Cl0p Hacking Group Claims Data Theft From Shell, Philips, GE and Fiserv
Global · CYBERSECURITY
Key Facts
—Cl0p claim: The group listed nearly 50 companies on its extortion site, claiming data theft from firms including Shell, Philips, GE and Fiserv. Reuters reported the claims on 13 August 2026 and did not date the posting itself.
—Claimed volumes: Trade-press accounts of the posting put the alleged haul at about 89 gigabytes from Shell and 13.5 gigabytes from Philips. Reuters said it could not independently verify what was taken or how much.
—Alleged Shell data: Engineering drawings, photos of facilities, scans of facility testing reports, and project plans.
—Alleged Philips data: Portable Document Format drawings, diagrams, and blueprints.
—Company responses: Philips said it contained an attempted compromise of an internal server and Shell said it was investigating a possible incident. GE said it had initiated its cyber response protocols, and Fiserv said it found no evidence of compromise.
—The suspected route: Ransom-ISAC warned on 22 July 2026 that Cl0p was exploiting flaws in PTC Windchill and FlexPLM engineering software, tracked as CVE-2026-12569. PTC has urged customers to patch since 18 June 2026.
The Cl0p data theft claims against Shell, Philips, GE and Fiserv remain unverified: none of the four has confirmed that data was taken, and the group has published no samples.

What Cl0p claims it took
The cybercrime group Cl0p, which some researchers and regional reporting link to Russian-speaking operators, listed nearly 50 companies on its extortion site and said it had stolen large volumes of data from them. Reuters reported the claims on 13 August 2026 without dating the posting; trade-press accounts place it earlier the same week and put the alleged haul at about 89 gigabytes from Shell and 13.5 gigabytes from Philips.
The alleged Shell material included engineering drawings, photos of facilities, scans of facility testing reports, and project plans. The alleged Philips material included Portable Document Format drawings, diagrams, and blueprints.
Reuters said it could not independently verify the group’s claims about what kind of data it took or how much, and that the hackers did not respond to a request for comment. Cl0p has published no samples, and that absence of proof is central to how companies and regulators are treating the claims.
How the companies responded
Philips said it identified and contained an attempted cybersecurity compromise of a specific enterprise server tied to internal data. The Dutch health technology group added that customer environments were not affected.
Shell said it was aware of a recent possible incident and was investigating with security experts. Fiserv said it found no evidence of compromise of customer data, banking or transactional data, or personal information.
A GE spokesperson said the company was aware of the claim and had initiated its cyber response protocols while it works to assess the potential issue. None of the four named firms confirmed that data was actually exfiltrated from their systems.
Why industrial data matters
The targeted firms sit at the intersection of energy, healthcare, industrial engineering and financial infrastructure. Even unconfirmed theft claims can affect procurement security, regulatory exposure, and counterparty trust.
The alleged Shell material is the kind of data that can be valuable for industrial espionage, operational mapping, and physical-security planning. It is not just classic fraud data such as credit card numbers or login credentials.
Philips pointed to an internal server rather than customer systems. That underscores a broader corporate reality: attackers increasingly aim at back-end engineering and documentation systems, where sensitive strategic information resides even when customer-facing operations remain unaffected.
The Cl0p data theft playbook
Cl0p has built a reputation for high-volume, industrialised extortion by exploiting software flaws across many victims at once. Reuters reported that Ransom-ISAC, an industry information-sharing group, issued a notice on 22 July 2026 warning that Cl0p was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used in engineering and manufacturing.
The Boston-based vendor PTC has issued security notices since 18 June 2026 urging customers to apply a patch, and the flaw, tracked as CVE-2026-12569, is on the US cybersecurity agency’s Known Exploited Vulnerabilities list. Brandon Parsons, who wrote the Ransom-ISAC advisory, said the group targets a specific vulnerability rather than a specific company.
This type of campaign hits the core assets of modern corporations: design files, supplier records, project plans, and operational documentation. These are the digital equivalents of blueprints and plant diagrams.
Reuters describes Cl0p as a ransomware operation. Ukrainian and other regional reporting link it to Russian-speaking operators, though no state connection has been established.
The wider geopolitical angle
Because Shell and Philips are European multinationals with global footprints, the incident fits a larger pattern in which critical industrial data flows are vulnerable across borders. Firms often rely on common enterprise software stacks, which creates a single point of failure.
In great-power terms, mass-leak groups contribute to a wider environment in which commercial espionage, financial coercion, and strategic data theft blur together. That increases pressure on Western industrial and energy firms without requiring overt state action.
For regulators in emerging markets, the episode is a reminder that supply-chain data security is now a core business risk. Engineering and product-lifecycle software of the kind implicated here is deployed well beyond the handful of multinationals Cl0p has named.
What to watch next
The key question is whether Cl0p releases sample files to prove its claims. If it does, the reputational and legal exposure for the named firms will rise sharply.
Because the suspected route is a widely deployed engineering-software flaw, the campaign is likely to be broader than the 50 names already posted. Some companies began receiving Cl0p notices in late July, according to the Ransom-ISAC advisory.
For now the pattern is familiar: mass exploitation of one enterprise software flaw, then pressure applied company by company. The claims expose the fragility of industrial data supply chains, even before any theft is confirmed.
Frequently asked questions
Did Cl0p actually steal data from Shell and Philips?
Not confirmed. Reuters reported the claims on 13 August 2026, but Shell and Philips have said only that they were targeted or may have experienced an incident, not that data was exfiltrated.
What kind of data did Cl0p claim to have taken from Shell?
Trade-press accounts of the posting describe engineering drawings, photos of facilities, scans of facility testing reports and project plans, totalling about 89 gigabytes. Reuters said it could not verify the claim.
Is Cl0p linked to the Russian state?
Reuters describes Cl0p as a ransomware operation, and Ukrainian and other regional reporting link it to Russian-speaking operators. No state connection has been established.
Connected Coverage
For more on how critical data and infrastructure are becoming contested terrain, read our coverage of the global contest over strategic infrastructure.
Sources
- Reuters — Hacking group claims mass data theft from Shell, Philips, GE, Fiserv (13 Aug 2026)
- Ransom-ISAC — Cl0p exploitation of Windchill and FlexPLM
- Help Net Security — CVE-2026-12569 actively exploited
- AskTraders — Shell targeted by Cl0p, claimed data volumes (13 Aug 2026)
This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error
LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.
Read More from The Rio Times