Bottom line: Clop is exploiting the critical PTC Windchill/FlexPLM vulnerability CVE-2026-12569 and lists Shell alongside at least 42 other companies as a victim, claiming to have stolen 89 GB of data.
The ransomware group Clop claims to have stolen around 89 gigabytes of confidential corporate data from energy company Shell. Shell confirms ongoing investigations, but details on the scope remain unclear.
The British energy company Shell is currently examining a possible security incident in its IT systems. The extortion group Clop has listed Shell on its darknet leak platform alongside 42 other companies as a new victim, claiming to have stolen around 89 GB of sensitive data — including technical design drawings, facility test reports, photographs of installations, and strategic project plans. A Shell spokesperson told media outlets: “We are aware of a potential incident. We are working with our security teams and relevant experts to investigate it.” The company has so far not provided specific details on the extent of the impact. Other major corporations such as General Electric and Philips are also said to be targeted in the ongoing Clop campaign.
Security analysts identified a critical vulnerability in the product lifecycle management platforms PTC Windchill and FlexPLM as the entry point, tracked under the identifier CVE-2026-12569. Security firms such as ReliaQuest and the organization Ransom-ISAC confirmed active exploitation of the flaw: attackers deploy JSP web shells on publicly accessible servers to exfiltrate development and corporate data. CISA and the BSI had already warned of the acute threat back in June and called for immediate remediation of the vulnerability.
For CISOs, it is relevant that the affected PTC software is used worldwide by more than 30,000 customers in sectors such as aerospace, automotive manufacturing, mechanical engineering, and energy — industries with a high proportion of intellectual property embedded in development data. A successful compromise of Windchill or FlexPLM can therefore directly lead to the leakage of design data and strategic project information, as the Shell case demonstrates. The broad victim list of the Clop campaign points to systematic exploitation of the vulnerability across multiple industries, rather than an isolated single case.
Operators of PTC products should immediately apply the security patches provided by PTC for Windchill and FlexPLM, place affected systems behind secured VPNs or trusted gateways, and, in the event of suspected compromise, isolate affected servers, preserve forensic evidence, and renew all access credentials.
Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.