Tuesday, September 8, 2026

Shell Global Hacked using Flaw in the MOVEit File Transfer System

Shell corporation has published a report indicating that they have faced a security incident that involved Accelion’s File Transfer appliance in 2021. 

This is the second time the company has faced a security incident after 2021. Shell is one of the major Oil and gas giants, which has a turnover of around $381 Billion (as of 2022) and has employees of more than 80,000 worldwide.

Earlier this month, the MOVEit File transfer application was reported to be vulnerable to potential privilege escalation and SQL injection attacks. Clop ransomware group has been identified to be exploiting MOVEit file transfer used by many organizations.

The recent security incident states that an unauthorized third party has infiltrated Shell corporation for a short period of time within which they could extract some personal data and other stakeholder information.

“We are aware of a cyber security incident that has impacted a third party tool from Progress called MOVEit Transfer which is used by a small number of Shell employees and customers,” said a spokesperson from Shell corporation.

In addition to this, the Clop ransomware group has published a report on the dark web that showed a number of companies hacked by them showcased several UK-based organizations, including Shell Inc and many US-based financial organizations.

It is still unclear how many organizations were attacked and infiltrated by this. However, Clop ransomware group hasn’t published the complete report yet.

Though this is confirmed, Shell stated, “There is no evidence of any impact to Shell’s core IT systems as the file transfer service is isolated from the rest of Shell’s digital infrastructure.”

The company also mentioned that they have been working with the cyber security team and authorities to investigate this incident further. They are also in contact with the affected individuals to address the possible risk of this incident.

Looking For an All-in-One Multi-OS Patch Management Platform – 

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic’s Claude Mythos Preview has demonstrated the ability to...

WhatsApp Testing Guest Calls for People Without a WhatsApp Account

WhatsApp is developing a guest-call feature that would let...

The 12 Best Managed Firewall Services, Compared and Priced

Best value overall: Fortinet. Delivered directly and through the...

The Best DNS Security Solutions, Compared and Priced (2026)

DNS security delivers more blocked attacks per dollar than...

Related Articles

Recent News