Cl0p says it stole data from nearly 50 companies, including Shell, Philips, GE, and Fiserv. Here’s what is confirmed, what remains unclear, and how you can protect yourself right now.
Table of Contents
What Happened in the Cl0p Data Theft Claims?
The group named major companies including Shell, Philips, Fiserv, and GE on its website.
However, Reuters said it could not independently verify what information Cl0p obtained or how much data was taken.
Philips confirmed that it detected and contained an attempted attack on one enterprise server connected to internal data.
The company said customer environments were not affected.
Shell said it was investigating a possible recent incident. GE also started its cybersecurity response process after learning about the claim.
Fiserv said its investigation found no evidence that customer, banking, transaction, or personal data had been taken.
The exact data involved remains unclear. Still, stolen information from cyberattacks can later be used in phishing emails, fake calls, or impersonation attempts.
You may also have information circulating from other breaches without realizing it.
If you are unsure whether your information was leaked elsewhere, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Which Companies Were Named and What Data Is Confirmed?
Cl0p claimed that nearly 50 companies worldwide were involved. Reuters specifically reported on Shell, Philips, Fiserv, and GE.
However, the number of people potentially affected has not been shared publicly.
Reuters also could not confirm what types of information Cl0p obtained.
Philips said the attempted attack involved an enterprise server connected to internal data, but customer environments were unaffected.
Fiserv said it found no evidence that customer information, banking data, transaction records, or personal data had been taken.
Shell and GE were still investigating the situation when Reuters published its report.
Because these investigations are ongoing, claims about stolen customer or personal data should be treated carefully until companies confirm them.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyHow Cl0p May Have Reached Multiple Companies
Reuters said it is still unclear exactly how Cl0p accessed the companies it named.
However, Ransom-ISAC issued a warning on July 22 about Cl0p exploiting weaknesses in PTC Windchill and FlexPLM.
These are business software tools used for engineering, manufacturing, and product management.
PTC had already issued security notices beginning June 18 and urged customers to install security updates.
Cl0p is known for looking for weaknesses in widely used software and then targeting many organizations using the same product.
One security expert described the group as focusing on software vulnerabilities rather than choosing individual companies first.
Some attacks may involve a zero-day vulnerability, meaning a software weakness that criminals exploit before a fix is widely available.
However, Reuters did not confirm that the same vulnerability was used against every company named by Cl0p.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
