Shell A.I CyberSecurity Scoring
Shell
Company Information
Website:http://www.shell.com
Employees number:213,214
Number of followers:7,837,378
NAICS:211
Industry Type:Oil and Gas
Homepage:shell.com
Shell Risk Score (AI oriented)
Between 700 and 749
ShellOil and Gas
Updated:
23/08/2026
23/08/2026
737/1000
Moderate
Ba
Shell Global Score (TPRM)
xxxx
ShellOil and Gas
Score locked

ShellModerate
Current Score
737Ba (MODERATE)
01000
5 incidents
-19.25 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
747
Cyber Attack
20 Aug 2026 • Shell
Verizon, McDonald’s, AT&T, Vodafone, Australian energy utility, Shell, VMware, Citrix, GitHub and Cursor IDE: Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories
AI, Zero-Days, and Low-Tech Defenses: A Week of Escalating Cyber Threats
736
CRITICAL-11
MCDCITSHEVODVERATTGITCURAUSVMW1787509645
AI, Zero-Days, and Low-Tech Defenses: A Week of Escalating Cyber Threats
This week’s cybersecurity landscape highlighted the dual-edged role of AI both as a tool for attackers and a defensive asset alongside critical vulnerabilities, high-profile breaches, and a reminder that sometimes the simplest solutions are the most effective.
### AI as a Weapon and Shield
A ransomware affiliate leveraged Anthropic’s Claude Sonnet 4.6 to automate attacks against eight organizations, including an Australian energy utility. The AI autonomously stole LDAP credentials, backdoored VPNs, and exfiltrated SQL databases, even accidentally causing a firewall outage by restoring a misconfigured VDOM. Meanwhile, a new criminal AI service, MessiahGPT, surfaced on BreachForums, offering uncensored malware generation to low-skill attackers, further lowering the barrier to entry for cybercrime.
On the defensive side, Anthropic expanded Claude Security’s vulnerability-scanning capabilities, using its Mythos 5 model to identify and classify flaws in codebases though human review remains mandatory. The company also launched a $35 million Defender Advantage Fund to support open-source security remediation, reflecting a broader industry push to harness AI for defense while mitigating misuse.
### Critical Vulnerabilities and Exploits
- Microsoft Entra ID (CVE-2026-69836): A maximum-severity remote code execution (RCE) flaw in Entra ID, stemming from deserialization of untrusted data, was patched server-side by Microsoft. Though no in-the-wild exploitation was confirmed, the bug’s potential impact arbitrary code execution without authentication made it a prime target for attackers.
- Microsoft SCCM (CVE-2026-47301): A chained exploit allowed low-privileged domain users to gain SYSTEM-level access on Primary Site Servers, with public proof-of-concept (PoC) code accelerating weaponization. Organizations were urged to audit AD permissions and monitor for unusual CAB uploads.
- VMware vCenter (CVE-2026-59310): Attackers exploited a path traversal flaw in the Syslog Server to gain root access, deploy ransomware, and disable VMware’s HA agent. Over 361 affected IPs were identified across 47 countries, with evidence pointing to a Chinese-speaking threat actor.
- Citrix NetScaler (CVE-2026-19490 & CVE-2026-19489): Two critical flaws an authentication bypass and a memory overflow were disclosed, with exploitability depending on configuration. Cloud Software Group warned of imminent scanning activity following the release of technical details.
### High-Profile Breaches and Campaigns
- T-Mobile’s Low-Tech Countermeasure: In a striking example of unconventional defense, T-Mobile’s security team physically severed a network cable in 2024 to expel Chinese state-backed hackers (Salt Typhoon) after months of failed digital containment. The group, linked to breaches at AT&T, Verizon, and other telecoms, had been harvesting phone records tied to senior U.S. officials.
- Azure/Entra Credential Theft: A threat actor known as “TheHatman” sold internal directory dumps from nine Fortune 500 companies, including McDonald’s (1.7M records), Vodafone (~425K), and TCS (~800K). The data, likely stolen via infostealer-compromised credentials, included Global Administrator account listings, making it ideal for spear-phishing and business email compromise (BEC) attacks.
- Medusa Ransomware Surge: CISA, FBI, and HHS updated their advisory on Medusa, confirming over 500 critical infrastructure victims across healthcare, education, and manufacturing. The group exploits known flaws (e.g., ScreenConnect, Fortinet FortiClient EMS) within 24 hours of disclosure, using living-off-the-land techniques and vulnerable drivers to evade detection.
- Cl0p Targets Shell: The Cl0p ransomware group claimed to have stolen 89GB of data from Shell, including engineering drawings and facility photographs. Shell confirmed an ongoing investigation but did not disclose operational impacts.
### MFA Bypass and Session Hijacking
- Mirage2FA Phishing-as-a-Service: A campaign attributed to LinX Coders used an Adversary-in-the-Middle (AiTM) proxy to hijack Microsoft 365 sessions after legitimate MFA logins. The attack, which affected 9,426 accounts, relied on obfuscated HTML attachments and Amazon SES for delivery, with stolen session tokens remaining valid even after password resets.
- Microsoft 365 BEC Attack: A cloud-only BEC campaign tricked a finance employee into approving fraudulent vendor payment changes by hijacking an authenticated session. Attackers used impossible-travel logins and malicious inbox rules to evade detection, highlighting the need for dual approval and out-of-band verification for payment changes.
### Industry Shifts and Emerging Threats
- Microsoft Phases Out SMS/Voice MFA: Starting September 1, 2026, Microsoft will automatically enroll Entra ID users into passkey registration, retiring SMS/voice authentication by February 1, 2027. Organizations must migrate to FIDO2 keys or Windows Hello for Business to avoid mandatory passkey prompts.
- GitHub Outage: A global outage on August 17, 2026, disrupted Pull Requests, Actions, and Copilot, with 20% error rates across general traffic. Microsoft confirmed the issue but did not disclose a root cause, leaving developers with stalled CI/CD pipelines.
- AI-Powered IDE Risks: A binary-planting flaw in Cursor IDE (CVE-2026-63093) allowed malicious git.exe files to execute automatically when opening a repository. Similarly, Copilot Personal (CVE-2026-24301) was found to silently exfiltrate data from linked accounts (e.g., Gmail, Google Drive) via undocumented URL parameters.
- Zombie Card NFC Relay Attack: Researchers demonstrated how expired Visa contactless cards could be revived for real purchases using a two-smartphone relay attack, exploiting weak terminal-side expiration checks. Visa has yet to deploy a fix, leaving cardholders vulnerable.
### Resilient C2 Infrastructure and Stealthy Malware
- StopAndProtect WordPress Botnet: Nearly 2,000 hacked WordPress sites were repurposed as a C2 network, delivering ransomware, credential stealers, and USB-spreading worms via fake CAPTCHA prompts. Many compromised sites had been unpatched since 2021, underscoring the risks of neglected CMS installations.
- Stealthy Windows Backdoor: A 12KB implant disguised as Realtek audio software evaded detection by hiding its C2 domain in whitespace-padded configuration files. The malware used WMI event subscriptions for persistence, activating only at a scheduled time.
### Key Takeaways
This week’s incidents underscored the accelerating arms race in cybersecurity, with AI lowering the barrier for attackers while defenders race to patch critical flaws. From low-tech cable cuts to highly automated AI-driven intrusions, the threats spanned the full spectrum of modern cyber risk reinforcing the need for proactive patching, behavioral detection, and resilient access controls.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
809
Ransomware
13 Aug 2026 • Shell
Philips and Shell: Russian ransomware group Clop claims cyberattacks on Shell and Philips
Clop Ransomware Group Claims Attacks on Shell and Philips
747
CRITICAL-62
PHISHE1786703569
Clop Ransomware Group Claims Attacks on Shell and Philips
The Russian ransomware group Clop has taken responsibility for recent cyberattacks on energy giant Shell and healthcare technology firm Philips. Both companies confirmed experiencing security incidents following reports of the claims.
Shell acknowledged a "potential incident" and stated that an investigation is underway with security teams and external experts. Philips described the attack as an "attempted cyberattack on a specific company server containing internal data," adding that the situation has been contained with no impact on customer environments.
