Skip to content
feed: live
>_ 0dayNews
ransomware
● Breaking

Clop Claims 89GB Shell Theft; Investigation Open

Shell confirms investigating a potential incident after Clop listed the oil giant on its extortion site, claiming 89GB of exfiltrated data. No breach confirmed; initial access vector undisclosed.

Clop Claims 89GB Shell Theft; Investigation Open
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgap airgap · Published · 2 min read

Shell confirmed it is investigating a “potential incident” after the Clop extortion group listed the oil and gas company on its data-leak site, claiming to have stolen 89 gigabytes of data.

Status

Shell investigating. Confirmed. The company acknowledged an inquiry in a statement reported by BleepingComputer. Shell has not confirmed unauthorized access — only that a potential incident is under review.

Clop’s 89GB claim. Unconfirmed. Clop listed Shell on its extortion portal with an 89-gigabyte figure. No data samples have been published as of this writing. That is consistent with the group’s standard hold-and-pressure cadence before a self-imposed publication deadline.

Initial access vector. Not disclosed. Shell has not confirmed how any access may have occurred. Clop has not specified an entry point or exploit chain in its initial listing.

Clop’s 2026 Campaign Context

The group is not a new actor. Clop ran the MOVEit file-transfer campaign in 2023, ultimately affecting over a thousand organizations. Their operational model has shifted toward pure data-theft extortion — no encryption, just exfiltration and staged exposure.

In July 2026, the group resumed active operations targeting PTC Windchill and FlexPLM product-lifecycle management environments via CVE-2026-12569, an unauthenticated remote code execution flaw. Shell operates large, complex enterprise IT environments across energy, logistics, and trading functions — whether today’s incident shares infrastructure or entry vector with the Windchill campaign is unconfirmed.

What’s Not Confirmed

  • The 89GB volume is Clop’s assertion. Not independently verified.
  • Whether the data is operational, employee, customer, or commercial in nature.
  • Whether a Shell subsidiary or joint-venture system rather than Shell corporate is the actual target.
  • Whether Clop has set an internal publication deadline and what that window is.

What to Watch

Clop’s documented pattern runs in stages: list the target, set a countdown, publish sample data, release the full dataset. Shell is at step one.

If Shell concludes unauthorized access occurred, a formal breach notification is likely within 72 hours under applicable regulatory frameworks. Whether CISA or the energy sector’s E-ISAC issues advisory guidance will signal how the incident is assessed beyond Shell’s own investigation.


Earlier Clop coverage: Clop Targets PTC Windchill and FlexPLM — July 2026 Campaign. Also developing: ShinyHunters Hits RingCentral, 1.6M Accounts Exposed — separate actor, same day.

Found this useful? Share it.