Menu
Browse

Cyber Incident Victim: Shell

Date

Jul 2026

Location

United Kingdom

Status

Unknown

Updated

2026-08-14 16:30

Timeline
Occurred
Undetermined
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

A hacking group known as Cl0p claimed to have stolen large volumes of data from dozens of companies worldwide, including Philips, Shell, Fiserv and GE. The company said it was aware of a possible incident and was working with its security teams and experts to investigate. Philips reported that it had identified and contained an attempted compromise of an internal enterprise server, noting that customer environments were not affected. Fiserv stated that, based on its review, it found no evidence that customer, banking, transaction or personal data had been compromised. GE said it had activated its cyber response protocols and was assessing the potential issue. The group allegedly exploited vulnerabilities in PTC Windchill and FlexPLM software, a fact highlighted by an industry information sharing notice. Independent verification of the hackers’ claims has not been obtained.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On August 14, 2026, a hacking group identified as Cl0p posted on its website claiming to have stolen large volumes of data from nearly 50 companies worldwide, naming Philips, Shell, Fiserv, and GE among the victims. The group’s post asserted a mass data theft campaign affecting dozens of organizations across various sectors. Shell confirmed awareness of a recent "possible incident," noting that it aligned with an earlier report from Dutch media outlet BNR. A Shell spokesperson stated that the company was working with its security teams and relevant experts to investigate the situation. The hacking group did not respond to a request for comment on its claims.

Cyber Incident Image

Philips reported that it had identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data, emphasizing that the incident did not impact customer environments. Fiserv said it had reviewed the threat actor's claims and found no evidence that customer, banking, transaction, or personal data had been compromised, nor that its operating environment had been affected. GE indicated that it had initiated its cyber response protocols and was working to assess the potential issue. Reuters could not independently verify the hacking group's assertions regarding the type or volume of data allegedly taken.

While the exact method used by the attackers to access the companies remains unclear, Ransom-ISAC issued a notice on July 22, 2026 warning that the hacking group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used in engineering and manufacturing processes. PTC had previously issued multiple security notices dating to June 18, urging customers to apply a patch for a vulnerability and sharing details about an unnamed attacker targeting its products. Brandon Parsons, threat intelligence manager with Ascent Solutions and author of the Ransom-ISAC advisory, noted that some companies began receiving notices from Cl0p on July 19 or July 20 and described the group as focusing on zero‑day vulnerabilities in key software packages rather than specific organizations. The advisory characterized the actors as professional data extortionists who target previously unknown bugs for which vendors have not yet released patches.

Sources
Sources available to members
1 source