Home ยป Cl0p cyber gang claims global data haul from nearly 50 companies

Cl0p cyber gang claims global data haul from nearly 50 companies

by Simon Jones Tech Reporter
14th Aug 26 7:48 am

A Russia-linked cybercrime group has claimed to have stolen data from almost 50 companies worldwide, escalating concerns over the vulnerability of widely used enterprise software and exposing some of the worldโ€™s biggest businesses to potential extortion.

Cl0p, a Russian-speaking hacking operation known for exploiting flaws in corporate software, has claimed victims including Philips, Shell, Fiserv and GE, according to Reuters. The scale of the alleged haul could make the campaign one of the groupโ€™s more significant operations this year.

The companies have responded cautiously.

Philips confirmed an attempted cyberattack involving a separate corporate server containing internal data, but said the incident had been contained and customer environments were unaffected.

Shell said it was investigating a possible cyber incident with its own cybersecurity specialists and external experts.

Fiserv said it was aware of Cl0pโ€™s claims but had found no evidence that customer, banking, payment or personal data had been compromised. Its operating environment also remained unaffected, the company said.

GE has not commented.

The claims have not been independently verified, and Cl0p did not respond to requests for information. It remains unclear how much data, if any, was actually removed from the companies.

The suspected entry point is particularly significant.

According to Reuters, attackers may have exploited vulnerabilities in PTCโ€™s Windchill and FlexPLM software, tools used by manufacturers and engineering businesses to manage product design and development.

The vulnerabilities had already attracted warnings. Ransom-ISAC raised the alarm on July 22, while PTC issued security guidance urging customers to install available updates.

Brandon Parsons, the cyber threat analyst who authored the Ransom-ISAC warning, said some companies began receiving messages from Cl0p around July 19 or 20.

The campaign illustrates a changing model of corporate hacking. Rather than breaking into individual companies one by one, attackers increasingly hunt for a weakness in software used across entire industries.

Parsons described Cl0p as โ€œprofessional data extortionistsโ€ โ€” a group whose business model depends on finding valuable information and threatening to release it.

Cl0p, also known as Cl0P, is assessed by Canadian cybersecurity authorities as a financially motivated Russian-speaking criminal group likely operating from a Commonwealth of Independent States country. It has been linked to the TA505/FIN11 cybercrime cluster and previously caused widespread disruption through attacks exploiting enterprise software vulnerabilities, most notably the MOVEit file-transfer platform.

The latest campaign underscores the uncomfortable economics of modern cybercrime: one vulnerability in a widely deployed corporate application can provide attackers with access to an entire ecosystem of potential targets.

For businesses, the danger is no longer necessarily an attacker specifically selecting them. A vulnerability somewhere in their software supply chain may be enough to put their data in the crosshairs.

Leave a Comment

You may also like

CLOSE AD