Protect.Computer
NEWS

Shell Probes Clop Data Theft as Ransomware Gang Claims 89GB Stolen

· 1 min read · Got hacked Data hijack
Shell Probes Clop Data Theft as Ransomware Gang Claims 89GB Stolen

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang posted it on their dark web leak site and claimed to have stolen 89GB of data. According to Clop’s post, the stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans. Shell — one of the world’s three largest oil and gas companies, with 85,000 employees across 70 countries — told BleepingComputer: “We are aware of a potential incident. We are working with our security teams and relevant experts to investigate.”

Clop listed Shell alongside 42 other organizations it says were targeted in a campaign exploiting CVE-2026-12569, a critical improper input validation vulnerability in PTC Windchill and FlexPLM — product lifecycle management software widely used in manufacturing and energy. In the same wave of attacks, Clop also claimed to have stolen data from General Electric and Philips, including backups, project files, diagrams, and blueprints. The gang has used this type of mass-exploitation playbook before, targeting widely deployed enterprise software to maximize the number of victims in a single campaign.

How to check if you’re affected

Affected products are PTC Windchill and FlexPLM instances exposed to the internet running vulnerable versions before the patch for CVE-2026-12569. If your organization uses either platform, check PTC’s security advisory for the patched versions and confirm whether your installation was internet-accessible during the exposure window. Review access logs for the application’s web interface for signs of unexpected API calls or bulk file access. If you find evidence of compromise, treat stolen data as a breach and notify relevant stakeholders per your incident response plan.

Sources

Related reading