Shell investigates ‘potential incident’ after Clop data theft claims

Oil giant Shell has found itself at the center of a potential cybersecurity incident after a notorious ransomware gang claimed to have stolen 89GB of sensitive data. The Clop gang, known for its brazen data theft attacks, published a list on its dark web leak site that includes Shell as one of 43 new victims allegedly targeted in recent weeks.

According to the list, the stolen files from Shell include engineering drawings, facility testing reports, and project plans. While Shell has yet to confirm the extent of the breach, the company’s spokesperson told BleepingComputer that it is “aware of a potential incident” and is working with security teams to investigate.

But what makes this case particularly concerning is the fact that Clop allegedly stole data from the networks of other major companies, including General Electric and Philips. These two conglomerates are among many that have been affected by a critical vulnerability in PTC Windchill and FlexPLM software platforms, which has been actively exploited by attackers.

PTC Windchill and FlexPLM are enterprise software platforms used for product lifecycle management, widely adopted by engineering, manufacturing, and quality teams at high-profile companies across various industries. The vulnerability, tracked as CVE-2026-12569, was patched by PTC in June, but the company warned customers of “heightened threat activity” just days later.

The US Cybersecurity and Infrastructure Security Agency (CISA) quickly added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to secure their PTC Windchill and FlexPLM instances within three days. German authorities also took emergency action, warning PTC customers in the middle of the night to patch their systems as quickly as possible.

The Clop gang’s attacks on PTC Windchill and FlexPLM platforms have been confirmed by several cybersecurity companies, including ReliaQuest, which advised PTC customers to patch their systems, place them behind VPNs or trusted access gateways, and isolate affected servers in the event of a suspected compromise.

This incident serves as a stark reminder of the importance of timely vulnerability patching and proactive threat defense. It also highlights the need for organizations to prioritize security measures beyond just prevention, including detection and response capabilities.

So what can Shell and other companies do to mitigate this risk? First and foremost, they should review their systems for indicators of compromise (IOCs) and take immediate action to patch any affected software platforms. This includes PTC Windchill and FlexPLM instances, which are still vulnerable to exploitation even after the June patches.

By taking these steps, companies can reduce the likelihood of a successful attack and minimize the damage if one occurs. It’s also essential for organizations to prioritize incident response planning and have a robust detection and response strategy in place to quickly identify and contain potential security incidents.


Source: Bleeping Computer — 2026-08-14