Cybersecurity

Shell and Philips Reports: Backups Do Not Undo Data Theft

The Shell and Philips reporting highlights a practical distinction: backups help restore operations, while access controls and monitoring address data theft risk.

Backups can help restore your business after files are damaged, deleted, or encrypted. They cannot retrieve copies someone has already stolen. That distinction matters because getting systems running again does not resolve the exposure of confidential drawings, customer records, or internal documentation. Recovery and confidentiality need separate controls, separate owners, and separate response plans.

What the reporting actually establishes

In its October 8, 2026 report, NL Times attributed reporting about alleged publication of Shell and Philips data to a BNR investigation. The theft claims originated in August; October 8 was the publication date, not an established date of a new intrusion. According to NL Times, BNR reviewed files presented as Philips data and sent several to Philips for verification. BNR could not access the Shell data. That distinction limits the evidence: reviewing files is not the same as company confirmation, and the report does not independently establish the Shell data’s contents. Shell and Philips had told BNR in August that they were investigating.

Availability is not confidentiality

A backup answers a specific question: can we recover a usable copy of what the business needs? It does not answer who else has that information.

Consider a company that restores a project folder after an incident. Employees may regain access to schedules, pricing, and engineering documents. If someone copied that folder beforehand, the restored version does nothing to remove the unauthorized copy.

This is why a successful restore should not automatically close an incident. The organization may still need to determine what was accessed, preserve evidence, restrict compromised identities, and coordinate communications. Those are distinct tasks, not shortcomings in the backup itself.

Encryption at rest has a boundary

Encryption at rest protects stored data under specific conditions, such as someone obtaining storage media without the necessary keys. It is valuable, but it does not make every authorized access path safe.

When a compromised account has permission to open a document, the application may decrypt and deliver that document normally. The attacker is using access the system believes is legitimate. Encryption remains in place while confidentiality is lost through the account.

The practical response is layered protection: stronger authentication, controlled sessions, narrower permissions, and monitoring of sensitive access. Do not treat an encryption checkbox as proof that stolen credentials cannot expose readable files.

Limit access before you need containment

Least privilege means giving people and applications only the access their work requires. For a Dallas-Fort Worth business, that often starts with ordinary shared folders and cloud workspaces—not an expensive new platform.

Separate finance, personnel, customer, and technical information according to actual job responsibilities. Remove former employees promptly. Review outside collaborators and service accounts. Avoid giving routine user accounts administrative privileges simply because it makes support easier.

Also examine accumulated access. Someone who changed departments may still retain permissions from a previous role. A vendor account may remain active after a project ends. Reducing those permissions limits potential exposure if an account is compromised, although it cannot eliminate risk.

Watch for data leaving, not just systems failing

Data theft may occur without obvious downtime. Monitoring should therefore include outbound movement, often called egress, alongside malware and availability alerts.

Useful signals can include unusual bulk downloads, new external sharing links, unexpected transfers to unfamiliar destinations, and access patterns that do not match an account’s normal work. None proves theft by itself. A legitimate migration or large project handoff can produce similar activity.

The operational question is who investigates, using which logs, and with what authority to restrict access. An alert nobody owns is not a response process. Discuss these requirements when evaluating managed IT and security services, including visibility gaps and the cost of retaining useful logs.

A practical review checklist

Use this checklist with your internal team or IT provider:

  • Locate sensitive information. Identify its business owner, storage locations, and approved users.
  • Review permissions. Check shared folders, external sharing, privileged accounts, and inactive identities.
  • Protect recovery copies. Separate backup administration from routine access where practical, and test restoration.
  • Define theft indicators. Choose meaningful download, sharing, and outbound-transfer alerts.
  • Assign response ownership. Document who investigates, preserves evidence, and approves containment.
  • Set recovery expectations. Agree on priorities and dependencies; a response SLA is not a recovery guarantee.
  • Review actual costs. Account for continuity, cloud, storage, and hardware requirements rather than assuming backups cover everything.

FAQ

Are backups still worth maintaining?

Yes. They remain essential for restoring availability after many kinds of disruption. Test them against business priorities, but do not describe them as protection that reverses disclosure.

Does a working backup remove an extortion decision?

No. Data exposure can create pressure even when recovery is possible. Decisions require incident-specific evidence and appropriate specialist input. This is not legal advice, and no provider should promise that a business will never face a payment decision.

What should we review first?

Start with sensitive data access and recovery evidence. At Spryder Technologies, we use flat-rate service with no hourly billing and no long-term contracts: we win your business every day. Continuity, cloud, storage, and hardware carry real, client-agreed costs. Request a review to examine permissions, monitoring ownership, and restore-test results together.

Sources

Talk to a technology expert or call 844-SPRYDER.