Prolific hacking group Cl0p has claimed it stole mass amounts of data from nearly 50 firms, including Shell, Philips, GE, and Fiserv.
The ransomware group, known for its exploitation of vulnerabilities, posted the claim on its website, with a range of responses from potentially impacted companies.
Philips has confirmed the attack, saying it was targeted by Cl0p, while Shell said that it was aware of a “possible incident” and it is currently investigating the situation.
“Philips has identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data,” the firm said in a statement, clarifying that customer environments have not been impacted in the incident.
Shell said that it is working with relevant experts and its security team to “investigate the situation.”
Over at Fiserv, the firm said that it is aware of the claims, but has yet to find any evidence of a breach “based on our comprehensive review to date.” The company said it found no evidence of compromise across its customer, transaction, banking, or personal data, or across its operations.
GE said that the firm is aware of the claim as well, and has “initiated our cyber response protocols and are working to assess the potential issue.”
The hacking claim has yet to be independently verified.
The Russian hacking group Cl0p is notable for its targeting of specific vulnerabilities rather than individual companies. It remains unclear how the ransomware group was able to allegedly hack into the various companies’ systems.
Recommended reading
- Data Theft Surges to 96% of Ransomware Attacks
- Comment | The Top Ways Attackers Infiltrate Systems Today
- Comment | The History of Ransomware
- Ransomware “Supergroups” Emerge After Record‑Breaking Year of Attacks
Cl0p claims that it stole 89 gigabytes of data from oil giant Shell, ranging from project plans, engineering drawings, and photos of facilities. Meanwhile, it said it stole 13.5 gigabytes worth of data from Philips, including blueprints, diagrams, and drawings.
Cl0p is perhaps most infamous for the 2023 MOVEit hack which exploited a file-transfer vulnerability to hack hundreds of firms, including Shell. The aftermath resulted in Shell refusing to pay a ransom or negotiate with the group, which subsequently leaked the oil firm’s stolen data.





