Cl0p asserts that they have conducted a major hack involving Shell, Philips, and numerous other companies.

Cl0p asserts that they have conducted a major hack involving Shell, Philips, and numerous other companies.

      The ransomware group Cl0p, linked to Russia, has reported a new series of cyberattacks, naming Shell and Philips among its targets, with estimates suggesting that nearly 50 companies may be involved. This is a common headline, reminiscent of the Oracle-related breaches that have troubled corporate security teams throughout the year.

      Cl0p's claims are significant. They assert that they obtained approximately 89GB of data from Shell, which includes technical drawings, facility images, test report scans, and project plans. From Philips, they allege to have taken around 13.5GB, primarily consisting of diagrams and blueprints. Other companies mentioned in the reports include GE and the financial technology firm Fiserv.

      Cl0p’s tactics differ from traditional ransomware that typically locks files. Instead, they engage in data-theft extortion: discreetly stealing files and then coercing victims to pay by threatening to publish the data on leak sites. This method of extortion through embarrassment has proven profitable.

      Recent events illustrate how this strategy unfolds. In the 2023 MOVEit mass hack, Cl0p exploited a single vulnerability in file transfer systems, impacting hundreds of organizations over several months as new victims emerged. When Shell refused to negotiate during that incident, the group published the stolen data, highlighting the seriousness of their leak threats.

      This current campaign differs from standard extortion efforts due to the suspected method of entry. Several security firms and sources have linked these attacks to a zero-day vulnerability in Oracle’s E-Business Suite—a widely used enterprise software for finance, procurement, and operations. While researchers have reported this connection, it has not been confirmed by the affected companies, and neither Shell nor Philips has disclosed how the breaches occurred, so this information should be considered strong reporting rather than established fact.

      If this link holds true, the process is chillingly effective. Instead of targeting companies individually, Cl0p may have discovered a flaw in software utilized by numerous large firms and exploited that to access them all simultaneously. This strategy mirrors the tactics used during the MOVEit incident, where a zero-day vulnerability in a shared tool proved highly valuable.

      The affected companies are maintaining a low profile regarding the situation. Shell has acknowledged being "aware of a potential incident" and is investigating, a statement that neither confirms nor denies a breach. Philips was slightly more forthcoming, noting “an attempted cyberattack on a specific company server containing internal data” that has been “brought under control,” indicating “no impact on customer environments.”

      The claim that nearly 50 firms are involved is currently a statement from Cl0p, and extortion groups are not known for their accuracy. There is a motive for the group to exaggerate the number of victims to increase pressure on the identified companies and enhance their standing within the criminal community, which they hope will continue to seek stolen access.

      Regardless, the implications should alarm any executive. Affected organizations—including an oil company, a medical device manufacturer, an industrial conglomerate, and a payments firm—indicate that the attackers do not discriminate based on industry. Instead, they focus on the software in use, which poses a more significant challenge for defense, reminiscent of the leak-site tactics seen with the 45GB data dump from Madison Square Garden.

      This presents a troubling lesson. As more companies standardize on the same enterprise platform, a single shared supplier risks becoming a common point of failure for all users, and no amount of internal security investment can entirely seal vulnerabilities in external code.

Other articles

Cl0p asserts that they have conducted a major hack involving Shell, Philips, and numerous other companies.

The ransomware group Cl0p, which has links to Russia, claims to have stolen data from Shell, Philips, and many other companies in a campaign that researchers attribute to a vulnerability in Oracle software.