Cyber Incident Victim: Shell
Timeline
Summary
A hacking group known as Cl0p claimed to have stolen large volumes of data from dozens of companies worldwide, including Philips, Shell, Fiserv and GE. The company said it was aware of a possible incident and was working with its security teams and experts to investigate. Philips reported that it had identified and contained an attempted compromise of an internal enterprise server, noting that customer environments were not affected. Fiserv stated that, based on its review, it found no evidence that customer, banking, transaction or personal data had been compromised. GE said it had activated its cyber response protocols and was assessing the potential issue. The group allegedly exploited vulnerabilities in PTC Windchill and FlexPLM software, a fact highlighted by an industry information sharing notice. Independent verification of the hackers’ claims has not been obtained.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On August 14, 2026, a hacking group identified as Cl0p posted on its website claiming to have stolen large volumes of data from nearly 50 companies worldwide, naming Philips, Shell, Fiserv, and GE among the victims. The group’s post asserted a mass data theft campaign affecting dozens of organizations across various sectors. Shell confirmed awareness of a recent "possible incident," noting that it aligned with an earlier report from Dutch media outlet BNR. A Shell spokesperson stated that the company was working with its security teams and relevant experts to investigate the situation. The hacking group did not respond to a request for comment on its claims.

Philips reported that it had identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data, emphasizing that the incident did not impact customer environments. Fiserv said it had reviewed the threat actor's claims and found no evidence that customer, banking, transaction, or personal data had been compromised, nor that its operating environment had been affected. GE indicated that it had initiated its cyber response protocols and was working to assess the potential issue. Reuters could not independently verify the hacking group's assertions regarding the type or volume of data allegedly taken.
While the exact method used by the attackers to access the companies remains unclear, Ransom-ISAC issued a notice on July 22, 2026 warning that the hacking group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used in engineering and manufacturing processes. PTC had previously issued multiple security notices dating to June 18, urging customers to apply a patch for a vulnerability and sharing details about an unnamed attacker targeting its products. Brandon Parsons, threat intelligence manager with Ascent Solutions and author of the Ransom-ISAC advisory, noted that some companies began receiving notices from Cl0p on July 19 or July 20 and described the group as focusing on zero‑day vulnerabilities in key software packages rather than specific organizations. The advisory characterized the actors as professional data extortionists who target previously unknown bugs for which vendors have not yet released patches.
