Cl0p Claims It Robbed Shell of 89GB. Shell Says "We're Looking."

Cl0p Claims It Robbed Shell of 89GB. Shell Says "We're Looking."

Ransomware gangs have never met a headline they didn't like, and Cl0p just added an oil supermajor to its trophy case. Whether the trophy is real is, as always with these groups, a separate question.

89 Gigabytes and a Very Public Accusation

The Cl0p ransomware group added Shell to its dark-web leak site, claiming to have exfiltrated roughly 89 GB of internal data including engineering drawings, facility photographs, project roadmaps, and testing reports. Shell says it's investigating but has not confirmed its systems were actually compromised, nor verified the authenticity, age, or scope of the data the gang is advertising — and reports no disruption to refineries, drilling, production networks, or core IT systems.

Shell isn't alone: Cl0p has tied the claim to a wider campaign hitting 43 newly listed victims, all linked to internet-exposed PTC Windchill and FlexPLM systems rather than a direct breach of any single company's core network.

The Supply Chain Strikes Again

This is Cl0p's signature move — the same playbook behind the MOVEit and Accellion FTA campaigns, where the group doesn't break into hundreds of companies one at a time, it finds one exposed enterprise software product used by hundreds of companies and walks through the same door repeatedly. If your organization runs PTC Windchill or FlexPLM anywhere near the public internet, this is your cue to check now, not after your name shows up on a leak site.

The unverified nature of the claim matters too — Cl0p has a track record of both real, devastating breaches and inflated or recycled claims designed to extract payment through pure reputational pressure. Shell's measured "we're looking into it" is the right response; panicking before the data's verified just hands the extortionists a bigger win.

Whether or not the data's real, the lesson's already landed: one exposed third-party system can put your name on a leak site before you even know you've been breached.

Cl0p thrives on companies that don't know what's exposed to the internet — if you're not sure what that list looks like for your own stack, that's the first thing worth fixing, and our free supply-chain security checklist is a solid place to start.

Source: CyberPress