Cyberattack: Massive Data Breach Hits Shell, Philips, and Nearly 50 Companies

Written by: Adel Khelifi on August 15, 2026

An important group of cybercriminals claims to have stolen large quantities of data belonging to nearly 50 companies worldwide, among which are international groups such as Shell, Philips, Fiserv and GE.

The claim comes from Cl0p, a group specialized in exploiting vulnerabilities present in software widely used by companies. Unlike an attack targeting a single company, this method allows criminals to compromise simultaneously a large number of organizations using the same vulnerable tool. Reuters says it has not been able to independently verify the nature or volume of the data that Cl0p claims to have recovered.

Several of the cited companies have nonetheless confirmed they are investigating incidents or intrusion attempts.

Philips confirms an intrusion attempt

The Dutch group Philips has confirmed it was targeted by Cl0p.

The company says it detected and contained a compromise attempt aimed at a specific server containing internal data.

Philips however assures that the incident did not affect its customers’ environments. The company has not publicly confirmed the extent of the data the attackers claim to have recovered.

Cl0p, for its part, says it obtained about 13.5 gigabytes of Philips-related data, including schemas and technical documents. This volume remains a claim by the group and has not been independently verified.

Shell investigating a “potential incident”

The oil giant Shell also said it was aware of a recent “potential incident,” confirming an investigation was ongoing.

“We are working with our security teams and the relevant experts to verify the situation,” a group spokesperson told Reuters.

Cl0p claims to have extracted about 89 gigabytes of Shell data. According to information published around the group’s claim, the files in question could include technical drawings, photographs of facilities, test reports, and documents relating to various projects.

Again, Shell has not confirmed that these 89 GB were actually stolen, and no independent verification currently allows validating the content announced by the attackers.

Fiserv: no banking data compromised at this stage

Fiserv, an American group specializing in technologies and financial services, also appears on the list released by Cl0p.

The company says it conducted a thorough analysis of the allegations and notes that at this stage there are no signs indicating a compromise of its customers’ data, banking information, transactions or personal data.

Fiserv also asserts that its operational environment does not seem to have been affected.

This clarification is particularly important given the nature of the group’s activities, which provide payment technologies and various services to financial institutions.

GE triggers its response procedures

GE has, for its part, confirmed awareness of the claims by the hacker group.

A spokesperson said the company had triggered its cyber incident response protocols and is now looking to determine the reality and extent of any potential issue.

At this stage, no major operational consequences have been publicly announced by the four major groups cited.

A common vulnerability could explain the wave of attacks

One of the main leads concerns vulnerabilities in PTC’s Windchill and FlexPLM software, used notably in engineering, design, and manufacturing sectors.

The information-sharing group specialized in Ransom-ISAC had issued on July 22 an alert indicating that Cl0p was exploiting vulnerabilities in these solutions. PTC itself had published several security advisories since June 18, urging its customers to install patches.

This type of attack is particularly worrisome: instead of trying to break into one company after another, a criminal group looks for a flaw in software used by dozens or hundreds of companies, then searches for vulnerable servers before patches are applied.

Cl0p has previously distinguished itself with such massive campaigns against enterprise software.

Cl0p, a group active for several years

Cl0p, sometimes written Cl0p or Clop, is a Russian-speaking cybercriminal group active for several years and known for targeting large companies.

According to Ukrainska Pravda, its activity dates back at least to early 2019 and the group would operate mainly from Russia and other territories of the former Soviet Union.

The group is notably associated with a strategy of data extortion.

The attackers seek to penetrate the IT systems of an organization, extract confidential information, then apply pressure on the victim by threatening to release these data if they refuse to pay.

This strategy is often described as “double extortion” when it combines blocking or disruption of systems with data theft and the threat of publication.

A spectacular claim, but still to be confirmed

Prudence remains essential.

The fact that Philips confirmed an intrusion attempt, that Shell is investigating a potential incident, and that GE has activated its response procedures shows that the campaign claimed by Cl0p is taken seriously by the companies involved.

This does not, however, mean that all the claims published by the group are established.

Reuters notes that it has not been able to independently verify the type of data allegedly stolen, their volume or the reality of all the compromises announced. The attackers have furthermore not responded to the agency’s requests for comment.

The case underscores, above all, a shift that has become central to the cybersecurity of large corporations: one vulnerability in shared software can allow a group of attackers to target dozens of organizations worldwide simultaneously.

For Shell, Philips, GE, Fiserv and the other cited companies, investigations must now determine whether the cybercriminals have actually managed to exfiltrate the data volumes they claim and, above all, the sensitivity of the information possibly compromised.




Adel Khelifi

Adel Khelifi

My name is Adel Khelifi, and I’m a journalist based in Tunis with a passion for telling local stories to a global audience. I cover current affairs, culture, and social issues with a focus on clarity and context. I believe journalism should connect people, not just inform them.