Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans.
The claim places Shell among dozens of organizations reportedly targeted through vulnerable, internet-facing product lifecycle management (PLM) systems.
“We are aware of a potential incident. We are working with our security teams and relevant experts to investigate,” a Shell spokesperson told BleepingComputer.
Key takeaways
- Shell is investigating a potential security incident after Clop claimed it stole 89 GB of engineering, facility, and project data.
- Clop reportedly listed Shell among 43 new victims in a campaign targeting internet-exposed PTC Windchill and FlexPLM environments.
- The attacks have been linked to CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM.
Shell data theft claims linked to PTC vulnerability
BleepingComputer reported that Shell was among 43 new organizations recently listed on Clop’s data leak site as part of a campaign targeting internet-exposed PTC Windchill and FlexPLM environments.
PTC Windchill and FlexPLM are product lifecycle management (PLM) platforms designed to help organizations manage product information and processes across areas such as design, engineering, manufacturing, and supply chain operations.
How CVE-2026-12569 puts PTC systems at risk
The attacks have been linked to CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM.
Improper input validation vulnerabilities occur when an application fails to adequately verify or restrict information it receives, potentially allowing attackers to manipulate the application in unintended ways.
What Clop claims it stole from Shell
Clop claims that it stole approximately 89 GB of data from Shell, including engineering drawings, scans of facility testing reports, photographs of facilities, and project plans.
If verified, the allegedly stolen files could provide insight into Shell’s projects, facilities, and engineering operations.
Shell has acknowledged that it is investigating a potential security incident with its security teams and relevant experts but has not confirmed if its systems were actually compromised or that any data was stolen.
How to mitigate PTC Windchill and FlexPLM risks
Organizations using PTC Windchill and FlexPLM should take a layered approach to reducing the risk of exploitation and data theft.
- Apply patches for affected PTC Windchill and FlexPLM systems.
- Restrict unnecessary internet exposure by placing PLM systems behind a zero-trust access layer.
- Enforce phishing-resistant MFA when available and least-privilege access for users, administrators, and service accounts.
- Use network segmentation, web application firewalls (WAFs), and egress filtering to limit unauthorized access, lateral movement, and data exfiltration.
- Monitor application, authentication, endpoint, and network activity for suspicious behavior and indicators of compromise.
- Rotate potentially exposed credentials, API keys, tokens, and other secrets, and hunt for IOCs of persistence if compromise is suspected.
- Test incident response plans and use attack simulation tools with scenarios around data exfiltration and extortion.
Collectively, these steps can help organizations reduce their overall exposure while building resilience.
Bottom line
The Shell investigation highlights how compromised enterprise platforms containing sensitive engineering and operational data can give attackers leverage for extortion.
Incidents like this can help frame board-level cyber risk around the business value of exposed data, the operational consequences of a compromise, and whether existing investments provide sufficient resilience against data theft and extortion.
For organizations looking to reduce that exposure, a Zero Trust approach can help limit access to sensitive systems and data.





