Shell is investigating a potential cybersecurity incident after the Clop ransomware group claimed it stole 89GB of data from the energy company.
Shell is a British multinational energy company and one of the world’s largest oil and gas firms. The company employs approximately 85,000 people across more than 70 countries and operates a global network of service stations and electric vehicle charging sites serving more than 20 million customers each day.
In a recent post on its dark web data leak site, Clop claimed that the stolen information includes engineering drawings, facility test report scans, photographs, and project plans.
When asked to comment on Clop’s data theft claims, a Shell spokesperson told BleepingComputer: “We are aware of the potential incident and are investigating it in collaboration with our security team and relevant experts.”
Shell has not released additional details about the incident. However, Clop listed the company among 43 new victims allegedly targeted through internet-exposed PTC Windchill and FlexPLM systems. The attacks exploited a critical improper input validation vulnerability tracked as CVE-2026-12569.
Clop has also claimed to have stolen sensitive information—including backups, system files, projects, drawings, diagrams, and blueprints—from the networks of technology companies General Electric and Philips as part of the same campaign.
Spokespeople for GE and Philips did not immediately respond to requests for comment from BleepingComputer. PTC also had not responded at the time of publication.

PTC released a security patch for CVE-2026-12569 on June 17. Although the company said there was no confirmed exploitation in the field at that time, it urged customers to review their environments for indicators of compromise (IOCs) through its security advisory.
After PTC warned customers on June 26 about “increased threat activity,” the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the vulnerability was being actively exploited. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities Catalog and directed federal agencies to secure affected PTC Windchill and FlexPLM systems within three days.
The vulnerability also prompted urgent action from German authorities. The German Federal Office for Information Security (BSI) warned PTC customers to patch their systems as soon as possible.
Clop’s exploitation of Windchill and FlexPLM systems has also been documented by the Ransomware Information Sharing and Analysis Center (Ransom-ISAC), a nonprofit organization that tracks and helps defend against ransomware threats.
Cybersecurity company ReliaQuest reported that the attackers are deploying a JavaServer Pages (JSP) web shell to maintain access and steal sensitive information from compromised product lifecycle management platforms.
ReliaQuest recommends that PTC customers patch Windchill and FlexPLM systems and, where possible, place them behind a virtual private network (VPN) or trusted access gateway. Organizations that suspect a compromise should isolate affected servers, preserve forensic evidence, rotate exposed credentials, and only restore services after completing an investigation.
PTC FlexPLM and PTC Windchill are enterprise product lifecycle management (PLM) platforms used to design, track, and manage products through manufacturing.
The platforms are widely used by engineering, manufacturing, quality, and supply chain teams in industries including aerospace, defense, automotive, heavy equipment, retail, and medical technology. PTC says its products serve more than 30,000 customers worldwide, including over 1,500 brands and retailers that use FlexPLM.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




