Cl0p Claims Mass Hack of Shell, Philips, and Dozens More
August 14, 2026 – 7:33 am
The Russia-linked ransomware group Cl0p has claimed a fresh wave of cyberattacks, targeting prominent companies like Shell and Philips, and potentially involving nearly 50 organizations.
The group’s unique extortion model involves quietly stealing large amounts of data and then threatening to expose it unless ransom is paid. This strategy has proven lucrative in the past, as seen during the 2023 MOVEit mass hack.
Cl0p alleges it stole approximately 89GB of data from Shell, including technical drawings, images, scans, and project plans. Philips, on the other hand, had around 13.5GB of diagrams and blueprints taken. Other companies reportedly affected include GE and Fiserv.
What makes this campaign noteworthy is the suspected method of infiltration: a zero-day vulnerability in Oracle’s E-Business Suite, a widely used enterprise software for financial, procurement, and operational tasks. While this has not been confirmed by victims, several security firms and outlets have reported on this link.
If validated, this approach would explain how Cl0p compromised numerous companies simultaneously by exploiting a single flaw in shared software. This is similar to their strategy during the MOVEit hack.
Victims are maintaining a cautious silence, with Shell stating they are "aware of a potential incident" and Philips describing an "attempted cyberattack" that has been contained without impacting customer environments. However, Cl0p claims to have compromised close to 50 firms, raising concerns among executives across various industries.