Russian hackers breach nearly 50 companies worldwide, including Shell, Philips and General Electric – Reuters

- 14 August, 03:30
Photo: Getty Images

The Russia-linked hacking group Cl0p has claimed to have stolen significant amounts of internal data from nearly 50 companies worldwide, including energy giant Shell, medical technology manufacturer Philips, and corporations such as General Electric and Fiserv.

Source: Reuters

Details: The hackers claim to have stolen around 89 gigabytes of data from Shell and 13.5 gigabytes from Philips.

In a statement published on 12 August, the cybercriminals claimed that the documents stolen from Shell included project drawings for energy facilities operated by the company, photographs of industrial sites, scanned copies of technical inspection reports and project planning materials. The hackers also claimed to have stolen schematics, drawings and diagrams in PDF format from Philips.

At the time of publication, the hackers had not released any samples of the stolen information.

Both companies confirmed attempts to gain unauthorised access to their systems and said they have launched internal investigations, but neither has so far confirmed that any data was stolen.

"We are working with our ​security teams and relevant experts to investigate the situation," a Shell spokesperson told Dutch news outlet BNR.

"Philips has identified ​and contained an attempted cybersecurity compromise of a specific enterprise server related to ⁠internal data," Philips said in a statement, adding that the incident has not affected customer environments.

A GE spokesperson said the company was aware of the hackers' claim and has "initiated ​our cyber response protocols and are working to assess the potential issue".

A spokesperson for financial technology company Fiserv said the company is aware of the cybercriminals' claims. The spokesperson said that "based on our comprehensive ​review to date", there is no evidence that any customer, bank, transaction or personal data has been compromised, nor is there any impact on its operating environment.

Although the initial access vector has yet to be officially established, the Ransomware Information Sharing and Analysis Center (Ransom-ISAC) warned as early as 22 July that Cl0p was actively exploiting vulnerabilities in PTC Windchill and FlexPLM engineering software, which is used to support manufacturing processes.

Brandon Parsons, head of threat analysis at Ascent Solutions, said the group operates as "professional data extortionists", focusing on exploiting vulnerable software platforms rather than targeting specific companies.

"They don't really target a specific company, they ​target a specific zero day vulnerability and go after it," Parsons said.

Ransomware attacks involving data theft, known as double extortion, can cause significantly greater damage than conventional encryption-based attacks, as companies risk not only losing control of their information but also having it publicly disclosed.

Shell is one of the world's largest energy companies. A leak of blueprints of its industrial facilities and inspection reports could pose a threat to the physical security of critical infrastructure, as such information could potentially be used to plan acts of sabotage.

Philips is a leading manufacturer of medical equipment. If the reported theft of blueprints and technical schematics is confirmed, the company could suffer significant intellectual property losses due to the risk of design documentation falling into the hands of competitors or malicious parties.

For reference: Cl0p (also known as Clop) is considered one of the most dangerous Russian-speaking cybercriminal groups and has been active since at least early 2019. Cybersecurity researchers have linked its activities to the well-known hacking clusters TA505 and FIN11.

The group operates primarily from Russia and other post-Soviet countries and reportedly follows an unwritten rule of not attacking organisations within the Commonwealth of Independent States (CIS). Cl0p's malware includes checks for keyboard language and operating system settings and automatically stops running if Russian-language settings are detected.

Cl0p was among the pioneers of the "double extortion" tactic, which involves not only blocking access to corporate systems but also threatening to publish confidential data on its dark-web site if victims refuse to pay a ransom in cryptocurrency.

In recent years, the group has largely moved away from conventional encryption of individual networks in favour of mass attacks exploiting zero-day vulnerabilities in widely used corporate software. Notably, the hackers carried out major global campaigns targeting Accellion FTA in 2021, GoAnywhere MFT in early 2023 and MOVEit Transfer in the summer of the same year, compromising data belonging to hundreds of millions of users, major corporations and government agencies in Western countries.

Your support on Patreon helps us keep the news free and accessible.