Skip to content
Cl0p Hackers Claim Data Theft from Nearly 50 Companies Including Shell, Philips, GE and Fiserv

Cl0p Hackers Claim Data Theft from Nearly 50 Companies Including Shell, Philips, GE and Fiserv

Infotechlead • August 14, 2026

The Cl0p hacking group has claimed it stole large volumes of corporate data from nearly 50 companies worldwide, including energy major Shell, health-technology company Philips, industrial group GE and financial-technology provider Fiserv.

The alleged global cyberattack campaign has exploited vulnerabilities in widely used engineering and manufacturing software, enabling the attackers to target numerous organisations simultaneously. However, the scale and nature of the claimed data theft have not been independently verified, media reports said.

Shell Investigates Possible Cybersecurity Incident

Shell confirmed that it was aware of a recent possible cybersecurity incident and had started working with its security teams and relevant external experts to investigate.

Cl0p reportedly claimed it obtained approximately 89 gigabytes of Shell data, potentially including engineering drawings, facility photographs, scanned testing reports and project plans. Shell has not confirmed that this information was stolen.

Philips Contains Attempted Server Compromise

Philips confirmed that it had been targeted by Cl0p but described the event as an attempted cybersecurity compromise affecting a specific enterprise server containing internal information.

The company said it had identified and contained the incident and stressed that customer environments were not affected.

Cl0p reportedly claimed it stole approximately 13.5 gigabytes of Philips data, including PDF drawings, diagrams and blueprints. The company has not verified the hacking group’s description of the alleged stolen information.

Fiserv Finds No Evidence of Customer Data Theft

Fiserv said it was aware of Cl0p’s allegations but had found no evidence that customer, banking, transaction, personal or operational data had been compromised.

The financial-technology company reached that conclusion following a comprehensive review conducted after learning of the threat actor’s claims. Fiserv also found no evidence that its operating environment had been affected.

GE confirmed that it was aware of the hacking group’s allegations. The company activated its cybersecurity response procedures and began assessing the potential incident.

PTC Software Vulnerabilities Under Investigation

The precise method used to access the targeted companies remains unclear. However, information-sharing organisation Ransom-ISAC issued an alert on July 22 warning that Cl0p was exploiting vulnerabilities in PTC Windchill and FlexPLM.

Windchill and FlexPLM are used by companies to support engineering, product-development and manufacturing processes. A vulnerability affecting these platforms could therefore expose multiple organisations across several industries through a common technology supplier.

PTC had published multiple security advisories dating back to June 18. The notices urged customers to install a security patch addressing a vulnerability and provided information an unidentified attacker targeting its products.

Companies Received Cl0p Notices from July 19

Some affected organisations began receiving notices from Cl0p on July 19 or July 20, according to Brandon Parsons, threat intelligence manager at Ascent Solutions and author of the Ransom-ISAC advisory.

Parsons described Cl0p as a professional data-extortion operation that targets vulnerabilities in important software platforms rather than selecting individual companies in advance.

This strategy allows the group to compromise numerous users of the same vulnerable product. Cl0p typically searches for zero-day vulnerabilities — previously unknown security defects for which vendors may not yet have released patches — and uses them to launch attacks across multiple organisations.

Scale of Cl0p Data Theft Remains Unverified

Cl0p did not respond to a request for information the campaign. The group’s claims concerning the type and volume of data allegedly stolen from nearly 50 companies also remain unverified, Reuters news report said.

Shell, Philips, GE and Fiserv have all launched assessments or reviewed the allegations, but none has confirmed the full scale of data theft claimed by Cl0p.

The incident demonstrates how a vulnerability in a shared enterprise software platform can potentially expose dozens of major organisations simultaneously. It also reinforces the importance of installing vendor security patches quickly, particularly for engineering and manufacturing systems containing sensitive intellectual property and operational information.

Extracted Entities

Attack Types (1)

Companies (4)

Platforms (2)

Ransomware Groups (1)