On August 14, 2026, the world faced another major cyber incident linked to the activities of the Russian-speaking hacking group Cl0p (Cl0P). The attackers claimed to have stolen large volumes of data from nearly 50 companies worldwide, including giants such as Philips, Shell, Fiserv, and General Electric (GE). According to experts, the attack was made possible by exploiting vulnerabilities in popular corporate software.
Scale of the Attack and Company Responses
The Cl0p group, known for its financially motivated attacks, published a list of victims that included companies from various economic sectors. Philips, the Dutch technology giant, confirmed the fact of a cyberattack attempt. In a company statement, it was noted that an attempt to compromise a specific corporate server related to internal data was detected and contained. Philips assured that the client environment was not affected, although details of the incident remain under review.
Shell, one of the largest oil and gas companies in the world, also reported a possible cyber incident. A company representative stated that cybersecurity specialists and external experts are conducting an investigation. So far, Shell has not confirmed a data breach but acknowledged that the situation requires careful analysis.
Fiserv, an American financial company, stated that it is aware of the hackers' claims but has not yet found signs of compromise of customer data, banking and payment information, or personal data. According to Fiserv representatives, their operational environment was not affected, although the company continues to monitor the situation.
Vulnerabilities in Software
According to Reuters, Cl0p may have exploited vulnerabilities in PTC Windchill and FlexPLM software, which are used in design and manufacturing processes. These vulnerabilities were previously known to cybersecurity specialists. The Ransom-ISAC industry group had warned about the exploitation of these vulnerabilities as early as July 22. PTC also published security advisories urging customers to install relevant updates.
Brandon Parsons, a cyber threat analyst and author of the Ransom-ISAC warning, reported that some companies began receiving messages from Cl0p on July 19 or 20. According to him, the group focuses not on specific companies but on vulnerabilities in popular software. Parsons described Cl0p as "professional data extortionists."
Contradictory Data
Reuters could not independently verify Cl0p's claims regarding exactly which data may have been stolen and in what volume. The hackers themselves did not respond to the agency's request. This creates uncertainty in assessing the scale of the incident. On one hand, companies claim that attacks have been contained and there is no damage to clients. On the other hand, hackers claim to have stolen large volumes of data. The discrepancies between the versions of the parties require further investigation and fact-checking.
Context and Previous Cl0p Attacks
Cl0p (also Cl0P) is a Russian-speaking cybercriminal group specializing in data theft and extortion. The Canadian Centre for Cyber Security assesses it as a financially motivated group, likely based in one of the CIS countries; the group is linked to the TA505/FIN11 cluster. Cl0p has repeatedly carried out large-scale attacks due to vulnerabilities in popular corporate software, specifically MOVEit. Western cybersecurity experts link the group's activities to the Russian-speaking cybercriminal environment.
Recall that recently, Russian hackers launched a global cyber campaign aimed at hacking Signal and WhatsApp messenger accounts. It was also reported that Russian hackers breached British military bases and stole secret documents. These events highlight the growing threat from cybercriminal groups linked to Russia.
Conclusion
The large-scale Cl0p cyberattack on Philips, Shell, GE, and other companies served as another reminder of the importance of cybersecurity in the modern world. Companies must be prepared for such threats and regularly update their software. At the same time, independent investigations and fact-checking remain critically important for understanding the real scale of the incident.