Shell is investigating a potential security incident at the centre of the Shell Clop data breach claims, after the Clop ransomware gang posted the company on its dark web leak site, alleging it had stolen 89GB of data including engineering drawings, facility testing reports, photographs and project plans.

A Shell spokesperson confirmed the situation to BleepingComputer in terse terms: ‘We are aware of a potential incident. We are working with our security teams and relevant experts to investigate.’ The company has not yet shared further detail, and its investigation is ongoing.

The PTC Vulnerability at the Root of the Attacks

Shell is one of 43 organisations Clop has listed as new victims in what appears to be a coordinated wave of attacks exploiting a critical flaw tracked as CVE-2026-12569. The vulnerability affects PTC Windchill PDMLink and FlexPLM, two enterprise platforms widely used by engineering, manufacturing and supply chain teams. According to SentinelOne, CVE-2026-12569 is a remote code execution vulnerability rooted in insecure deserialization of untrusted data, and it affects all CPS versions as well as Windchill and FlexPLM releases prior to version 11.0 M030.

PTC began releasing patches for the flaw on 17 June and, while it did not publicly confirm active exploitation at that point, it issued a private advisory urging customers to check their environments for indicators of compromise. The pace of events picked up sharply afterwards. On 26 June, PTC warned customers of ‘heightened threat activity.’ The US Cybersecurity and Infrastructure Security Agency then confirmed the vulnerability was being actively exploited in the wild, added it to its Known Exploited Vulnerabilities catalogue, and ordered federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

German authorities moved simultaneously. The Federal Office for Information Security issued a middle-of-the-night warning to PTC customers, urging them to patch as quickly as possible.

Shell Clop Data Breach Claims Sit Alongside GE and Philips

Shell is not the only large industrial name caught up in the campaign. Clop has also claimed it stole sensitive data from the networks of General Electric and Philips, including backups, system files, projects, drawings, diagrams and blueprints. Spokespersons for GE and Philips had not responded to requests for comment from BleepingComputer at the time of publication, and PTC had also yet to reply.

The attacks have been technically characterised by cybersecurity company ReliaQuest, which reported that the threat actors deployed JSP webshells to steal sensitive data from victims’ compromised PLM platforms. ReliaQuest has advised PTC customers to patch Windchill and FlexPLM immediately, place the systems behind VPNs or trusted access gateways where possible, isolate affected servers if compromise is suspected, collect forensic artefacts, and rotate any exposed credentials before restoring service.

The Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) also confirmed the Windchill and FlexPLM attacks independently.

Why the Victim List Spans So Many Sectors

PTC’s own figures indicate its products are used by over 30,000 customers globally, with more than 1,500 brand and retail customers using FlexPLM alone. That footprint explains the breadth of the victim pool. Help Net Security has confirmed that affected sectors include Manufacturing, Automotive, Aerospace, and Retail/Apparel, all industries where PLM systems hold precisely the kind of engineering and product data Clop has claimed to extract: drawings, blueprints, project plans and facility records.

PTC Windchill and FlexPLM sit at the core of how organisations track, design and manage products through to final manufacturing. That makes the data held in them commercially and operationally sensitive, and the combination of internet-exposed instances and an unpatched critical flaw a straightforward path for attackers working at scale.

Shell has not indicated whether any of the data Clop has posted or described relates to operational systems, and the company’s investigation continues. CISA’s three-day deadline for federal agencies to patch their own PTC instances has already passed, making the window for unpatched organisations in the private sector an active concern.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version