Cybersecurity

Shell Investigates Potential Security Incident After Clop Claims Theft of 89 Gigabytes of Data

Shell confirmed that it is investigating a potential security incident after the Clop group claimed to have stolen 89 gigabytes of its data, including engineering drawings and project plans. The claim is part of attacks that exploited a critical vulnerability in the PTC Windchill and FlexPLM platforms to access data belonging to several organizations.

2026-08-14
3 min read
7 views
فريق تحرير certi.news
Shell Investigates Potential Security Incident After Clop Claims Theft of 89 Gigabytes of Data

Shell confirmed that it is investigating a potential security incident after the Clop ransomware group claimed to have stolen 89 gigabytes of the company’s data. Shell did not confirm that data had been stolen, but said it was working with the relevant security teams and experts to investigate the claim.

A Shell spokesperson told BleepingComputer: We are aware of a potential incident and are working with the relevant security teams and experts to investigate. The company has not yet provided additional information about the nature of the incident or the data that may have been accessed or stolen.

The Data Clop Claims to Have Stolen

Clop listed Shell on its dark web data-leak site and said the stolen files included engineering drawings, scanned copies of facility test reports, images of facilities, and project plans.

Shell is a British multinational energy group that employs 85,000 people in more than 70 countries. It also operates an extensive network of service stations and charging stations that serve more than 20 million customers daily, according to the information provided in the report.

The Attack’s Connection to a Vulnerability in PTC Platforms

Shell was included on a list of 43 new victims that were likely targeted in data-theft attacks exploiting internet-exposed instances of the PTC Windchill and PTC FlexPLM platforms. The attacks took advantage of a critical input-validation vulnerability identified as CVE-2026-12569.

Windchill and FlexPLM are used to manage the product life cycle, including tracking, designing, and managing products through final manufacturing. The platforms are widely used by engineering, manufacturing, quality, and supply-chain teams in the aerospace, defense, automotive, heavy-equipment, retail, and medical-technology sectors. PTC says its products are used by more than 30,000 customers worldwide, including more than 1,500 brands and retail customers that use FlexPLM.

Security Warnings and Patches

PTC began releasing patches for the vulnerability on June 17 and also issued specific guidance for customers, urging them to examine their environments for signs of compromise, although it had not confirmed at the time that the vulnerability was actually being exploited.

After PTC warned on June 26 of increasing threat activity, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the vulnerability was actively being exploited in attacks and added it to its Known Exploited Vulnerabilities Catalog, requiring federal agencies to secure their Windchill and FlexPLM instances within three days. Germany’s Federal Office for Information Security (BSI) also warned PTC customers about the vulnerability and urged them to install the updates as soon as possible.

Ransom-ISAC, which specializes in tracking and defending against ransomware threats, and cybersecurity company ReliaQuest confirmed that Clop attacks linked to the platforms had occurred. ReliaQuest said the attackers deployed JSP webshell files that enabled them to steal sensitive data from compromised product life-cycle management platforms.

Clop also claimed to have stolen sensitive data, including backups, system files, projects, drawings, and diagrams, from the networks of General Electric and Philips. Spokespeople for the two companies, along with a PTC spokesperson, had not immediately responded to requests for comment when the report was prepared.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news