The Russia-linked ransomware group Cl0p has claimed a fresh wave of cyberattacks, naming Shell and Philips among its victims and, by some counts, dragging close to 50 companies into the mess.

It is a familiar sort of headline, and one that reads more than a little like a rerun of the Oracle-linked breaches that have unsettled corporate security teams for much of the year.

The numbers Cl0p is throwing around are not modest. From Shell, the group claims to have taken roughly 89GB of material, including technical drawings, images of facilities, scans of test reports, and project plans.

From Philips, it says it lifted about 13.5GB, mostly diagrams and blueprints. Other names circulating in coverage include GE and the financial-technology firm Fiserv.

Cl0p’s business model is not the noisy, lock-up-your-files kind of ransomware that once dominated the news. Instead it favours data-theft extortion: steal the files quietly, then lean on victims to pay by threatening to dump everything on a leak site. It is extortion by embarrassment, and it has proved lucrative.