Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. The allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
Intelligence analysis by Llama

Shell is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. The stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
Imagine you have a big company that makes oil and gas, and someone breaks into their computer system and steals some important documents. That's what happened to Shell, a big oil and gas company, and it's like a big puzzle to figure out what happened and how to fix it.
Analysis
Shell's Security Incident Investigation
Shell, a British multinational energy conglomerate and one of the world's top three oil and gas companies, has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. The allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
The investigation is ongoing, and Shell has not shared more information about the incident. However, the Clop gang listed Shell as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
PTC, the company behind Windchill and FlexPLM, began releasing CVE-2026-12569 security patches on June 17 and urged customers to review environments for indicators of compromise (IOCs). After PTC warned customers of 'heightened threat activity' on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog, and ordering federal agencies to secure their PTC Windchill and FlexPLM instances within three days.
CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch their systems as quickly as possible. Clop's Windchill and FlexPLM attacks were also confirmed by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) and by cybersecurity company ReliaQuest, which said that the threat actors have been deploying JSP webshells that allow them to steal sensitive data from victims' compromised PLM platforms.
The investigation into Shell's potential security incident is ongoing, and it remains to be seen what the outcome will be. However, the incident highlights the importance of securing software platforms like Windchill and FlexPLM against potential vulnerabilities and the need for companies to be proactive in addressing potential security threats.
Key points
- Shell is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
- The allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.
- The investigation is ongoing, and Shell has not shared more information about the incident.
- The Clop gang listed Shell as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
- PTC, the company behind Windchill and FlexPLM, began releasing CVE-2026-12569 security patches on June 17 and urged customers to review environments for indicators of compromise (IOCs).
If Shell is able to secure its systems and prevent further data theft, it could help to prevent similar incidents in the future and demonstrate the company's commitment to cybersecurity.
If the investigation into Shell's potential security incident reveals that the company was not proactive in addressing potential security threats, it could lead to a loss of trust in the company and potentially even regulatory action.



