Clop has claimed 89GB of data was taken in what Shell calls a "potential incident" and that allegation sits amid broader, confirmed exploitation of a critical PTC vulnerability tracked as CVE-2026-12569.
Shell confirms an investigation after Clop's claim
Shell, the British multinational energy conglomerate with 85,000 employees in more than 70 countries and a network of tens of thousands of service and recharge stations serving over 20 million customers daily, told BleepingComputer it is "aware of a potential incident." A Shell spokesperson added, "We are working with our security teams and relevant experts to investigate." Beyond that statement the company has not publicly shared additional details.
Clop's allegations and the types of files listed
On Clop's dark web data leak site the group listed Shell among 43 newly named victims and said it had stolen 89GB of data. The files Clop claims to have published include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans. In the same series of attacks Clop also claimed to have taken backups, system files, projects, drawings, diagrams, and blueprints from networks belonging to General Electric and Philips; spokespeople for GE and Philips were not immediately available for comment when contacted.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCVE-2026-12569, PTC advisories, and government response
Clop's activity is tied in the reporting to attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569. PTC began releasing security patches for CVE-2026-12569 on June 17. Although PTC did not confirm in-the-wild exploitation at the time, it released a private advisory urging customers to review environments for indicators of compromise (IOCs).
After PTC warned customers of "heightened threat activity" on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the flaw is actively exploited in attacks, added it to its Known Exploited Vulnerabilities catalog, and ordered federal agencies to secure their PTC Windchill and FlexPLM instances within three days. German authorities also took emergency action: the Federal Office for Information Security (BSI) warned PTC customers in the middle of the night to patch systems as quickly as possible.
Technical confirmations and mitigation guidance from Ransom‑ISAC and ReliaQuest
The Ransomware Information Sharing and Analysis Centre (Ransom‑ISAC) confirmed Clop's Windchill and FlexPLM attacks, and cybersecurity company ReliaQuest reported the threat actors have been deploying JSP webshells that allow them to steal sensitive data from compromised PLM platforms. ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and, where possible, place them behind VPNs or trusted access gateways.
ReliaQuest also recommended specific incident response steps when compromise is suspected: isolate affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service. Those steps are consistent with the guidance PTC urged when it distributed patches and private advisories.
What this means for PTC customers, federal agencies, and Shell
- PTC customers and engineering teams: Windchill and FlexPLM are product lifecycle management platforms used to track, design, and manage products to final manufacturing, and PTC says over 30,000 customers use its products globally, including more than 1,500 brand and retail customers on FlexPLM. Those customers face direct operational and intellectual‑property risk if their internet‑exposed instances are not patched or placed behind trusted access gateways.
- Federal agencies and regulators: CISA's three‑day order to secure PTC instances signals urgency for government operators to apply patches and validate IOCs in their environments — an action already mirrored by BSI's emergency warning to German customers.
- Shell's security teams and supply‑chain partners: Shell has acknowledged only that it is investigating, but the Clop claims — if verified — point to potential exposure of engineering drawings, facility testing reports and project plans, assets that could have operational and procurement implications until the investigation concludes.
ReliaQuest's observations underscore a technical nuance the Blue Report 2026 highlighted: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." That assessment, measured across 338 million simulations in customer production environments according to the report, stresses why defenders are pushing both rapid patching and post‑compromise controls such as credential rotation and forensic collection.
Shell's investigation and the wider set of PTC‑related compromises reported by Clop, Ransom‑ISAC, and ReliaQuest leave two concrete actions visible today: affected organizations need to confirm whether internet‑exposed PTC Windchill and FlexPLM instances are patched and to look for JSP webshell indicators; and federal and regulated entities already subject to CISA and BSI urgings must demonstrate remediation within the timelines those authorities set. Beyond that, the public record in this case awaits the outcome of Shell's internal review and any forensic findings that may confirm or refute the claims posted on Clop's leak site.




