Threat Analysis: Clop's Managed File Transfer Playbook, ShinyHunters' SaaS Pivot, and a Maximum-Severity SAP Flaw Under Active Attack

Threats & Attacks

Threat Analysis: Clop's Managed File Transfer Playbook, ShinyHunters' SaaS Pivot, and a Maximum-Severity SAP Flaw Under Active Attack

Hello, Mauven here.

This is your Daily Threat Analysis for 14th August 2026.

Three distinct threat streams broke today. On their own, each is worth your attention. Together, they tell you something about where we actually are with supplier risk, SaaS security, and patch management, none of which the headlines are quite saying plainly enough.

Let’s go through them.


Clop Claims Shell. The Method Is Six Years Old.

The Clop ransomware group has claimed it stole 89GB of data from Shell, the oil and energy giant. Shell has confirmed it is investigating a potential security incident. The named vectors are PTC FlexPLM and PTC Windchill, both managed file transfer and product lifecycle management platforms.

The advisory coverage of this will focus on Shell. That is the wrong frame.

Team Cymru’s analysis of Clop across six years identifies a very specific pattern: the group systematically targets managed file transfer infrastructure. Not corporate endpoints. Not email. Not VPN. MFT platforms. They have run nine distinct campaigns against platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Each time, they find a zero-day or near-zero-day in the MFT tool, exploit it at scale before patches exist, extract data, and make claims.

What Clop understands, and what a great many organisations still don’t, is that managed file transfer tools are high-value, often poorly monitored, and frequently shared across supply chains. You don’t need to be Shell to be affected by a Clop campaign. You need to be in Shell’s supply chain, or in a supply chain that uses the same MFT platform.

The question for UK SMBs is not “do we use Shell’s software.” The question is: do you know which managed file transfer platforms your suppliers and partners use? If you’re a professional services firm, a manufacturer, a logistics business, or anyone who exchanges large volumes of data with enterprise clients, this question is not hypothetical.

PTC Windchill has a significant installed base in UK engineering and manufacturing. If you work with firms in those sectors, this is worth a conversation with your IT provider today.

What to check:

  • Ask your IT provider which MFT platforms are in use across your supplier connections
  • Review which suppliers have access to your data systems and under what conditions
  • Monitor NCSC advisories, if Clop’s PTC campaign expands, there will be published guidance

ShinyHunters Pivots From Data Theft to SaaS Infiltration

Two ShinyHunters stories landed today, and they need to be read together.

First: ShinyHunters breached RingCentral in July, exposing personal information from 1.6 million accounts. Have I Been Pwned has confirmed the breach. The data includes information from RingCentral’s user base, a communications platform used extensively by UK SMBs as a cloud phone and collaboration system.

If your business uses RingCentral, check your staff email addresses against Have I Been Pwned now. The exposed data creates material for targeted phishing and social engineering.

Second, and this is the part that matters more for how you respond, a Microsoft Security Blog analysis covering mid-2025 to mid-2026 documents ShinyHunters systematically abusing OAuth to compromise Salesforce and other SaaS platforms. The three primary intrusion paths they used:

  1. Voice phishing. Operators call staff, impersonate IT support, and instruct them to authorise a malicious OAuth application. The call sounds legitimate. The request looks like a standard app approval. The victim clicks approve and hands over persistent access to their SaaS environment.
  2. Supply chain compromise. Trusted integrations, including Salesloft, Gainsight, and others, were leveraged to pivot into customer Salesforce environments.
  3. Credential theft. Stolen credentials from breaches like the RingCentral incident are used to access connected SaaS platforms.

The advisory coverage of today’s RingCentral breach will not tell you that ShinyHunters is simultaneously running a sophisticated OAuth abuse campaign. It should. The breach and the campaign are the same group, and the exposed RingCentral data feeds directly into the vishing and credential-stuffing operations.

For UK SMBs, the practical implication is this: no legitimate IT team will call your staff and ask them to approve an application connection. That is not a normal thing that happens. If your staff don’t know that, they will approve it when it happens, because the caller will sound plausible and the request will seem routine.

