A Russia-linked hacking group called Cl0p has claimed responsibility for a sprawling Cl0p ransomware attack that reportedly hit some of the biggest names in global industry, including Shell, Philips, GE, and the payments firm Fiserv. According to reports published August 13, 2026, the group says it pulled data from close to 50 companies in total, though that figure comes from Cl0p itself and has not been independently verified.
Summary
Key takeaways
- Cl0p claims to have hit Shell, Philips, GE, Fiserv, and up to 50 companies in total, though the tally is unverified.
- The group says it stole roughly 89GB of data from Shell, including technical drawings, facility images, and project plans.
- From Philips, Cl0p claims to have taken about 13.5GB, mostly diagrams and blueprints.
- Security researchers have linked the spree to a suspected zero-day flaw in Oracle’s E-Business Suite, though this is reported, not confirmed.
- Shell says it is investigating a “potential incident,” while Philips confirmed an attempted breach that it says caused no impact on customers.
Cl0p’s Mass Cyberattack on Major Multinational Firms
Cl0p’s latest campaign looks less like a targeted heist and more like a wide net thrown across the corporate world. The group is known for large-scale data-theft campaigns, and this one follows a pattern that has become uncomfortably familiar since its 2023 rampage through the MOVEit file-transfer software, which compromised hundreds of organizations through a single shared flaw.
Targeted Companies and Data Stolen
Cl0p says it took approximately 89GB of material from Shell, including technical drawings, images of facilities, scans of test reports, and internal project plans. From Philips, the haul is smaller but still notable: roughly 13.5GB, described as mostly diagrams and blueprints. Other names surfacing in coverage of the campaign include GE and Fiserv, though the full scope of what, if anything, was taken from those two remains unclear.
Attack Methodology and Extortion Strategy
What separates Cl0p from older-style ransomware crews is the absence of file-locking altogether. Rather than encrypting systems and demanding a ransom to unlock them, Cl0p relies on data-theft extortion: quietly copying files, then threatening to publish them on a leak site unless the victim pays. It is extortion built on the fear of embarrassment rather than operational disruption, and the tactic has proven lucrative for the group in past campaigns. During the MOVEit incident, when Shell reportedly declined to negotiate, Cl0p simply published the stolen data, a precedent that gives its current threats added weight.
Suspected Oracle E-Business Suite Vulnerability as Attack Vector
Several security researchers and outlets have tied this wave of intrusions to a suspected zero-day vulnerability in Oracle’s E-Business Suite, a widely used enterprise platform that large companies rely on to manage finance, procurement, and day-to-day operations. That connection has been reported rather than confirmed by any of the named victims, and neither Shell nor Philips has publicly detailed how its systems were accessed.
If the Oracle link holds up, it would explain how a single crew managed to touch so many unrelated companies at once. Rather than chasing individual targets, Cl0p would have exploited one flaw in software that dozens of blue-chip firms happen to share, harvesting data from all of them in a coordinated sweep. It is the same efficient logic that made the MOVEit zero-day such a valuable find for the group three years ago.
Corporate Responses from Shell and Philips
Shell has offered a cautious response, saying it is “aware of a potential incident” and is currently investigating. That statement neither confirms a breach occurred nor rules one out, leaving the company’s actual exposure an open question.
Philips has been somewhat more specific. The company described “an attempted cyberattack on a specific company server containing internal data,” adding that the incident has been “brought under control” and that there has been “no impact on customer environments.” Neither company has disclosed how the intrusion happened or confirmed the volume of data Cl0p claims to have taken.
Implications of the Cl0p Campaign for Enterprise Security
Why does this matter beyond the companies named so far? Because the pattern points to a structural weakness rather than a series of isolated break-ins. When a large share of the corporate world runs the same enterprise software, one unpatched flaw can turn into a single point of failure for dozens of unrelated businesses at once, regardless of how much each individual firm spends on internal security.
There is also reason for caution about the numbers Cl0p is circulating. Extortion groups have a clear incentive to inflate victim counts, both to pressure the companies it has named and to boost its own standing among other criminal operators. Still, a claimed haul spanning an energy major, a medical-device maker, an industrial conglomerate, and a payments firm suggests a campaign built around a shared software dependency rather than any single company’s individual weaknesses. That is the harder problem for security teams to solve, because it depends on a supplier’s code rather than their own defenses.
For now, the response from the named companies remains limited to brief acknowledgments and internal reviews. Whether more victims come forward, or whether Cl0p follows through on its threat to leak the stolen files, will likely shape how seriously the broader tech industry treats the suspected Oracle E-Business Suite flaw in the weeks ahead.
FAQ
Which companies have been targeted by the Cl0p ransomware group in this recent attack?
Cl0p has claimed to have targeted Shell, Philips, GE, Fiserv, and close to 50 companies in total.
What type of data did Cl0p reportedly steal from Shell and Philips?
Cl0p reportedly stole about 89GB of data from Shell, including technical drawings, images, and test reports, and about 13.5GB from Philips, mostly diagrams and blueprints.
How does Cl0p’s ransomware extortion method work?
Cl0p uses data-theft extortion by quietly stealing files and then threatening to publicly leak them to pressure victims, instead of locking files with traditional ransomware.
What has been the official response from Shell and Philips regarding the incidents?
Shell acknowledged it is investigating a potential incident without confirming a breach, while Philips described the incident as an attempted cyberattack on a server that was brought under control with no impact on customer environments.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

