Cl0p says it broke into Shell, Philips, and dozens of other companies in its latest extortion campaign.
The Russia-linked ransomware group has claimed a new wave of attacks, naming Shell and Philips among a list of alleged victims that reportedly stretches toward 50 companies. Cl0p typically operates by exploiting a vulnerability in widely used enterprise software, then threatening to leak stolen data unless victims pay up. Neither Shell nor Philips has confirmed the claims publicly, and the full list of alleged targets has not been independently verified. Right now, Cl0p's own disclosures are the only source for how many companies are actually involved.
Mass claims like this matter less as individual breach stories and more as a pattern. It is the same playbook Cl0p ran against companies tied to Oracle-linked software earlier this year: hit one shared vulnerability, then squeeze dozens of downstream victims at once. That approach turns a single software flaw into leverage over an entire client list, which is exactly why ransomware groups keep using it.
Until Shell, Philips, or any of the other named companies confirm what was actually taken, the real scope of this one remains a claim, not a fact.