Oil Giant Shell Investigates Potential Data Breach Following Clop Ransomware Claims
Global energy conglomerate **Shell** is investigating a potential security incident after the **Clop** ransomware gang claimed to have exfiltrated 89GB of sensitive data. This alleged breach is linked to a wider campaign exploiting a critical vulnerability in **PTC Windchill** and **FlexPLM** software, impacting numerous high-profile organizations.
Oil and gas giant **Shell** has confirmed it is investigating a potential security incident after the notorious **Clop** ransomware gang listed the company on its dark web data leak site. **Clop** claims to have stolen a substantial 89GB of data from **Shell**, a British multinational energy conglomerate with 85,000 employees across more than 70 countries.
According to **Clop**'s recent dark web post, the allegedly stolen files include critical engineering drawings, scans of facility testing reports, facility photographs, and project plans.
A **Shell** spokesperson stated, "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate."

### Exploiting PTC Windchill and FlexPLM Vulnerability
**Shell**'s inclusion on **Clop**'s leak site places it among 43 new victims believed to be targeted in data theft attacks exploiting a critical improper input validation vulnerability, **CVE-2026-12569**. This vulnerability affects Internet-exposed instances of **PTC Windchill** and **FlexPLM**.
In the same wave of attacks, **Clop** also claimed to have exfiltrated sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of technology conglomerates **General Electric** and **Philips**.

### Urgent Patches and Warnings
**PTC** began releasing security patches for **CVE-2026-12569** on June 17. While the company did not explicitly confirm in-the-wild exploitation, it issued a private advisory urging customers to review their environments for indicators of compromise (IOCs).
Following **PTC**'s warning of "heightened threat activity" on June 26, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** confirmed active exploitation of the flaw. **CISA** added **CVE-2026-12569** to its **Known Exploited Vulnerabilities catalog** and mandated federal agencies to secure their **PTC Windchill** and **FlexPLM** instances within three days.
German authorities, specifically the **Federal Office for Information Security (BSI)**, also took emergency action, issuing overnight warnings to **PTC** customers to patch their systems immediately.
### Widespread Impact on PLM Platforms
The **Ransomware Information Sharing and Analysis Centre (Ransom-ISAC)** and other security researchers have corroborated **Clop**'s exploitation of **Windchill** and **FlexPLM**. Threat actors have reportedly deployed JSP webshells to steal sensitive data from compromised Product Lifecycle Management (PLM) platforms.
**PTC FlexPLM** and **PTC Windchill** are widely adopted enterprise software platforms essential for tracking, designing, and managing products through their entire lifecycle, from concept to manufacturing. These systems are crucial for engineering, manufacturing, quality, and supply chain teams across diverse high-profile sectors, including aerospace, defense, automotive, heavy machinery, retail, and medtech. **PTC** boasts over 30,000 global customers, with more than 1,500 brand and retail clients utilizing **FlexPLM**.