Oil or fuel facility
Shell — Clop ransomware group claims data-theft attack
Claims surfaced 12–13 August 2026
The Hague / global operations, Netherlands
What happened
The Russia-linked Clop ransomware/extortion group claimed on its dark-web leak site to have stolen data from Shell (along with Philips and other companies), reportedly around 89 gigabytes of Shell material including technical drawings, images of company facilities, test-report scans and project plans, according to the dark-web-monitoring platform GalaxyWarden. Shell said it was 'aware of a potential incident' and that its security teams and outside experts were investigating; the company did not confirm a breach, data loss or any operational impact on refining, production or grid-connected assets. Clop is a known extortion group that typically exfiltrates data rather than deploying disruptive ransomware, and its leak-site claims have not always been independently verified in past incidents. No impact on Shell's physical energy infrastructure or operations was reported, so this is recorded as an unconfirmed corporate data-theft claim rather than a documented breach.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Reported / attributed
- Confidence
- Moderate
- Infrastructure
- Oil or fuel facility
- Latitude
- 52.0800°
- Longitude
- 4.4800°
Attribution
Claimed by Clop ransomware group
Clop's claim is unverified by Shell or independent forensic reporting at the time of this entry; Shell said only that it was investigating a 'potential incident'.
