Russian ransomware group Clop has claimed responsibility for cyberattacks targeting energy company Shell and healthcare technology company Philips, with claims emerging that data was obtained from both companies. Shell has acknowledged a potential incident and launched an investigation, while Philips said an attempted cyberattack affected a specific company server containing internal data.
The extent of any damage remains unclear. Both companies confirmed experiencing security incidents after reports emerged about the ransomware group’s claims. The information attributed to the hackers, including the volume and nature of allegedly stolen data, has not been independently verified.
Shell Investigates Potential Incident as Clop Claims 89GB of Data
Shell said it was aware of a potential incident and that an investigation was under way with its security teams and relevant experts.
Clop has claimed that it obtained 89 gigabytes of Shell data. The allegedly stolen material is said to include technical drawings, images of company facilities, test report scans and project plans.
The ransomware group is known for targeting businesses and attempting to obtain sensitive information that can subsequently be used to pressure victims into paying a ransom.
This is not the first time Shell has been targeted by Clop. The ransomware group also targeted the company in 2023 during the large-scale exploitation of a vulnerability involving the MOVEit Transfer platform.
Shell confirmed at the time that it had been affected. After the company refused to engage or pay, Clop placed Shell on its dark web leak site and began publishing allegedly stolen files.
Philips Says Attack Was Contained to One Server
Philips described the latest incident as an attempted cyberattack targeting a specific company server containing internal data.
The healthcare technology company said the incident had been brought under control and had not affected customer environments.
Clop has separately claimed to have obtained 13.5 gigabytes of data from Philips. The files allegedly include diagrams and blueprints.
However, the information about the alleged Philips data comes directly from the hackers and has not been independently verified. The available information does not establish whether all the material claimed by the ransomware group was actually obtained or whether the reported volume of data is accurate.
Claims Remain Unverified as Investigations Continue
The incidents highlight the continuing use of data theft as a pressure tactic in ransomware operations. Rather than relying solely on encrypting systems, ransomware groups can seek sensitive corporate information and threaten its disclosure as leverage against targeted organisations.
In Shell’s case, the company has said only that it is investigating a potential incident. Philips has provided more detail, confirming an attempted attack on an internal server while saying that customer environments were unaffected.
The precise scope of the latest attacks and the validity of Clop’s data theft claims remain uncertain. The alleged figures of 89 gigabytes from Shell and 13.5 gigabytes from Philips should therefore be treated as claims by the ransomware group rather than independently established facts.
