Philips and Shell: Russian ransomware group Clop claims cyberattacks on Shell and Philips

Philips and Shell: Russian ransomware group Clop claims cyberattacks on Shell and Philips

Clop Ransomware Group Claims Attacks on Shell and Philips

The Russian ransomware group Clop has taken responsibility for recent cyberattacks on energy giant Shell and healthcare technology firm Philips. Both companies confirmed experiencing security incidents following reports of the claims.

Shell acknowledged a "potential incident" and stated that an investigation is underway with security teams and external experts. Philips described the attack as an "attempted cyberattack on a specific company server containing internal data," adding that the situation has been contained with no impact on customer environments.

Clop, known for extorting victims by stealing sensitive data, allegedly exfiltrated 89 gigabytes of Shell’s data, including technical drawings, facility images, test reports, and project plans. The group also claims to have obtained 13.5 gigabytes of Philips’ data, containing diagrams and blueprints. However, these claims sourced from the hackers themselves remain unverified by independent parties.

This is not the first time Clop has targeted Shell. In 2023, the group exploited a vulnerability in the MOVEit Transfer file-sharing software, breaching Shell and multiple other organizations. After Shell refused to pay a ransom, Clop publicly leaked stolen files on its dark web leak site.

The full extent of the damage from the latest attacks is still under investigation.

Source: https://nltimes.nl/2026/08/13/russian-ransomware-group-clop-claims-cyberattacks-shell-philips

Philips TPRM report: https://www.rankiteo.com/company/philips

Shell TPRM report: https://www.rankiteo.com/company/shell

"id": "phishe1786703569",
"linkid": "philips, shell",
"type": "Ransomware",
"date": "8/2026",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Energy',
                        'name': 'Shell',
                        'type': 'Corporation'},
                       {'customers_affected': 'No impact on customer '
                                              'environments',
                        'industry': 'Healthcare Technology',
                        'name': 'Philips',
                        'type': 'Corporation'}],
 'attack_vector': 'Exploitation of vulnerability (MOVEit Transfer file-sharing '
                  'software in prior attack)',
 'customer_advisories': 'No impact on customer environments (Philips)',
 'data_breach': {'data_exfiltration': 'Yes (89 GB from Shell, 13.5 GB from '
                                      'Philips)',
                 'sensitivity_of_data': 'High (internal data, proprietary '
                                        'information)',
                 'type_of_data_compromised': ['Technical drawings',
                                              'Facility images',
                                              'Test reports',
                                              'Project plans',
                                              'Diagrams',
                                              'Blueprints']},
 'description': 'The Russian ransomware group Clop has taken responsibility '
                'for recent cyberattacks on energy giant Shell and healthcare '
                'technology firm Philips. Both companies confirmed '
                'experiencing security incidents following reports of the '
                'claims. Clop allegedly exfiltrated 89 gigabytes of Shell’s '
                'data and 13.5 gigabytes of Philips’ data, including technical '
                'drawings, facility images, test reports, project plans, '
                'diagrams, and blueprints.',
 'impact': {'data_compromised': '89 GB (Shell), 13.5 GB (Philips)',
            'operational_impact': 'Contained (Philips), under investigation '
                                  '(Shell)',
            'systems_affected': 'Specific company servers (Philips), '
                                'unspecified systems (Shell)'},
 'investigation_status': 'Ongoing',
 'motivation': 'Extortion, Data Theft',
 'ransomware': {'data_exfiltration': 'Yes',
                'ransom_paid': 'No (Shell in prior incident)',
                'ransomware_strain': 'Clop'},
 'references': [{'source': 'Clop Ransomware Group Claims'}],
 'response': {'containment_measures': 'Yes (Philips: situation contained)',
              'incident_response_plan_activated': 'Yes (both companies)',
              'third_party_assistance': 'Yes (Shell: external experts)'},
 'threat_actor': 'Clop Ransomware Group',
 'title': 'Clop Ransomware Group Claims Attacks on Shell and Philips',
 'type': 'Ransomware',
 'vulnerability_exploited': 'MOVEit Transfer file-sharing software '
                            'vulnerability (prior incident)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.