Clop lists Shell as ransomware victim
Clop ransomware group claims a breach of an energy-sector organization, alleging exfiltration of 89GB including engineering drawings and facility data.
Ransomware.live's tracking of Clop's leak site lists a new victim entry dated August 2026, with data exfiltration claims totaling 89GB. The stolen data reportedly includes engineering drawings, facility photographs, testing reports, and project plans, suggesting the target operates industrial or energy infrastructure. DNS and WHOIS records embedded in the listing repeatedly reference shell.com, indicating the victim organization is likely affiliated with a large energy/oil company, though the entry is flagged as a possible duplicate of an existing database record.
The listing includes extensive third-party SaaS and cloud service verification records (Adobe, Atlassian, Salesforce, DocuSign, MongoDB, OneTrust, Twilio, Cisco Duo, etc.), which are standard artifacts of a large enterprise's domain configuration rather than indicators of compromise themselves. No specific malware samples, C2 infrastructure, or exploited vulnerabilities are disclosed in this listing. Clop is a well-established ransomware/extortion operation known for large-scale data theft and double-extortion campaigns, frequently leveraging file-transfer and enterprise software vulnerabilities (e.g., MOVEit, Accellion) in past campaigns, though this specific intrusion vector is not detailed here.
Given the scale of the claimed victim (a major multinational energy company based on revenue figures cited) and the sensitivity of exfiltrated engineering and facility data, this listing warrants monitoring, though it represents a routine addition to Clop's ongoing extortion activity rather than a novel technique or newly disclosed vulnerability.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/U0hFTEwuQ09NIChBdWd1c3QgMjAyNilAY2xvcA==
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free