Energy company Shell is investigating a possible cybersecurity incident after the Clop ransomware group claimed to have stolen 89GB of company data. The alleged breach comes amid a wider Clop campaign targeting organizations running internet-accessible PTC Windchill and FlexPLM systems.

 

 

Shell acknowledged the situation after Clop added the company to its dark web leak site. A company spokesperson said Shell was aware of a potential incident and had brought in its security teams and relevant specialists to investigate. Shell has not yet confirmed that the attackers obtained the files described by Clop.

According to the cybercriminal group’s claims, the stolen material includes engineering drawings, facility photographs, project plans and scanned reports connected to facility testing. Those details remain allegations from Clop while Shell’s investigation continues, and the company has not publicly confirmed the volume or contents of any compromised information.

The timing links Shell’s appearance on Clop’s leak site with a much broader series of attacks. Shell was one of 43 newly listed organizations believed to have been targeted through exposed instances of PTC’s Windchill and FlexPLM product lifecycle management software. Clop has also claimed data theft from General Electric and Philips as part of the same activity.

The attacks have been associated with CVE-2026-12569, a critical vulnerability affecting PTC Windchill and FlexPLM. PTC says the security flaw can allow an unauthorized attacker to remotely execute code. The company began providing remediation guidance in June and subsequently released security patches covering affected versions of both platforms.

PTC also documented indicators showing attackers deploying persistent JSP webshells into Windchill’s login directory. Such webshells can provide remote command execution and facilitate data exfiltration from compromised servers. By late June, PTC was warning customers about continued “heightened threat activity” and urging immediate remediation.

Windchill and FlexPLM are used to manage information throughout the lifecycle of products, making compromised installations potentially valuable sources of corporate and engineering information. This corresponds with the types of material Clop claims to have obtained from Shell, including drawings and project documentation, although Shell has not confirmed that CVE-2026-12569 was the route used to access its systems.

PTC has continued updating its security guidance as additional indicators of compromise have emerged. The vendor advises customers to apply available patches immediately, examine their environments for known indicators, and restrict unnecessary internet exposure of Windchill login interfaces.

Clop’s latest activity appears focused heavily on stealing information rather than necessarily encrypting corporate systems. In the Windchill and FlexPLM campaign, compromised product-management servers can contain projects, technical drawings, diagrams, backups, and other internal files that can subsequently be used for extortion.

For Shell specifically, the confirmed information remains limited. The company has acknowledged that it is investigating a potential security incident, while the claim that 89GB of engineering and project-related information was stolen currently comes from Clop. Shell has not publicly confirmed the amount of affected data, the specific systems involved, or whether the PTC vulnerability was responsible for the potential compromise.

Leave a Reply