This is a staff awareness gap, and it costs nothing to close.

What to do:

  • Check staff accounts against Have I Been Pwned (haveibeenpwned.com)
  • Brief staff that unsolicited requests to authorise OAuth applications, by phone, email, or Teams message, should be refused and reported
  • Review which third-party applications have OAuth access to your Microsoft 365 or Salesforce environment. Remove anything that doesn’t need to be there.
  • Enable conditional access policies on your SaaS platforms

SAP Commerce Cloud: Maximum Severity, Already Exploited

Three days ago, SAP patched a remote code execution vulnerability in SAP Commerce Cloud with a maximum severity rating. As of today, according to threat intelligence firm Defused, it is already being targeted in active attacks.

Three days from patch to active exploitation.

The NCSC has published guidance on patch management timelines multiple times. The fact that organisations are still operating with 30-day patch cycles when maximum-severity vulnerabilities are being weaponised inside 72 hours tells you everything about how seriously those timelines are being taken.

SAP Commerce Cloud is not a niche product. It is used extensively by retailers and e-commerce operators across the UK. If you are a retailer, or if you work with a managed service provider who supports retail clients, this is a conversation to have today rather than at next month’s review.

Ask your IT provider or MSP:

  • Which of our systems run SAP Commerce Cloud?
  • Has the patch been applied?
  • When?

If they can’t answer the third question, that tells you something.


The Pattern Underneath Today’s Stories

It’s worth stepping back for a moment, because today’s three stories are not unrelated.

Clop exploits supplier infrastructure, managed file transfer tools that exist in the gaps between organisations. ShinyHunters exploits SaaS integrations and the human layer, OAuth connections and staff who don’t recognise a social engineering call. And a maximum-severity SAP vulnerability is being actively exploited before most organisations have had a chance to patch.

What connects them is supplier and third-party exposure. You can have a reasonably well-managed internal environment and still be compromised through a supplier’s MFT platform, through an OAuth connection you authorised months ago and forgot about, or through a piece of software your MSP runs for you that hasn’t been patched.

Separately today, the Crown Office and Procurator Fiscal Service in Scotland confirmed a supplier data breach exposing staff names, roles, and email addresses. And Trezor confirmed that 13,000 customer details were exposed through a logistics supplier breach, nothing to do with Trezor’s own security. The hardware was fine. The logistics partner was not.

This is not a coincidence. Supplier risk is the dominant attack surface of 2026, and the threat groups know it.

If your organisation has not conducted a supplier security review in the last twelve months, you are operating with a blind spot that multiple active threat groups are specifically targeting.


Sources

SourceTitleURL
BleepingComputerShell investigates ‘potential incident’ after Clop data theft claimshttps://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
BleepingComputerRingCentral data breach exposed info of 1.6 million accountshttps://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
BleepingComputerMax severity SAP Commerce Cloud flaw now targeted in attackshttps://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/
Microsoft Security BlogDefending SaaS-based applications against ShinyHunters OAuth abusehttps://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/
Team CymruCl0p Ransomware: Attack Pattern in Threat Intelligencehttps://www.team-cymru.com/post/cl0p-ransomware-mft-attack-pattern-threat-intelligence
The RegisterScottish prosecutors cast eye over leaky supplier after staff data exposedhttps://www.theregister.com/security/2026/08/14/scottish-prosecutors-cast-eye-over-leaky-supplier-after-staff-data-exposed/5287479
The RegisterCrypto wallet maker Trezor confirms 13,000 customers’ details exposed in logistics breachhttps://www.theregister.com/security/2026/08/14/crypto-wallet-maker-trezor-confirms-13000-customers-details-exposed-in-logistics-breach/5287734

Before the next story: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically. And if someone in your network needs this, a client, a colleague, a business owner who thinks they’re too small to matter, pass it on. The groups we’ve covered today disagree with that assessment.

Mauven.

Filed under

  • ransomware-groups
  • supply-chain-risk
  • vendor-risk
  • smb-security
  • uk-business
  • cloud-security
  • incident-response