Clop Ransomware Gang Targets Global Multinationals in Massive Data Theft Campaign
The Russian-linked group has claimed breaches of dozens of corporations, including Shell and AOL, by exploiting enterprise software vulnerabilities.
The Clop ransomware gang has claimed to have breached dozens of multinational corporations, stealing gigabytes of sensitive data across several critical sectors. This latest campaign underscores the group's persistent ability to compromise global corporate giants and critical infrastructure.
In a series of high-profile extortion attempts throughout August 2026, Clop targeted a diverse array of industries, including energy, digital media, and healthcare. The gang claimed to have stolen 89GB of data from the British energy conglomerate Shell. On August 12, 2026, Clop claimed responsibility for a cyberattack against AOL.com, threatening to release sensitive information. The group's reach extended into the education sector as well, with a breach at Dartmouth College that affected more than 40,000 individuals.
The Clop Modus Operandi
Clop is a notorious Russian-linked cybercriminal organization recognized for its use of multilevel extortion. Rather than simply encrypting files, the group focuses on stealing massive datasets to pressure victims into paying ransoms to avoid public leaks. They frequently achieve this scale by exploiting zero-day vulnerabilities in widely used enterprise software, allowing them to gain access to multiple companies simultaneously. A recent example of this strategy was seen in the breach of Barts Health NHS, which was compromised via an Oracle EBS zero-day vulnerability identified as CVE-2025-61882.
Systemic Risks to Global Industry
The scale of these attacks demonstrates a significant systemic risk posed by vulnerabilities in the enterprise software supply chain. By targeting multinationals, Clop maximizes its leverage for ransom payments, knowing that the potential for reputational damage and regulatory fines for these giants is immense. The ability to pivot from a single software flaw to the internal networks of energy providers and healthcare systems highlights a critical weakness in how global corporations manage third-party software risks.
Future Outlook
As Clop continues to refine its extortion tactics, security experts are watching for further evidence of zero-day exploits in other enterprise-grade platforms. While several companies are currently investigating the claims, the primary concern remains the volume of data already exfiltrated. It remains to be seen how many of the "dozens" of claimed multinational victims will be publicly confirmed or if the gang will shift its focus toward different software vulnerabilities to maintain its momentum.