Published on August 14, 2026

Shell Investigates Potential Security Incident After Clop Claims 89GB Data Theft


Severity
Medium

Detail

Shell is investigating a potential security incident after the Clop ransomware group claimed it stole 89GB of data from the company. Clop’s dark web data leak site listed Shell among 43 new victims allegedly targeted in data theft attacks involving internet-exposed PTC Windchill and FlexPLM systems. The group claimed that the stolen Shell data includes engineering drawings, facility testing report scans, facility photographs and project plans. Shell has acknowledged the potential incident and said it is working with its security teams and relevant experts to investigate.

How?

The incident is reportedly linked to attacks against internet-exposed PTC Windchill and FlexPLM deployments exploiting the critical vulnerability CVE-2026-12569. The vulnerability has been actively exploited by threat actors, with attackers reportedly deploying JSP web shells to compromised PLM platforms and using them to steal sensitive information.

PTC began releasing security patches for CVE-2026-12569 on June 17 and subsequently urged customers to review their environments for indicators of compromise. CISA later confirmed active exploitation and added the vulnerability to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure affected systems.

Impact

According to Clop’s claims, the attackers allegedly accessed 89GB of Shell data, including engineering drawings, facility testing reports, facility photographs, and project plans. Other organizations reportedly targeted in the same campaign include General Electric and Philips, with Clop claiming to have stolen sensitive information such as backups, system files, projects, drawings, diagrams, and blueprints.

The campaign affects PTC Windchill and FlexPLM environments, which are used by engineering, manufacturing, quality, and supply chain teams across sectors including aerospace, defense, automotive, heavy machinery, retail, and medtech. PTC states that its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers using FlexPLM.

Recommendation

PTC customers should patch Windchill and FlexPLM systems against CVE-2026-12569. Where possible, affected systems should be placed behind VPNs or trusted access gateways. Organizations that suspect compromise should isolate affected servers, collect forensic artifacts, and rotate exposed credentials before restoring services, as advised by ReliaQuest. PTC customers should also review their environments for indicators of compromise, following PTC’s advisory.

Conclusion

The reported Shell incident highlights the ongoing exploitation of CVE-2026-12569 against internet-exposed PTC Windchill and FlexPLM environments. While Shell has confirmed only that it is investigating a potential incident, Clop claims to have stolen 89GB of data containing engineering and facility-related information.

Organizations using these PTC platforms should prioritize patching, restrict external access where possible, and investigate their environments for potential compromise.

Source

https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/