Following a significant ransomware attack, multinational energy giant Shell has initiated an investigation into the Cl0p cybercrime group's alleged theft of sensitive internal data This article explores investigation cl0p cybercrime. . The extortion gang listed Shell on its dark web leak portal, claiming they stole approximately 89 gigabytes of proprietary corporate data.

According to statements published by the cybercriminals, the compromised files include engineering drawings, facility photographs, project roadmaps, and testing reports. Cl0p's historical focus on data exfiltration rather than encrypting operational technology networks has been replaced by the exposure of engineering blueprints and facility audits, introducing significant safety and counterparty security concerns. Company representatives emphasized ongoing investigations alongside third-party digital forensics firms to determine whether production environments or employee assets were compromised.

The syndicate previously carried out zero-day supply chain attacks on managed file transfer platforms like MOVEit Transfer and Accellion FTA, compromising hundreds of organizations worldwide. Instead of traditional ransomware encryption, they exploit custom web shells to exfiltrate structured databases and unencrypted files, demanding multi-million-dollar ransoms in exchange for non-publication. This tactic complicates incident triage by allowing file systems to operate normally while compromising confidential data.

Enterprises should enforce centralized log aggregation across authentication gateways, deploy multi-factor authentication on all administrative services, and review outbound traffic for anomalous spikes to detect potential exfiltration attempts.