---
title: "Shell investigates Cl0p data theft claim as eng… | Firevault"
description: "Shell has opened an investigation after the Cl0p ransomware group claimed the theft of around 89 gigabytes of internal data, said to include engineering…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim#webpage",
      "url": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim",
      "name": "Shell investigates Cl0p data theft claim as eng…",
      "description": "Shell has opened an investigation after the Cl0p ransomware group claimed the theft of around 89 gigabytes of internal data, said to include engineering…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/shell-cl0p-data-breach-claim.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Shell investigates Cl0p data theft claim as engineering files are listed",
          "item": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Shell investigates Cl0p data theft claim as engineering files are listed",
      "description": "Shell has opened an investigation after the Cl0p ransomware group claimed the theft of around 89 gigabytes of internal data, said to include engineering drawings, facility photographs, project roadmaps and testing reports. Shell is one of dozens of organisations named in the same campaign.",
      "url": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/shell-cl0p-data-breach-claim.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/shell-cl0p-data-breach-claim.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/shell-cl0p-data-breach-claim.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/shell-cl0p-data-breach-claim.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-16T07:35:01.977436+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/shell-cl0p-ransomware-data-theft-claim"
      },
      "inLanguage": "en-GB",
      "articleSection": "Insight",
      "wordCount": 513,
      "keywords": "Shell, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Shell has launched an active investigation after the Cl0p ransomware syndicate claimed responsibility for exfiltrating sensitive internal data. The group listed Shell on its dark web leak portal, alleging the theft of approximately 89 gigabytes of proprietary corporate material. What has been claimed According to the statements published on the group's leak site, the files purportedly include engi",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What has been claimedThis is a campaign, not a single…Why engineering data matters mor…Extortion without encryptionThe Firevault viewMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Insight · 16 August 2026 

# Shell investigates Cl0p data theft claim as engineering files are listed

Shell has opened an investigation after the Cl0p ransomware group claimed the theft of around 89 gigabytes of internal data, said to include engineering drawings, facility photographs, project roadmaps and testing reports. Shell is one of dozens of organisations named in the same campaign.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fshell-cl0p-ransomware-data-theft-claim)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fshell-cl0p-ransomware-data-theft-claim&text=Shell%20investigates%20Cl0p%20data%20theft%20claim%20as%20engineering%20files%20are%20listed%0A%0AShell%20has%20opened%20an%20investigation%20after%20the%20Cl0p%20ransomware%20group%20claimed%20the%20theft%20of%20around%2089%20gigabytes%20of%20internal%20data%2C%20said%20to%20include%20engineering%20drawings%2C%20facility%20photographs%2C%20project%20roadmaps%20and%20testing%20reports.%20Shell%20is%20one%20of%20dozens%20of%20organisations%20named%20in%20the%20same%20campaign.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fshell-cl0p-ransomware-data-theft-claim)[](mailto:?subject=Shell%20investigates%20Cl0p%20data%20theft%20claim%20as%20engineering%20files%20are%20listed&body=Shell%20has%20opened%20an%20investigation%20after%20the%20Cl0p%20ransomware%20group%20claimed%20the%20theft%20of%20around%2089%20gigabytes%20of%20internal%20data%2C%20said%20to%20include%20engineering%20drawings%2C%20facility%20photographs%2C%20project%20roadmaps%20and%20testing%20reports.%20Shell%20is%20one%20of%20dozens%20of%20organisations%20named%20in%20the%20same%20campaign.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fshell-cl0p-ransomware-data-theft-claim)

![Energy refinery at dusk with engineering blueprints dissolving into stolen data beside a physically disconnected offline storage drive](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/shell-cl0p-data-breach-claim.jpg)

Energy refinery at dusk with engineering blueprints dissolving into stolen data beside a physically disconnected offline storage drive

Why it matters

## What this means for organisations holding critical data

Shell has opened an investigation after the Cl0p ransomware group claimed the theft of around 89 gigabytes of internal data, said to include engineering drawings, facility photographs, project roadmaps and testing reports. Shell is one of dozens of organisations named in the same campaign.

In this analysis

1.  01 [What has been claimed](#section-0)
2.  02 [This is a campaign, not a single…](#section-1)
3.  03 [Why engineering data matters mor…](#section-2)
4.  04 [Extortion without encryption](#section-3)

**On this page**[What has been claimed](#section-0)[This is a campaign, not a single…](#section-1)[Why engineering data matters mor…](#section-2)[Extortion without encryption](#section-3)

Shell has launched an active investigation after the Cl0p ransomware syndicate claimed responsibility for exfiltrating sensitive internal data. The group listed Shell on its dark web leak portal, alleging the theft of approximately 89 gigabytes of proprietary corporate material.

## What has been claimed

According to the statements published on the group's leak site, the files purportedly include engineering drawings, facility photographs, project roadmaps and testing reports. Shell has confirmed it is looking into a potential incident. Nothing in the listing has been independently verified, and that is entirely deliberate on the attacker's part. Preview listings of this kind are a pressure tactic, published to force an enterprise victim into negotiation before a full dataset is released.

## This is a campaign, not a single victim

Shell is not being singled out. Cl0p has named dozens of organisations in the same wave, including Philips, GE and Fiserv, with reporting linking the activity to the exploitation of a flaw in a widely deployed enterprise product rather than to any weakness unique to one company. That is the pattern this group has used repeatedly: find one trusted piece of software sitting inside thousands of estates, harvest data at scale, then extort each organisation individually.

## Why engineering data matters more than it looks

Corporate document theft is often reported as a reputational problem. For an energy operator it is an operational one. Engineering drawings, plant photographs, testing reports and project roadmaps describe how physical facilities are built, configured and maintained. That material is reconnaissance for anyone planning a later intrusion into operational technology, and it retains value for years. Unlike a password, an engineering drawing cannot be rotated after a breach.

## Extortion without encryption

There is no reported outage here, and that is the point. Cl0p has moved away from mass encryption towards pure data theft extortion. The leverage is not downtime, it is publication. This changes what a recovery plan has to cover. Restoring systems quickly does nothing to help if the sensitive material was reachable, copied and is now held by a criminal group.

## The Firevault view

Every claim in this listing rests on the same precondition: the data was reachable from a network. Documents held on connected file shares, collaboration platforms, managed transfer products and always available cloud repositories can be enumerated and copied the moment an attacker gains a foothold in the software that touches them.

[Offline Secure Storage](/offline-secure-storage)® (#OSS) removes that precondition. A Firevault Vault holds data on [physically disconnected storage](/storage) inside a secure bunker. There is no network path to it, so it cannot be discovered, copied or listed during an intrusion. Access is enabled deliberately by the customer, used, then removed again. The archive that matters most, the engineering record, the design history, the project material with a long shelf life, does not need to sit online to be useful.

The question for any operator reading this week's coverage is not whether their perimeter held. It is which of their most sensitive records were reachable at all, and how many of those could have been offline.

**Source:** [BleepingComputer, Shell investigates potential incident after Clop data theft claims](https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/).

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. New research shows no hacking was required: server-side marketing API keys sat in the public JavaScript of all three airport websites, unrotated, for more than four years.

27 Aug 2026 8 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)[

![Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Insight 

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min 







](/news/beacon-charity-database-breach-hiv-charity-health-data-2026)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)