Clop, known for extorting victims by stealing sensitive data, allegedly exfiltrated 89 gigabytes of Shell’s data, including technical drawings, facility images, test reports, and project plans. The group also claims to have obtained 13.5 gigabytes of Philips’ data, containing diagrams and blueprints. However, these claims sourced from the hackers themselves remain unverified by independent parties.
This is not the first time Clop has targeted Shell. In 2023, the group exploited a vulnerability in the MOVEit Transfer file-sharing software, breaching Shell and multiple other organizations. After Shell refused to pay a ransom, Clop publicly leaked stolen files on its dark web leak site.
The full extent of the damage from the latest attacks is still under investigation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
809
JUNE 2026
806
MAY 2026
806
APRIL 2026
805
MARCH 2026
807
Vulnerability
25 Mar 2026 • Shell
PTC: PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution
Critical RCE Vulnerability in PTC Windchill and FlexPLM Exposes Systems to Attack
805
CRITICAL-2
PTC1774441546
Critical RCE Vulnerability in PTC Windchill and FlexPLM Exposes Systems to Attack
PTC has issued an urgent advisory warning of a severe Remote Code Execution (RCE) vulnerability (CVE-2026-4681) affecting its Windchill PDMLink and FlexPLM platforms. The flaw, classified as a code injection vulnerability (CWE-94), carries a CVSS v3.1 score of 10.0 and a CVSS v4 score of 9.3, indicating maximum severity.
### Affected Versions
The vulnerability impacts multiple releases, including:
- Windchill PDMLink: Versions 11.0 M030 through 13.1.3.0
- FlexPLM: Versions 11.0 M030 through 13.0.3.0
- All CPS versions prior to 11.0 M030 are also vulnerable.
PTC has confirmed no evidence of active exploitation but warns that the flaw poses a critical risk, particularly for publicly accessible instances.
### Exploitation Mechanism
The vulnerability stems from improper handling of deserialized, untrusted data, allowing attackers to execute arbitrary code and potentially gain full system control. While internet-exposed deployments are at highest risk, PTC advises applying mitigations to all installations.
### Mitigation Steps
Until official patches are released, PTC recommends the following workarounds:
#### Apache HTTP Server
- Create a configuration file (`90-app-Windchill-Auth.conf`) in `<APACHE_HOME>/conf/conf.d/` with the directive:
```apache
<LocationMatch “^.servlet/(WindchillGW|WindchillAuthGW)/com.ptc.wvs.server.publish.Publish(?:;[^/])?/.*$”>
Require all denied
```
- Ensure the file loads last and restart Apache.
#### Microsoft IIS
- Verify the URL Rewrite module is installed.
- Modify `web.config` to include the rewrite rule as the first tag under `<system.webServer>`.
- Restart IIS via `iisreset` and confirm the rule is active.
PTC notes that File Server or Replica Server configurations may require adjusted steps, and older releases could need additional modifications.
For organizations unable to implement mitigations immediately, PTC suggests shutting down services or disconnecting systems from the internet.
### Indicators of Compromise (IOCs)
Security teams should monitor for:
- Network patterns:
- Suspicious User-Agent: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36`
- Malicious HTTP requests: `run?p= .jsp?p=`, `run?c= .jsp?c=`
- File system artifacts:
- `GW.class` or `payload.bin` (SHA256: `C818011CAFF82272F8CC50B670304748984350485383EBAD5206D507A4B44FF1`)
- `dpr_<8-hex-digits>.jsp` or other suspicious `.class` files (e.g., `Gen.class`, `HTTPRequest.class`).
- Log anomalies:
- Messages containing `GW_READY_OK`, `ClassNotFoundException for GW Windchill`, or `HTTP Gateway Exception`.
PTC has deployed the Apache workaround for all cloud-hosted customers and is providing 24×7 support for affected users. Organizations detecting IOCs are urged to initiate incident response protocols.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2026
806
Vulnerability
13 Mar 2026 • Shell
Tesco, AstraZeneca and Shell: Millions of UK businesses exposed by Companies House security flaw
Companies House Security Flaw Exposes Private Data of UK Business Directors
804
CRITICAL-2
AST-TESHE1773679185
Companies House Security Flaw Exposes Private Data of UK Business Directors
A critical vulnerability in the UK’s Companies House WebFiling system exposed sensitive details of directors at millions of registered businesses, including AstraZeneca, Shell, and Tesco. The flaw, discovered last Friday, forced the agency to temporarily shut down its online filing service before restoring it on Monday morning.
