Clop Ransomware Group Claims Attacks on Shell and Philips
The Russian ransomware group Clop has taken responsibility for recent cyberattacks on energy giant Shell and healthcare technology firm Philips. Both companies confirmed experiencing security incidents following reports of the claims.
Shell acknowledged a "potential incident" and stated that an investigation is underway with security teams and external experts. Philips described the attack as an "attempted cyberattack on a specific company server containing internal data," adding that the situation has been contained with no impact on customer environments.
Clop, known for extorting victims by stealing sensitive data, allegedly exfiltrated 89 gigabytes of Shell’s data, including technical drawings, facility images, test reports, and project plans. The group also claims to have obtained 13.5 gigabytes of Philips’ data, containing diagrams and blueprints. However, these claims sourced from the hackers themselves remain unverified by independent parties.
This is not the first time Clop has targeted Shell. In 2023, the group exploited a vulnerability in the MOVEit Transfer file-sharing software, breaching Shell and multiple other organizations. After Shell refused to pay a ransom, Clop publicly leaked stolen files on its dark web leak site.
The full extent of the damage from the latest attacks is still under investigation.
Source: https://nltimes.nl/2026/08/13/russian-ransomware-group-clop-claims-cyberattacks-shell-philips
Philips TPRM report: https://www.rankiteo.com/company/philips
Shell TPRM report: https://www.rankiteo.com/company/shell
"id": "phishe1786703569",
"linkid": "philips, shell",
"type": "Ransomware",
"date": "8/2026",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Energy',
'name': 'Shell',
'type': 'Corporation'},
{'customers_affected': 'No impact on customer '
'environments',
'industry': 'Healthcare Technology',
'name': 'Philips',
'type': 'Corporation'}],
'attack_vector': 'Exploitation of vulnerability (MOVEit Transfer file-sharing '
'software in prior attack)',
'customer_advisories': 'No impact on customer environments (Philips)',
'data_breach': {'data_exfiltration': 'Yes (89 GB from Shell, 13.5 GB from '
'Philips)',
'sensitivity_of_data': 'High (internal data, proprietary '
'information)',
'type_of_data_compromised': ['Technical drawings',
'Facility images',
'Test reports',
'Project plans',
'Diagrams',
'Blueprints']},
'description': 'The Russian ransomware group Clop has taken responsibility '
'for recent cyberattacks on energy giant Shell and healthcare '
'technology firm Philips. Both companies confirmed '
'experiencing security incidents following reports of the '
'claims. Clop allegedly exfiltrated 89 gigabytes of Shell’s '
'data and 13.5 gigabytes of Philips’ data, including technical '
'drawings, facility images, test reports, project plans, '
'diagrams, and blueprints.',
'impact': {'data_compromised': '89 GB (Shell), 13.5 GB (Philips)',
'operational_impact': 'Contained (Philips), under investigation '
'(Shell)',
'systems_affected': 'Specific company servers (Philips), '
'unspecified systems (Shell)'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion, Data Theft',
'ransomware': {'data_exfiltration': 'Yes',
'ransom_paid': 'No (Shell in prior incident)',
'ransomware_strain': 'Clop'},
'references': [{'source': 'Clop Ransomware Group Claims'}],
'response': {'containment_measures': 'Yes (Philips: situation contained)',
'incident_response_plan_activated': 'Yes (both companies)',
'third_party_assistance': 'Yes (Shell: external experts)'},
'threat_actor': 'Clop Ransomware Group',
'title': 'Clop Ransomware Group Claims Attacks on Shell and Philips',
'type': 'Ransomware',
'vulnerability_exploited': 'MOVEit Transfer file-sharing software '
'vulnerability (prior incident)'}