Shell is investigating a potential cyber incident after the Clop ransomware group claimed it stole 89GB of data from the energy giant.

The alleged Shell data theft forms part of a wider campaign targeting internet-exposed PTC Windchill and FlexPLM systems. Clop has listed dozens of organisations on its data leak site and claims to have taken sensitive corporate files from several major companies.

Shell confirms investigation

A Shell spokesperson confirmed that the company is aware of the claims and has started an investigation.

“We are aware of a potential incident,” the spokesperson said. “We are working with our security teams and relevant experts to investigate.”

Shell has not confirmed that attackers accessed its systems or removed data. It has also not disclosed how the incident may have happened.

However, Clop claims it stole engineering drawings, facility testing reports, photographs of facilities and project plans. The group listed Shell among 43 new alleged victims on its dark web leak site.

Shell operates in more than 70 countries and employs around 85,000 people. Its global network includes thousands of fuel and charging locations serving more than 20 million customers each day.

Clop targets PTC Windchill and FlexPLM systems

The alleged Shell data theft appears linked to attacks against PTC Windchill and FlexPLM instances exposed to the internet.

Attackers have exploited CVE-2026-12569, a critical improper input validation vulnerability affecting the enterprise product lifecycle management platforms. PTC began issuing security updates for the flaw on 17 June.

The company later warned customers about heightened threat activity and urged them to check their environments for signs of compromise. Although PTC did not initially confirm active exploitation, US authorities later added the flaw to the Known Exploited Vulnerabilities catalog.

CISA ordered federal agencies to secure vulnerable Windchill and FlexPLM installations within three days. Germany’s Federal Office for Information Security also issued an urgent warning that called on affected organisations to patch their systems as quickly as possible.

Other major companies listed

Clop also claimed it stole sensitive files from General Electric and Philips during the same campaign. The group said the files included backups, system data, projects, drawings, diagrams and blueprints.

Neither company had publicly confirmed an incident at the time of reporting.

Ransom-ISAC and cybersecurity firm ReliaQuest have linked Clop to attacks exploiting the PTC vulnerability. ReliaQuest said the attackers deployed JSP webshells on compromised systems, allowing them to access and steal data from affected platforms.

Why Windchill and FlexPLM are attractive targets

PTC Windchill and FlexPLM help companies design, track and manage products throughout the manufacturing process.

Engineering, manufacturing, quality and supply-chain teams use the platforms across aerospace, defence, automotive, heavy machinery, retail and medical technology sectors. Because these systems can hold product plans, technical files and internal documents, they can offer attackers valuable data for extortion.

PTC says more than 30,000 customers use its products worldwide, including over 1,500 retail and brand customers that use FlexPLM.


0 responses to “Shell Investigates Potential Incident After Clop Claims 89GB Data Theft”