← Shell Plc

2021 Shell — Accellion FTA zero-days; personal & corporate files accessed from isolated transfer appliance (Mar)

2021 Unknown records affected Share on X

Data compromised

Unspecified mixture of personal and B2B stakeholder files per Shell’s summary—no consolidated public row count

Technical writeup

Shell joined a long roster of Accellion File Transfer Appliance (FTA) customers confirming data touched the legacy SaaS appliance after December 2020 exploitation of multiple chainable CVEs detailed in joint government guidance. SecurityWeek quoted Shell saying core enterprise IT stayed isolated, but personal and some Shell corporate / stakeholder documents transited the compromised FTA during a limited window, prompting regulator outreach without publishing a numeric census. CISA AA21-055A documents the global Accellion campaign spanning energy sector victims and extortion follow-on—useful technical context for the `shell-plc` directory slug mirroring the public Royal Dutch Shell / Shell plc disclosure narrative.

Root cause

Unpatched third-party managed file-transfer edge appliance exploited for data theft and extortion

References