started · updated
Cl0p hacking group claims mass data theft from Shell and Philips
The Cl0p ransomware group has claimed responsibility for a massive cyberattack targeting nearly 50 companies worldwide, including major corporations such as Shell, Philips, Fiserv, and GE.
Cl0p alleges it has stolen significant volumes of data. Specifically, the group claims to have exfiltrated approximately 89 gigabytes of data from Shell, including engineering drawings, facility photos, and project plans. For Philips, the group claims to have stolen roughly 13.5 gigabytes of data, including blueprints and technical diagrams.
Philips confirmed it identified and contained an attempted compromise of an enterprise server containing internal data, though it stated the incident did not affect customer environments. Shell acknowledged a “possible incident” and is currently investigating the matter alongside security experts. Fiserv and GE have also stated they are aware of the claims and are conducting reviews or implementing response protocols; Fiserv reported finding no evidence of compromised customer or personal data.
Industry reports suggest the attacks may be linked to vulnerabilities in PTC Windchill and FlexPLM software. While the group has made extensive claims, independent verification of the stolen data volumes and contents has not yet been established.
Entities
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 14 SOURCES] Cl0p claims to have stolen approximately 89 gigabytes of data from Shell, including engineering drawings and project plans. wixx.com · wkzo.com · wtvbam.com · mix929.com · lajornadasanluis.com.mx · +9 more
- [● 14 SOURCES] Shell is aware of a possible recent security incident and is investigating with security teams. wixx.com · wkzo.com · wtvbam.com · mix929.com · lajornadasanluis.com.mx · +9 more
- [● 11 SOURCES] The hacking group Cl0p targeted Philips and Shell. wixx.com · wkzo.com · wtvbam.com · mix929.com · lajornadasanluis.com.mx · +6 more
- [● 14 SOURCES] Philips identified and contained an attempted compromise of an enterprise server containing internal data. wixx.com · wkzo.com · wtvbam.com · mix929.com · lajornadasanluis.com.mx · +9 more
- [● 14 SOURCES] The cybersecurity incident at Philips does not affect customer environments. wixx.com · wkzo.com · wtvbam.com · mix929.com · lajornadasanluis.com.mx · +9 more
- [● 14 SOURCES] Cl0p claims to have stolen approximately 13.5 gigabytes of data from Philips, including blueprints and diagrams. wixx.com · wkzo.com · wtvbam.com · mix929.com · lajornadasanluis.com.mx · +9 more
- [● 3 SOURCES] The group may be exploiting vulnerabilities in PTC Windchill and FlexPLM software. lajornadasanluis.com.mx · datafloq.com · www.bizcommunity.com
- [● 5 SOURCES] The Cl0p hacking group claims to have targeted nearly 50 companies globally. www.aljazeera.net · lajornadasanluis.com.mx · datafloq.com · www.tunisiaonlinenews.com · www.bizcommunity.com
- [● 4 SOURCES] Fiserv reported finding no evidence of compromised customer, banking, or personal data. www.aljazeera.net · lajornadasanluis.com.mx · datafloq.com · www.bizcommunity.com