Published Product3 min read
Cl0p claims 89GB from Shell, and the loss is drawings, not downtime
The group says it took technical drawings and test reports from Shell and blueprints from Philips, and has named close to 50 organisations. Nothing was encrypted, and nothing can be restored.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Cl0p, described as a Russia-linked ransomware group, claimed a fresh wave of cyberattacks naming Shell and Philips among its victims, and by some counts close to 50 companies.
- Cl0p claims to have taken roughly 89GB of material from Shell, including technical drawings, images of facilities, scans of test reports, and project plans.
- Cl0p says it took about 13.5GB from Philips, mostly diagrams and blueprints.
- Other names circulating in coverage of the campaign include GE and the financial-technology firm Fiserv.
- Cl0p favours data-theft extortion rather than file-encrypting ransomware: it steals files quietly, then pressures victims to pay by threatening to dump everything on a leak site.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Cl0p has claimed a fresh wave of intrusions, naming Shell and Philips and, by some counts, dragging close to 50 companies into it [1]. The interesting number is not the victim count but the contents: roughly 89GB from Shell, described as technical drawings, images of facilities, scans of test reports and project plans, and about 13.5GB from Philips, mostly diagrams and blueprints [2][3].
Nothing in that description is a locked server. Cl0p's model is data-theft extortion rather than the lock-up-your-files variety: take the files quietly, then press for payment by threatening to publish everything on a leak site [5]. That distinction changes which part of the business is exposed. An encrypted file server is an availability problem, and availability problems have owners, runbooks and recovery time objectives. A scanned test report and a facility layout are neither encrypted nor recoverable in any meaningful sense, because they were never taken away. They were copied, and the only remedy on offer is a payment that buys a promise.
There is precedent for how seriously to treat that promise. During the 2023 MOVEit campaign, Cl0p breached hundreds of organisations through a single file-transfer flaw, with new victims surfacing for months afterwards [6]. Shell declined to negotiate then, and the group published its data [7]. Whatever the merits of not paying, the outcome was publication.
The suspected route in this round is a zero-day in Oracle's E-Business Suite, the finance, procurement and operations software large firms run, a link drawn by several security firms and outlets [8]. That attribution comes from researchers, not from the victims; neither Shell nor Philips has said how it was breached [9]. Shell has said only that it is "aware of a potential incident" and is investigating [10]. Philips described "an attempted cyberattack on a specific company server containing internal data" that has been "brought under control," with "no impact on customer environments" [11]. The publisher notes the episode reads as a rerun of the Oracle-linked breaches that have occupied corporate security teams for much of the year [16].
Discount the headcount. The figure near 50 is Cl0p's own claim, and the group has reasons to inflate it: pressure on the named, and standing with the criminal market it sells stolen access to [12]. GE and the payments firm Fiserv are also circulating in coverage [4]. The volumes are worth sizing against a familiar benchmark: the Shell claim is about twice the 45GB dump that generated the Madison Square Garden leak-site theatrics [13][15], and roughly six and a half times what Cl0p says it took from Philips [14].
The composition of the victim list is the operational point. A set spanning an oil major, a medical-devices maker, an industrial conglomerate and a payments firm is not the work of a crew selecting by sector; it is a crew selecting by shared software [17].
Watch three things. Whether the named list grows over months, as MOVEit's did, which would indicate harvesting from a common platform rather than a handful of targeted intrusions [6]. Whether any victim confirms the Oracle E-Business Suite vector, which none has so far [9]. And whether firms that hold engineering documentation in enterprise systems start treating drawings and test reports as a regulated data class with retention limits, rather than as inert attachments that sit in procurement and finance forever [2][3].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cl0p, described as a Russia-linked ransomware group, claimed a fresh wave of cyberattacks naming Shell and Philips among its victims, and by some counts close to 50 companies.
- [2]
Cl0p claims to have taken roughly 89GB of material from Shell, including technical drawings, images of facilities, scans of test reports, and project plans.
- [3]
Cl0p says it took about 13.5GB from Philips, mostly diagrams and blueprints.
- [4]
Other names circulating in coverage of the campaign include GE and the financial-technology firm Fiserv.
- [5]
Cl0p favours data-theft extortion rather than file-encrypting ransomware: it steals files quietly, then pressures victims to pay by threatening to dump everything on a leak site.
- [6]
During the 2023 MOVEit mass hack, Cl0p breached hundreds of organisations through a single file-transfer flaw, and the fallout continued for months as new victims kept surfacing.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- thenextweb.comAna-Maria StanciucAug 14Cl0p claims a mass hack of Shell, Philips, and dozens more
Cited in this coverage: thenextweb.com
Cited in this coverage: thenextweb.com, reporting Cl0p's claim
Cited in this coverage: security firms and outlets, per thenextweb.com
Cited in this coverage: Shell, via thenextweb.com
Cited in this coverage: Philips, via thenextweb.com



