Unsubscribe with one click in any edition. If you stop opening us for 30 days we stop sending by ourselves, as we assume the interest is no longer there. See our privacy policy. We never share your email.

Global · CYBERSECURITY

Key Facts

—Cl0p claim: The group listed nearly 50 companies on its extortion site, claiming data theft from firms including Shell, Philips, GE and Fiserv. Reuters reported the claims on 13 August 2026 and did not date the posting itself.

Free daily brief — no card needed
Get every Business story in one morning email
We build you a personalized brief around the topics you follow — free for 7 days. Love it? Your first month after that is US$1.

—Claimed volumes: Trade-press accounts of the posting put the alleged haul at about 89 gigabytes from Shell and 13.5 gigabytes from Philips. Reuters said it could not independently verify what was taken or how much.

—Alleged Shell data: Engineering drawings, photos of facilities, scans of facility testing reports, and project plans.

—Alleged Philips data: Portable Document Format drawings, diagrams, and blueprints.

—Company responses: Philips said it contained an attempted compromise of an internal server and Shell said it was investigating a possible incident. GE said it had initiated its cyber response protocols, and Fiserv said it found no evidence of compromise.

—The suspected route: Ransom-ISAC warned on 22 July 2026 that Cl0p was exploiting flaws in PTC Windchill and FlexPLM engineering software, tracked as CVE-2026-12569. PTC has urged customers to patch since 18 June 2026.

The Cl0p data theft claims against Shell, Philips, GE and Fiserv remain unverified: none of the four has confirmed that data was taken, and the group has published no samples.

Cl0p data theft claim - lines of website source code on a dark computer monitor
Cl0p Hacking Group Claims Data Theft From Shell, Philips, GE and Fiserv. Photo: Sai Kiran Anagani _imkiran, CC0, Wikimedia Commons.
One-stop reference
Company Intelligence
Every listed company in Latin America — financials, ownership and structure for 1,450+ companies across 26 exchanges, in one place.
Browse the directory →
RT
Ask Rio Times
Latin American markets, currencies and companies.
Open the full Ask Rio Times →

What Cl0p claims it took

The cybercrime group Cl0p, which some researchers and regional reporting link to Russian-speaking operators, listed nearly 50 companies on its extortion site and said it had stolen large volumes of data from them. Reuters reported the claims on 13 August 2026 without dating the posting; trade-press accounts place it earlier the same week and put the alleged haul at about 89 gigabytes from Shell and 13.5 gigabytes from Philips.

The alleged Shell material included engineering drawings, photos of facilities, scans of facility testing reports, and project plans. The alleged Philips material included Portable Document Format drawings, diagrams, and blueprints.

Reuters said it could not independently verify the group’s claims about what kind of data it took or how much, and that the hackers did not respond to a request for comment. Cl0p has published no samples, and that absence of proof is central to how companies and regulators are treating the claims.

How the companies responded

Philips said it identified and contained an attempted cybersecurity compromise of a specific enterprise server tied to internal data. The Dutch health technology group added that customer environments were not affected.

Shell said it was aware of a recent possible incident and was investigating with security experts. Fiserv said it found no evidence of compromise of customer data, banking or transactional data, or personal information.

A GE spokesperson said the company was aware of the claim and had initiated its cyber response protocols while it works to assess the potential issue. None of the four named firms confirmed that data was actually exfiltrated from their systems.

Why industrial data matters

The targeted firms sit at the intersection of energy, healthcare, industrial engineering and financial infrastructure. Even unconfirmed theft claims can affect procurement security, regulatory exposure, and counterparty trust.

The alleged Shell material is the kind of data that can be valuable for industrial espionage, operational mapping, and physical-security planning. It is not just classic fraud data such as credit card numbers or login credentials.

Philips pointed to an internal server rather than customer systems. That underscores a broader corporate reality: attackers increasingly aim at back-end engineering and documentation systems, where sensitive strategic information resides even when customer-facing operations remain unaffected.

The Cl0p data theft playbook

Cl0p has built a reputation for high-volume, industrialised extortion by exploiting software flaws across many victims at once. Reuters reported that Ransom-ISAC, an industry information-sharing group, issued a notice on 22 July 2026 warning that Cl0p was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used in engineering and manufacturing.

The Boston-based vendor PTC has issued security notices since 18 June 2026 urging customers to apply a patch, and the flaw, tracked as CVE-2026-12569, is on the US cybersecurity agency’s Known Exploited Vulnerabilities list. Brandon Parsons, who wrote the Ransom-ISAC advisory, said the group targets a specific vulnerability rather than a specific company.

This type of campaign hits the core assets of modern corporations: design files, supplier records, project plans, and operational documentation. These are the digital equivalents of blueprints and plant diagrams.

Reuters describes Cl0p as a ransomware operation. Ukrainian and other regional reporting link it to Russian-speaking operators, though no state connection has been established.

The wider geopolitical angle

Because Shell and Philips are European multinationals with global footprints, the incident fits a larger pattern in which critical industrial data flows are vulnerable across borders. Firms often rely on common enterprise software stacks, which creates a single point of failure.

In great-power terms, mass-leak groups contribute to a wider environment in which commercial espionage, financial coercion, and strategic data theft blur together. That increases pressure on Western industrial and energy firms without requiring overt state action.

For regulators in emerging markets, the episode is a reminder that supply-chain data security is now a core business risk. Engineering and product-lifecycle software of the kind implicated here is deployed well beyond the handful of multinationals Cl0p has named.

What to watch next

The key question is whether Cl0p releases sample files to prove its claims. If it does, the reputational and legal exposure for the named firms will rise sharply.

Because the suspected route is a widely deployed engineering-software flaw, the campaign is likely to be broader than the 50 names already posted. Some companies began receiving Cl0p notices in late July, according to the Ransom-ISAC advisory.

For now the pattern is familiar: mass exploitation of one enterprise software flaw, then pressure applied company by company. The claims expose the fragility of industrial data supply chains, even before any theft is confirmed.

Frequently Asked Questions

Did Cl0p actually steal data from Shell and Philips?

Not confirmed. Reuters reported the claims on 13 August 2026, but Shell and Philips have said only that they were targeted or may have experienced an incident, not that data was exfiltrated.

What kind of data did Cl0p claim to have taken from Shell?

Trade-press accounts of the posting describe engineering drawings, photos of facilities, scans of facility testing reports and project plans, totalling about 89 gigabytes. Reuters said it could not verify the claim.

Is Cl0p linked to the Russian state?

Reuters describes Cl0p as a ransomware operation, and Ukrainian and other regional reporting link it to Russian-speaking operators. No state connection has been established.

Connected Coverage

For more on how critical data and infrastructure are becoming contested terrain, read our coverage of the global contest over strategic infrastructure.

Sources

This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error

LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.

Read More from The Rio Times

The Rio Times · Power Map
See who really holds power in Latin America
Click to open the Power Map →

Rotate for Best Experience

This report is optimized for landscape viewing. Rotate your phone for the full experience.