TechNewsReel
Live

Shell Compromised in Cl0p Ransomware Attack via MOVEit Flaw

The energy giant is among hundreds of organizations hit by a zero-day SQL injection vulnerability in Progress Software's file transfer tool.

TechNewsReel Newsroom · August 15, 2026

Shell has been identified as a victim of a massive supply chain cyberattack orchestrated by the Cl0p ransomware group. The breach occurred through a critical vulnerability in a third-party file transfer service, exposing the company to one of the most widespread software exploits of the year.

The incident centered on a zero-day SQL injection vulnerability, tracked as CVE-2023-34362, within the MOVEit Transfer software developed by Progress Software. The Cl0p ransomware group claimed responsibility for the operation, explicitly listing Shell as a victim on its dark web blog. In response, Shell confirmed it was aware of the cybersecurity incident, noting that the breach impacted a third-party tool used by a small number of its employees and customers.

The MOVEit Campaign

This breach was not an isolated attack on Shell but part of a coordinated global campaign by Cl0p. The group targeted hundreds of organizations worldwide, ranging from major corporations like British Airways and the BBC to various government agencies. A defining characteristic of this campaign was the use of indirect compromise; many organizations were not breached directly but were exposed because their third-party service providers—such as the payroll firm Zellis—utilized the flawed MOVEit software.

Supply Chain Risks

The Shell incident underscores the systemic risk inherent in the modern software supply chain. When a single, widely adopted tool like MOVEit Transfer contains a critical flaw, it creates a single point of failure that can be leveraged to gain access to the sensitive data of numerous global enterprises and government entities simultaneously. For companies like Shell, the risk extends beyond their own internal security perimeter to the security posture of every vendor in their ecosystem.

Future Outlook

As organizations continue to scrub their environments for indicators of compromise, the industry is watching how Progress Software and its clients manage the long-term fallout of CVE-2023-34362. While Shell has characterized the impact as limited to a small number of users, the full extent of the data exfiltrated by Cl0p across all its victims remains a primary concern for cybersecurity regulators and affected parties.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.