Shell and Philips hit by Russian ransomware attack
Russia-linked ransomware group Cl0p says it hacked Shell and Philips, claiming it stole about 89 GB from Shell and 13.5 GB from Philips. Both companies said they are investigating. Philips reported it contained an attempted compromise on a specific enterprise server with no customer impact. Researchers linked the campaign to a Windchill flaw patched June 17.
How this was made

The 30-second read
Why it matters
Shell and Philips are both investigating. Shell acknowledges a possible incident. Philips says it identified and contained an attempted compromise on a specific enterprise server and reports no customer impact, but the breach method and ransom terms are not disclosed.
Market read
This is a cybersecurity headline with partial company confirmation, which can drive short-term volatility and risk repricing until scope, customer impact, and remediation costs are clarified.
What to watch
Watch for follow-on disclosures: whether regulators require incident reporting, whether customer systems were accessed, and whether remediation costs or downtime are quantified.
Background
Cl0p is described as a Russia-linked ransomware group active since 2019 that steals files and threatens publication unless ransom is paid; researchers link the campaign to a Windchill engineering-software flaw patched June 17.
Ticker impact
Shell says it is aware of a possible incident after Cl0p claims it hacked the company and stole 89GB of materials.
Choppy, risk-off trading possible on headlines until Shell confirms scope and remediation; magnitude uncertain.
The text is a third-party claim with limited verification, yet it includes a specific statement from Shell acknowledging a possible incident and a large volume of allegedly stolen data.
Philips reports it contained an attempted cybersecurity compromise on a specific enterprise server after Cl0p claimed it stole 13.5GB of data.
Likely limited downside if containment is credible; further investigation could extend volatility.
Philips provides a concrete containment update and says there is no customer impact, which should cap immediate damage, but the incident is still under investigation.
Market effects
Highlights supply-chain and industrial engineering software exposure (Windchill flaw) that can pressure cybersecurity spending and risk premiums across industrials and healthcare tech.
European large-cap industrial and healthtech names may see correlated volatility on ransomware headlines.
If the Windchill-linked vector is widely exploited, it can broaden perceived cyber risk for multinational infrastructure and engineering workflows.
Counterpoint
Because the claims are from the ransomware group and details of the breach are not confirmed, the market may overreact until forensic evidence narrows scope.
Key entities
- ransomware groupCl0p
Russia-linked group claiming it hacked Shell and Philips and stole technical and blueprint data.
- companyShell
Says it is aware of a possible incident after Cl0p’s claim of 89GB stolen.
- companyPhilips
Says it contained an attempted compromise on a specific enterprise server and reports no customer impact after Cl0p’s claim of 13.5GB stolen.
- softwarePTC Windchill
Engineering software cited by researchers as having a flaw linked to the campaign, patched June 17.




