Russian ransomware group Cl0p published data it claims to have stolen from Shell and Philips on the dark web in October 2026, after the companies did not pay the extortion demands first made in August. BNR reviewed published Philips files, including technical drawings of MRI scanners and medical equipment, and information about Philips’ IT infrastructure, and sent samples to Philips for verification. Cl0p claims 89GB of Shell data including construction drawings, facility photos, test reports, and project plans. BNR could not independently access Shell’s published data.
What’s in the Philips Data
BNR’s review of the Philips material surfaced two categories of particularly sensitive content.
The first: technical drawings of MRI scanners and other medical equipment. These engineering documents describe how a device is built, its components, and how they’re arranged. In the wrong hands, this type of documentation has multiple applications. It represents valuable competitive intelligence for any company developing competing medical imaging technology. It could also expose design details that reveal known failure modes or exploitable weaknesses in equipment used in hospitals worldwide.
The second: information about Philips’ IT infrastructure. This category is arguably the more immediately dangerous of the two. A document or database that maps out how a company’s systems are configured, what software versions are running, and how networks are segmented and connected is a reconnaissance map for the next attack. Any threat actor who downloads this material gains a starting point for identifying vulnerabilities without needing to do the initial access work themselves.
BNR sent several files from the Philips dataset to the company for verification. Philips has not publicly confirmed the material’s authenticity.
What Cl0p Claims About Shell
The Shell dataset is larger. Cl0p claims 89 gigabytes, covering construction drawings, photographs of physical facilities, scans of test reports, and project plans.
BNR could not access the Shell data independently. It may be behind a paywall on a dark web forum, accessible only to verified buyers or paying subscribers, a common structure for high-value corporate data on criminal platforms. That Shell’s data is behind a payment barrier. At the same time, Philips’ data being more freely accessible may reflect a strategic choice by Cl0p: using Shell’s data as a commercial product while using Philips’ data primarily to prove the group delivers on extortion threats.
Construction drawings and facility photographs for a global energy company represent a different category of risk than a business data leak. Shell operates refineries, pipelines, offshore platforms, and distribution infrastructure. Detailed engineering and facility documentation for these sites has potential value beyond ordinary data theft. This information has long concerned critical infrastructure security agencies, including CISA.
Why Data Gets Published: The Extortion Logic
The pattern here is straightforward. Cl0p claims a breach in August, sends a ransom demand, and sets an implicit or explicit deadline. Neither Shell nor Philips publicly confirmed payment. In October, Cl0p publishes.
This is Cl0p’s business model in 2026. The group first gained wider attention in 2019, operating as a traditional ransomware group that encrypted systems and demanded payment to decrypt them. It has since shifted toward pure data extortion: steal data, threaten to publish, demand payment, publish when payment doesn’t come. No encryption, no operational disruption, just the pressure of knowing sensitive corporate information sits on a server, ready to be released.
The same pressure mechanism has played out in cases involving other groups and other victims throughout this year. The Flink case is the most recent European example: LPG Group attempted triple extortion against the grocery delivery service and its customers simultaneously, and according to reports, received no payments from either. The stolen data is now reportedly being sold to the highest bidder.
When victims don’t pay, publication usually follows. Even if payment happens, data may still be published, depending on the group. The model works because the threat of exposure is real regardless of what the victim does, forcing every breached organization to decide whether payment buys them anything.
The Timing: After the ShinyHunters Hijack
There’s a detail here that gives Cl0p’s current operation an unusual context.
In September 2026, ShinyHunters publicly claimed to have hijacked Cl0p’s dark web leak site, exploiting a vulnerability in the Grav CMS the site ran on to steal the private keys controlling Cl0p’s Tor onion service and threaten to extort the ransomware group in return. As we covered in detail in our piece on the ShinyHunters-Cl0p infrastructure breach, ShinyHunters claimed access to Cl0p’s backend systems, victim negotiation logs, and operator infrastructure.
The Shell and Philips data publication in October suggests Cl0p has either rebuilt its leak infrastructure, is using alternative channels, or the ShinyHunters hijack was less complete than claimed. The fact that criminal groups in the same ecosystem can attack each other’s infrastructure and still keep operating reminds us that the dark web’s criminal market is competitive and adversarial, even among its participants.
How This Connects to Cl0p’s Wider 2026 Campaign
Cl0p is not operating in isolation against individual targets. The Shell and Philips claims are part of a broader campaign the group ran through the second half of 2026. In August, it claimed it stole data from nearly 50 organizations, including companies beyond Shell and Philips, a pattern consistent with the group’s previous supply chain exploitation.
Cl0p’s major campaigns have repeatedly relied on finding a single vulnerability in widely-used enterprise software and exploiting it across many victims simultaneously. The 2023 MOVEit vulnerability was the largest example. It exposed data from over 600 organizations globally, including companies like CenterPoint Energy, whose 2026 breach we covered separately. The current Shell and Philips publications fit the same model: batch-claim in public, wait for payment, publish when it doesn’t come.
This is also why early dark web monitoring matters. By the time a group like Cl0p publishes data, the window for any internal “we didn’t know about this” response from the victim company has long closed. The stolen data was on Cl0p’s servers from the moment of theft in August. Shell and Philips had two months during which they could have described that data as “under investigation” and not publicly accessible. That period ends with publication.
As we’ve covered in looking at how dark web warning signals precede public breach disclosure, the gap between theft and publication is where monitoring tools and threat intelligence teams can act. Once data is on a dark web forum, the calculus shifts: it’s no longer about preventing exposure; it’s about mitigating the damage from exposure that has already occurred.
What Shell and Philips Employees and Partners Should Know
If you work for Shell, Philips, or a company with significant business relationships with either organization, the publication of this data creates specific short-term risks.
Technical drawings and infrastructure information in criminal hands enable highly targeted phishing. A supplier receiving an email that accurately references a specific MRI scanner component project, or a Shell contractor being contacted with accurate details about a specific facility, faces a much more convincing attack than a generic phishing attempt.
Watch for contact that references project-specific details that shouldn’t be widely known. Treat any unexpected inbound communication about sensitive technical or infrastructure matters with extra skepticism for the next several months, regardless of how well-informed the contact appears to be.
For anyone assessing broader data exposure risk, our guide on what to do when your personal or business data appears on the dark web covers the response framework.
Frequently Asked Questions
What did Cl0p publish?
Data claimed to have been stolen from Shell (89GB including construction drawings and facility information) and Philips (including MRI scanner technical drawings and IT infrastructure details).
Did BNR verify the data is real?
BNR reviewed the Philips files and sent them to the company for verification. The files included MRI scanner technical drawings and IT infrastructure information. BNR could not independently access Shell’s data.
Why did Cl0p publish now?
Cl0p claimed the data in August 2026. Neither company publicly confirmed that it paid a ransom. Publication typically follows when extortion demands go unmet.
Is this related to Cl0p’s previous MOVEit attacks?
Cl0p’s 2026 campaign appears to follow the same batch-exploitation model the group used with MOVEit in 2023, targeting multiple major organizations simultaneously through a shared vulnerability.
What about the ShinyHunters hijack?
ShinyHunters claimed in September to have seized Cl0p’s dark web infrastructure. The October data publications suggest Cl0p has maintained or rebuilt operational capability regardless.