Shell investigates ‘potential incident’ after Clop data theft claims

Oil Giant Shell Investigates Potential Data Breach Amid Ransomware Claims

Shell, one of the world’s largest oil and gas companies, is currently investigating a potential security incident after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive data. The alleged heist includes engineering drawings, facility testing reports, project plans, and other confidential information.

The breach is believed to be linked to vulnerabilities in PTC’s Windchill and FlexPLM software platforms, which are widely used by high-profile companies across various industries for product lifecycle management. Clop’s attack on these platforms is part of a larger campaign that has already targeted numerous organizations, including tech conglomerates General Electric and Philips.

According to security researchers, the attackers exploited a critical vulnerability (CVE-2026-12569) in PTC’s Windchill and FlexPLM instances, which was first patched by PTC on June 17. Despite this, many companies failed to apply the necessary patches, leaving their systems exposed to potential attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had already warned of the vulnerability’s exploitation in real-world attacks, prompting emergency action from German authorities and a private advisory from PTC urging customers to review their environments for signs of compromise.

As part of its investigation, Shell is working closely with security teams and experts to assess the scope of the potential breach. While the company has not yet shared further details, the incident serves as a stark reminder of the importance of timely patching and vigilance in the face of evolving cyber threats.

The aftermath of this attack also highlights the need for companies to prioritize robust cybersecurity measures, including regular software updates, employee training, and incident response planning. As more organizations fall victim to ransomware attacks, it’s essential that they take proactive steps to protect themselves against similar incidents.

For users of PTC Windchill and FlexPLM platforms, this attack serves as a wake-up call to review their security posture and ensure they are in compliance with the latest patching requirements. Additionally, companies should consider implementing additional security measures, such as isolating affected servers, collecting forensic artifacts, and rotating exposed credentials.

Ultimately, the Shell investigation underscores the ever-present threat of data breaches and ransomware attacks, which can have devastating consequences for organizations that fail to prioritize cybersecurity. As the cyber landscape continues to evolve, it’s crucial that companies remain vigilant and proactive in their approach to protecting sensitive information.


Source: Bleeping Computer — 2026-08-14