Shell probes possible data theft as Clop ransomware crew names it in engineering software raid
The gang claims 89GB of drawings and project files, part of a wider spree hitting PTC Windchill and FlexPLM systems.

Key points
- Shell says it is investigating a potential security incident after the Clop ransomware crew, a Russian-speaking extortion group, claimed to have stolen 89GB of its data.
- Clop listed Shell alongside 42 other alleged victims tied to attacks on PTC Windchill and FlexPLM, engineering software used to design and manage products.
- The attacks abuse CVE-2026-12569, a flaw that lets attackers slip bad input past the software's checks and take control.
- PTC began shipping patches on June 17; the U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities list after confirmed in-the-wild abuse.
- General Electric and Philips were also named on Clop's leak site as part of the same campaign.
Oil giant Shell has confirmed it is looking into a possible break-in after Clop, a long-running extortion crew, claimed on its dark web leak site to have stolen 89GB of company files.
"We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson said in a statement first carried by BleepingComputer.
Clop says the haul includes engineering drawings, scans of facility test reports, site photos, and project plans. Shell has not confirmed what, if anything, was taken.
How did the hackers get in?
They appear to have exploited a flaw in engineering software that Shell and many industrial firms rely on. Clop listed Shell as one of 43 new alleged victims tied to attacks on internet-facing PTC Windchill and FlexPLM servers. These are Product Lifecycle Management platforms, meaning tools engineers use to design a product and track it through to manufacturing.
The bug being abused is tracked as CVE-2026-12569, an improper input validation flaw. In plain terms, the software failed to properly check data sent to it, letting an attacker sneak in commands and take over the system.
Security firm ReliaQuest says the attackers dropped JSP webshells on hacked servers. A webshell is a small hidden control panel that lets an intruder run commands and quietly siphon files. That matches the pattern of previous Clop campaigns, which have repeatedly hit file-transfer and enterprise apps to steal data at scale rather than encrypt it.
What is Clop and why does this fit its pattern?
Clop is a Russian-speaking extortion crew tracked under overlapping names including FIN11 and TA505 by various vendors. Its recent playbook is not classic ransomware. Instead of locking files, the group finds a fresh flaw in a widely deployed enterprise product, steals data from every exposed customer it can reach, then names victims on its leak site to squeeze payment. The MOVEit and GoAnywhere campaigns followed the same shape.
Attribution here rests on Clop's own claims plus corroboration from the Ransomware Information Sharing and Analysis Centre and ReliaQuest. Treat that as medium confidence pending forensic detail from victims.
Who else has been named?
Clop also claims to have stolen backups, system files, projects, drawings, and blueprints from General Electric and Philips. Neither company had commented at the time of writing. PTC has not responded to requests for comment either.
| Date | Event |
|---|---|
| June 17 | PTC begins releasing CVE-2026-12569 patches |
| June 26 | PTC warns of "heightened threat activity" |
| Late June | CISA adds the flaw to its Known Exploited Vulnerabilities catalog, gives federal agencies three days to patch |
| Late June | Germany's BSI issues an overnight warning to PTC customers |
PTC says its products are used by more than 30,000 customers globally, including over 1,500 brand and retail customers on FlexPLM. Users span aerospace, defence, automotive, heavy machinery, retail, and medical devices.
What should ordinary people do?
Probably nothing directly. This is an industrial software breach, not a consumer data leak. There is no sign, yet, that customer names, payment details, or loyalty accounts are involved. If that changes, Shell would be required to notify affected people under UK and EU data protection rules.
For engineering firms running Windchill or FlexPLM, ReliaQuest's advice is blunt: patch now, put the servers behind a VPN or trusted access gateway, and if you suspect a break-in, isolate the machine, preserve forensic evidence, and rotate any credentials that touched it.



