Shell Investigates Clop Data Theft Claims Tied to PTC Flaw 

Shell is investigating a potential security incident after Clop claimed it stole 89 GB of data.

Written By
Ken Underhill
Ken Underhill
Aug 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans. 

The claim places Shell among dozens of organizations reportedly targeted through vulnerable, internet-facing product lifecycle management (PLM) systems.

“We are aware of a potential incident. We are working with our security teams and relevant experts to investigate,” a Shell spokesperson told BleepingComputer.

Key takeaways

  • Shell is investigating a potential security incident after Clop claimed it stole 89 GB of engineering, facility, and project data.
  • Clop reportedly listed Shell among 43 new victims in a campaign targeting internet-exposed PTC Windchill and FlexPLM environments.
  • The attacks have been linked to CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM. 

Shell data theft claims linked to PTC vulnerability 

BleepingComputer reported that Shell was among 43 new organizations recently listed on Clop’s data leak site as part of a campaign targeting internet-exposed PTC Windchill and FlexPLM environments.

PTC Windchill and FlexPLM are product lifecycle management (PLM) platforms designed to help organizations manage product information and processes across areas such as design, engineering, manufacturing, and supply chain operations.

How CVE-2026-12569 puts PTC systems at risk 

The attacks have been linked to CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM. 

Improper input validation vulnerabilities occur when an application fails to adequately verify or restrict information it receives, potentially allowing attackers to manipulate the application in unintended ways.

Advertisement

What Clop claims it stole from Shell 

Clop claims that it stole approximately 89 GB of data from Shell, including engineering drawings, scans of facility testing reports, photographs of facilities, and project plans. 

If verified, the allegedly stolen files could provide insight into Shell’s projects, facilities, and engineering operations.

Shell has acknowledged that it is investigating a potential security incident with its security teams and relevant experts but has not confirmed if its systems were actually compromised or that any data was stolen.

How to mitigate PTC Windchill and FlexPLM risks 

Organizations using PTC Windchill and FlexPLM should take a layered approach to reducing the risk of exploitation and data theft. 

  • Apply patches for affected PTC Windchill and FlexPLM systems.
  • Restrict unnecessary internet exposure by placing PLM systems behind a zero-trust access layer.
  • Enforce phishing-resistant MFA when available and least-privilege access for users, administrators, and service accounts.
  • Use network segmentation, web application firewalls (WAFs), and egress filtering to limit unauthorized access, lateral movement, and data exfiltration.
  • Monitor application, authentication, endpoint, and network activity for suspicious behavior and indicators of compromise.
  • Rotate potentially exposed credentials, API keys, tokens, and other secrets, and hunt for IOCs of persistence if compromise is suspected.
  • Test incident response plans and use attack simulation tools with scenarios around data exfiltration and extortion.

Collectively, these steps can help organizations reduce their overall exposure while building resilience.

Bottom line

The Shell investigation highlights how compromised enterprise platforms containing sensitive engineering and operational data can give attackers leverage for extortion. 

Incidents like this can help frame board-level cyber risk around the business value of exposed data, the operational consequences of a compromise, and whether existing investments provide sufficient resilience against data theft and extortion. 

For organizations looking to reduce that exposure, a Zero Trust approach can help limit access to sensitive systems and data. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.