Russian hackers claim to have stolen data from Shell, Philips and nearly 50 other companies

illustrative, hacker / Getty Images
Фото: illustrative, hacker / Getty Images

A Russia-linked hacking group Cl0p claimed to have stolen large amounts of internal data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE. The attackers published information about their likely victims on their own website.

Philips confirmed that it was targeted by Cl0p. The company said it detected and localized an attempt to compromise a separate corporate server related to internal data. According to the company, customer environments were not affected by the incident. Shell said it is aware of a "possible incident" and is investigating together with its cybersecurity specialists.

Cl0p claims to have obtained about 89 GB of Shell data, allegedly including engineering drawings, photos of facilities, test reports and project plans. In the case of Philips, the group claimed about 13.5 GB of stolen files, including drawings, diagrams and technical documentation. There is no independent confirmation of these amounts.

Fiserv said it checked the hackers' claims and has so far found no evidence of compromise of customer, banking, transactional or personal data or impact on its operational infrastructure. GE is also aware of Cl0p's claim and has initiated internal cyber response procedures to assess the possible incident.

The new Cl0p campaign may be related to attacks on corporate platforms PTC Windchill and FlexPLM, which are used for product lifecycle management in industrial, engineering, medical and other sectors. In July, BleepingComputer reported that Cl0p is exploiting a critical vulnerability CVE-2026-12569 in these systems. It allows remote code execution on vulnerable servers and theft of confidential data.

Cl0p is known for large-scale campaigns in which attackers seek vulnerabilities in popular enterprise software and simultaneously attack a large number of its users. The group has previously used similar tactics in attacks on MOVEit Transfer, GoAnywhere and other corporate platforms.

Based on materials from: Reuters, Investing.com, BleepingComputer

analytics