Shell investigates ‘potential incident’ after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.

Shell is a British multinational energy conglomerate and one of the world’s top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily.

According to a recent post on Clop’s dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.

“We are aware of a potential incident. We are working with our security teams and relevant experts to investigate,” a Shell spokesperson told BleepingComputer when asked to confirm Clop’s data theft claims.

While the company has yet to share more information, the Clop gang listed it on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.

As part of the same attacks, Clop also claimed it stole sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of tech conglomerates General Electric and Philips.

GE and Philips spokespersons were not immediately available for comment when BleepingComputer contacted them earlier today. A PTC spokesperson has also yet to reply to a request for comment.

​PTC began releasing CVE-2026-12569 security patches on June 17 and, even though it didn’t confirm in-the-wild exploitation, it also released a private advisory urging customers to review environments for indicators of compromise (IOCs).

After PTC warned customers of “heightened threat activity” on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog, and ordering federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch their systems as quickly as possible.

Clop’s Windchill and FlexPLM attacks were also confirmed by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats, and by cybersecurity company ReliaQuest, which said that the threat actors have been deploying JSP webshells that allow them to steal sensitive data from victims’ compromised PLM platforms.

ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and, where possible, place them behind VPNs or trusted access gateways. Additionally, if compromise is suspected, they should isolate affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.

PTC FlexPLM and PTC Windchill are enterprise software platforms in the Product Lifecycle Management (PLM) category, used to track, design, and manage products up to final manufacturing.

The two systems are widely popular among engineering, manufacturing, quality, and supply chain teams at high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says that its products are used by over 30,000 customers globally, including more than 1,500 brand and retail customers using FlexPLM.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Clop ransomware targets Windchill, FlexPLM in data theft attacks

Data analyst sent to prison for stealing data, extorting employer

“City-Forum” data-theft attacks target Salesforce, ServiceNow portals

Wesco confirms security incident after ExfilSquad claims data theft

Metabase SQLi zero-day exploited in customer data-theft attacks

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Stop AI slopsquatting attacks. Secure open source package ingestion before it hits your build.

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Overdue a password health-check? Audit your Active Directory for free

Overdue a password health-check? Audit your Active Directory for free

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.