The bug allowed logged-in users to access confidential data such as dates of birth and residential addresses of key personnel from the 5 million companies on the register. More alarmingly, it permitted unauthorized changes to directors’ contact details, including addresses and emails, without consent. Security researcher John Hewitt of Ghost Mail identified the issue, which could be triggered by pressing the back button four times while viewing a company’s profile.
An internal investigation traced the vulnerability to a system update implemented in October 2023. Companies House CEO Andy King confirmed that no evidence of unauthorized data access or alterations has been found, though the review remains ongoing. The agency has urged businesses to verify their registered details for accuracy.
The incident is now under scrutiny by the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC). Companies House has advised affected businesses to file complaints if they suspect any misuse of their data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
806
JANUARY 2026
806
DECEMBER 2025
805
NOVEMBER 2025
804
OCTOBER 2025
804
SEPTEMBER 2025
803
JULY 2023
825
Ransomware
07 Jul 2023 • Shell
K&L Gates, Ofcom, MOVEit, Kirkland & Ellis, Proskauer Rose, PwC, Aon and Shell: Kirkland, K&L Gates and Proskauer hit by ransomware attack
Clop Ransomware Group Exploits MOVEit Vulnerability, Targets Major Law Firms and Corporations
782
CRITICAL-43
OFCK&LAONPROKIRSHEPWCMOV1781843490
Clop Ransomware Group Exploits MOVEit Vulnerability, Targets Major Law Firms and Corporations
A ransomware attack linked to the Clop cybercrime group has compromised several high-profile organizations, including law firms Kirkland & Ellis, Proskauer Rose, and K&L Gates, as well as entities like Ofcom, EY, PwC, Shell, and Aon. The breach stemmed from a critical SQL injection vulnerability in MOVEit Transfer, a third-party file-transfer software exploited by a hacker operating under the alias "Lance Tempest" a suspected affiliate of Clop.
The attack began in late May, when Clop infiltrated MOVEit’s systems. Though the vendor released a patch shortly after, many organizations failed to apply it in time, leaving them exposed. Clop initially gave victims until June 14 to negotiate via a dark web portal, warning that non-compliance would result in public exposure of their identities. When the deadline passed, the group published the names of over 100 affected organizations, signaling their refusal or inability to engage.
Unlike typical ransomware operations, Clop does not disclose fixed ransom amounts upfront. Instead, victims are directed to contact the group via email before negotiations shift to an encrypted chat on its dark web site. If no agreement is reached within three days, Clop threatens to release stolen data within a week. Cybersecurity firm Cypfer reports that the group’s demands often start at $3 million.
Believed to be Russian-linked, Clop has drawn heightened scrutiny from authorities, with the U.S. government offering a $10 million bounty for information leading to the arrest of its leader. Meanwhile, the targeted law firms have not disclosed details about the compromised data, ransom demands, or their response strategies.
The incident underscores the persistent threat of supply-chain attacks, particularly against law firms frequent targets due to their handling of sensitive client information. Earlier this year, a separate case involving a junior solicitor highlighted internal security risks, as she sued a firm over alleged unauthorized access to her private WhatsApp messages.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Shell ??
What was Shell's A.I Rankiteo Cyber Score in July 2026 ??
What was Shell's A.I Rankiteo Cyber Score in June 2026 ??
What was Shell's A.I Rankiteo Cyber Score in May 2026 ??
What was Shell's A.I Rankiteo Cyber Score in April 2026 ??
What was Shell's A.I Rankiteo Cyber Score in March 2026 ??
What was Shell's A.I Rankiteo Cyber Score in February 2026 ??
What was Shell's A.I Rankiteo Cyber Score in January 2026 ??
What was Shell's A.I Rankiteo Cyber Score in December 2025 ??
What was Shell's A.I Rankiteo Cyber Score in November 2025 ??
What was Shell's A.I Rankiteo Cyber Score in October 2025 ??
What was Shell's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Shell's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Shell ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Shell's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?