Skip to content

Clop extortion: Shell investigates suspected data theft via PTC Windchill flaw

Bottom line: Clop is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill/FlexPLM to steal data from Shell and at least 42 other companies, even though CISA and BSI had already warned about the flaw back in June.

The ransomware group Clop claims to have stolen around 89 gigabytes of confidential corporate data from energy company Shell. A critical vulnerability in the PTC platforms Windchill and FlexPLM is believed to be the entry point, which CISA and BSI had already classified as actively exploited back in June.

Shell is currently investigating a potential security incident in its IT systems. The ransomware group Clop lists the British energy company as a new victim on its darknet extortion platform, alongside 42 other companies, allegedly including General Electric and Philips. According to the attackers, the stolen files include technical design drawings, equipment test reports, photographs of facilities, and strategic project plans. A Shell spokesperson confirmed to media outlets that investigations are ongoing together with internal security teams and external experts, but has not yet provided further details on the scope of the impact.

Security analysts have identified a critical vulnerability in the product lifecycle management platforms PTC Windchill and FlexPLM, tracked under the identifier CVE-2026-12569, as the entry point. Security firms ReliaQuest and the organization Ransom-ISAC confirm active exploitation of the flaw: attackers are deploying JSP web shells on publicly accessible servers to exfiltrate development and corporate data. Both the US agency CISA and Germany’s BSI had already warned about the threat in June and ordered immediate remediation of the flaw.

For CISOs, it is relevant that the affected PTC software is used worldwide by more than 30,000 customers in sectors such as aerospace, automotive, mechanical engineering, and energy — sectors with a high proportion of intellectual property embedded in design data and manufacturing processes. The case once again illustrates Clop’s pattern of exploiting critical vulnerabilities in product lifecycle and file management software at scale before patches are widely deployed.

Security experts recommend that operators of Windchill and FlexPLM immediately apply the patches provided by PTC, place the systems behind secured VPNs or trusted gateways, and, in the event of suspected compromise, isolate affected servers, preserve forensic evidence, and fully rotate all credentials.


Source: www.it-daily.net · Published August 17, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: