Published Security3 min read
Clop names 43 victims from a PTC Windchill flaw, and Shell confirms it is investigating
CVE-2026-12569 is on CISA's exploited list and drew a middle-of-the-night warning from Germany's BSI. The systems it lives in are rarely on anyone's asset inventory.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Oil giant Shell confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
- A Shell spokesperson told BleepingComputer: "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate."
- Clop listed Shell on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
- According to a post on Clop's dark web leak site, the allegedly stolen Shell files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
- As part of the same attacks, Clop claimed it stole sensitive data including backups, system files, projects, drawings, diagrams, and blueprints from the networks of General Electric and Philips.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data from the company [1]. Shell is one of 43 new victims Clop listed in a campaign against Internet-exposed PTC Windchill and FlexPLM instances, exploiting a critical improper input validation flaw tracked as CVE-2026-12569 [3].
"We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer [2]. Clop's leak site post describes engineering drawings, scans of facility testing reports, photos of facilities, and project plans [4]. In the same wave, Clop claimed it took backups, system files, projects, drawings, diagrams, and blueprints from General Electric and Philips [5]. Spokespeople for GE and Philips were not immediately available for comment, and PTC had not replied to BleepingComputer's request [6].
The exploitation timeline is unusually compressed. PTC began releasing patches for CVE-2026-12569 on June 17, and while it did not confirm in-the-wild exploitation, it issued a private advisory telling customers to review their environments for indicators of compromise [7]. On June 26 it warned of "heightened threat activity" [8], nine days later [14]. CISA then confirmed active exploitation, added the flaw to its Known Exploited Vulnerabilities catalog, and gave federal agencies three days to secure their Windchill and FlexPLM instances [9]. Germany's Federal Office for Information Security warned PTC customers in the middle of the night to patch as fast as possible [10]. A private IOC advisory before public confirmation of exploitation, followed by a three-day federal deadline, is the shape of a vendor and a regulator both discovering the same thing at different speeds.
The Ransomware Information Sharing and Analysis Centre and ReliaQuest have both confirmed the Windchill and FlexPLM attacks, with ReliaQuest reporting that the attackers deployed JSP webshells to steal data from compromised PLM platforms [11]. JSP webshells on an application server are not exotic; they are what you get when a web-facing Java application accepts input it should not.
The reason this campaign yields blueprints rather than payroll files is what these systems are. Windchill and FlexPLM are product lifecycle management platforms used to track, design, and manage products through to final manufacturing [12], and they sit with engineering, manufacturing, quality, and supply chain teams across aerospace, defense, automotive, heavy machinery, retail, and medtech [13]. PTC says its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers on FlexPLM [15]. That is a large exposed surface owned, in most organisations, by engineering rather than IT, which is exactly why it tends to be missing from the asset inventory the security team actually maintains.
Of the 43 listed victims, three have been publicly named so far, leaving 40 organisations that have not been [16]. Shell alone runs 85,000 employees in more than 70 countries [17]. Expect that gap to close over the next several weeks as Clop works its posting schedule and disclosure obligations catch up.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Oil giant Shell confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
- [2]
A Shell spokesperson told BleepingComputer: "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate."
- [3]
Clop listed Shell on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
- [4]
According to a post on Clop's dark web leak site, the allegedly stolen Shell files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
- [5]
As part of the same attacks, Clop claimed it stole sensitive data including backups, system files, projects, drawings, diagrams, and blueprints from the networks of General Electric and Philips.
- [6]
GE and Philips spokespersons were not immediately available for comment when BleepingComputer contacted them, and a PTC spokesperson had yet to reply to a request for comment.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu GatlanAug 14Shell investigates 'potential incident' after Clop data theft claims
- bleepingcomputer.comSergiu Gatlan6d agoPhilips and GE investigating Clop ransomware data theft claims
Additional citations
- BleepingComputer
- Shell spokesperson via BleepingComputer
- Clop leak site, via BleepingComputer



