The Russia-linked ransomware group Cl0p has claimed a fresh wave of cyberattacks, naming Shell and Philips among its victims and, by some counts, dragging close to 50 companies into the mess.
It is a familiar sort of headline, and one that reads more than a little like a rerun of the Oracle-linked breaches that have unsettled corporate security teams for much of the year.
The numbers Cl0p is throwing around are not modest. From Shell, the group claims to have taken roughly 89GB of material, including technical drawings, images of facilities, scans of test reports, and project plans.
From Philips, it says it lifted about 13.5GB, mostly diagrams and blueprints. Other names circulating in coverage include GE and the financial-technology firm Fiserv.
Cl0p’s business model is not the noisy, lock-up-your-files kind of ransomware that once dominated the news. Instead it favours data-theft extortion: steal the files quietly, then lean on victims to pay by threatening to dump everything on a leak site. It is extortion by embarrassment, and it has proved lucrative.
We have seen exactly how this plays out, and not so long ago. During the 2023 MOVEit mass hack, Cl0p breached hundreds of organisations through a single file-transfer flaw, and the fallout dragged on for months as new victims kept surfacing.
When Shell declined to negotiate on that occasion, the group simply published its data, a reminder that the threat to leak is rarely an idle one.
What makes this campaign more than a routine shakedown is the suspected way in. Several security firms and outlets have tied the spree to a zero-day vulnerability in Oracle’s E-Business Suite, the sprawling enterprise software that large companies use to run finance, procurement, and operations.
That link is reported by researchers rather than confirmed by the victims, and neither Shell nor Philips has said how it was breached, so it is worth treating as strong reporting rather than settled fact.
If it holds up, the logic is grimly efficient. Rather than picking off targets one by one, Cl0p would have found a single flaw in software that dozens of blue-chip firms happen to run, then harvested them all at once.
It is the same playbook that made a zero-day in a shared tool such a prize during MOVEit.
The companies, for their part, are saying as little as they can get away with. Shell said it is “aware of a potential incident” and is investigating, the sort of holding line that neither confirms the breach nor denies it.
Philips was a touch more forthcoming, describing “an attempted cyberattack on a specific company server containing internal data” that it says has been “brought under control,” with “no impact on customer environments.”
Whether the wider tally really approaches 50 firms is, for now, Cl0p’s own claim, and extortion gangs are not renowned for their modesty.
The group has an incentive to inflate the count, both to pressure the named victims and to burnish its reputation among the criminal fraternity it hopes will keep buying stolen access.
Still, the shape of the thing should worry any executive. A haul that spans an oil major, a medical-devices maker, an industrial conglomerate, and a payments firm is not the work of a crew that cares what you make.
It is the work of a crew that cares what software you buy, which is a far harder thing to defend against, echoing the leak-site theatrics that surrounded the 45GB dump from Madison Square Garden.
That is the uncomfortable lesson lurking beneath the drama. When enough of the corporate world standardises on the same enterprise platform, one shared supplier quietly becomes everyone’s single point of failure, and no amount of internal security spending can fully patch a hole in someone else’s code.
Get the TNW newsletter
Get the most important tech news in your inbox each week.