Shell Investigates Clop Data Theft Claims Tied to PTC Flaw 

Shell is investigating a potential security incident after Clop claimed it stole 89 GB of data.

執筆者
Ken Underhill
Ken Underhill
Aug 14, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans. 

The claim places Shell among dozens of organizations reportedly targeted through vulnerable, internet-facing product lifecycle management (PLM) systems.

“We are aware of a potential incident. We are working with our security teams and relevant experts to investigate,” a Shell spokesperson told BleepingComputer.

Key takeaways

  • Shell is investigating a potential security incident after Clop claimed it stole 89 GB of engineering, facility, and project data.
  • Clop reportedly listed Shell among 43 new victims in a campaign targeting internet-exposed PTC Windchill and FlexPLM environments.
  • The attacks have been linked to CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM. 

Shell data theft claims linked to PTC vulnerability 

BleepingComputer reported that Shell was among 43 new organizations recently listed on Clop’s data leak site as part of a campaign targeting internet-exposed PTC Windchill and FlexPLM environments.

PTC Windchill and FlexPLM are product lifecycle management (PLM) platforms designed to help organizations manage product information and processes across areas such as design, engineering, manufacturing, and supply chain operations.

How CVE-2026-12569 puts PTC systems at risk 

The attacks have been linked to CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM. 

Improper input validation vulnerabilities occur when an application fails to adequately verify or restrict information it receives, potentially allowing attackers to manipulate the application in unintended ways.

Advertisement

What Clop claims it stole from Shell 

Clop claims that it stole approximately 89 GB of data from Shell, including engineering drawings, scans of facility testing reports, photographs of facilities, and project plans. 

If verified, the allegedly stolen files could provide insight into Shell’s projects, facilities, and engineering operations.

Shell has acknowledged that it is investigating a potential security incident with its security teams and relevant experts but has not confirmed if its systems were actually compromised or that any data was stolen.

How to mitigate PTC Windchill and FlexPLM risks 

Organizations using PTC Windchill and FlexPLM should take a layered approach to reducing the risk of exploitation and data theft. 

  • Apply patches for affected PTC Windchill and FlexPLM systems.
  • Restrict unnecessary internet exposure by placing PLM systems behind a zero-trust access layer.
  • Enforce phishing-resistant MFA when available and least-privilege access for users, administrators, and service accounts.
  • Use network segmentation, web application firewalls (WAFs), and egress filtering to limit unauthorized access, lateral movement, and data exfiltration.
  • Monitor application, authentication, endpoint, and network activity for suspicious behavior and indicators of compromise.
  • Rotate potentially exposed credentials, API keys, tokens, and other secrets, and hunt for IOCs of persistence if compromise is suspected.
  • Test incident response plans and use attack simulation tools with scenarios around data exfiltration and extortion.

Collectively, these steps can help organizations reduce their overall exposure while building resilience.

Bottom line

The Shell investigation highlights how compromised enterprise platforms containing sensitive engineering and operational data can give attackers leverage for extortion. 

Incidents like this can help frame board-level cyber risk around the business value of exposed data, the operational consequences of a compromise, and whether existing investments provide sufficient resilience against data theft and extortion. 

For organizations looking to reduce that exposure, a Zero Trust approach can help limit access to sensitive systems and data. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。