Published Security3 min read
Clop's 43-victim batch puts PLM servers, not file transfer, at the centre of mass exploitation
Shell says it is investigating after Clop claimed 89GB of engineering data. It is one of 43 names the gang tied to a single flaw in internet-exposed PTC Windchill and FlexPLM.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Shell confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data from the company.
- A Shell spokesperson told BleepingComputer: "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate."
- Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil, with 85,000 employees in more than 70 countries.
- According to a post on Clop's dark web data leak site, the allegedly stolen Shell files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
- Clop listed Shell on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data from the company [1]. Shell was listed as one of 43 new victims that Clop tied to data theft attacks against internet-exposed PTC Windchill and FlexPLM instances, exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569 [5].
"We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer [2]. According to Clop's dark web leak site post, the files taken from Shell include engineering drawings, scans of facility testing reports, photos of facilities, and project plans [4]. In the same campaign, Clop claimed it took backups, system files, projects, drawings, diagrams, and blueprints from General Electric and Philips [6]. Spokespeople for GE and Philips were not immediately available for comment, and PTC had not replied to a request for comment [7]. Shell employs 85,000 people in more than 70 countries and ranks behind only Chevron and ExxonMobil among oil and gas producers [3].
The patch timeline is the part worth studying. PTC began releasing fixes for CVE-2026-12569 on June 17, and while it did not confirm in-the-wild exploitation, it issued a private advisory telling customers to review their environments for indicators of compromise [8]. Nine days later, on June 26, PTC warned of "heightened threat activity", after which CISA confirmed active exploitation, added the flaw to its Known Exploited Vulnerabilities catalog, and gave federal agencies three days to secure their Windchill and FlexPLM instances [9][15]. Germany's Federal Office for Information Security went out in the middle of the night telling PTC customers to patch as quickly as possible [10]. A private IOC advisory alongside a patch is a strong tell that a vendor already knows what is happening; the public confirmation arrived after the harvest.
The tradecraft is unglamorous and repeatable. The Ransomware Information Sharing and Analysis Centre and the security firm ReliaQuest both confirmed the Windchill and FlexPLM attacks, with ReliaQuest reporting that the attackers deployed JSP webshells to steal data from compromised PLM platforms [11]. That is a single bug, a single webshell family, and a single application server tier, run at scale across dozens of organisations at once.
What makes this different from a document-transfer breach is where the data sits. Windchill and FlexPLM are product lifecycle management platforms used to track, design, and manage products through to final manufacturing [12], and they are in daily use by engineering, manufacturing, quality, and supply chain teams in aerospace, defence, automotive, heavy machinery, retail, and medtech [13]. A file transfer appliance holds whatever was in flight that week. A PLM instance holds the design record. PTC says its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers on FlexPLM [14], so the 43 named victims amount to roughly 0.1 percent of the installed base [16].
Watch whether the victim count climbs as Clop works through its staged leak schedule, whether GE, Philips, or PTC say anything on the record, and whether any of the 43 disclose that they were patched before June 26 and compromised anyway. Also worth watching: how many organisations discover their Windchill instance was internet-facing without anyone in security having put it there.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Shell confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data from the company.
- [2]
A Shell spokesperson told BleepingComputer: "We are aware of a potential incident. We are working with our security teams and relevant experts to investigate."
- [3]
Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil, with 85,000 employees in more than 70 countries.
- [4]
According to a post on Clop's dark web data leak site, the allegedly stolen Shell files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
- [5]
Clop listed Shell on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
- [6]
As part of the same attacks, Clop claimed it stole sensitive data including backups, system files, projects, drawings, diagrams, and blueprints from the networks of General Electric and Philips.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comSergiu GatlanAug 14Shell investigates 'potential incident' after Clop data theft claims
- bleepingcomputer.comSergiu Gatlan6d agoPhilips and GE investigating Clop ransomware data theft claims
Additional citations
- BleepingComputer
- Shell spokesperson, via BleepingComputer
- Clop leak site, via BleepingComputer




