Shell, the multinational energy conglomerate, has announced an investigation into a potential security incident following claims by the Clop ransomware group that it stole 89GB of data from the company. Shell confirmed it is working with its security teams and relevant experts to investigate the matter.
Clop listed Shell among 43 new victims on its dark web data leak site, asserting that the stolen files include engineering drawings, facility testing reports, facility photographs, and project plans. The group claims these thefts are part of a campaign exploiting a critical improper input validation vulnerability, CVE-2026-12569, in internet-exposed instances of PTC Windchill and FlexPLM software.
Beyond Shell, Clop has also claimed to have stolen sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of tech conglomerates General Electric and Philips, allegedly through the same vulnerability.
PTC, the vendor of Windchill and FlexPLM, began releasing security patches for CVE-2026-12569 on June 17. While PTC did not initially confirm in-the-wild exploitation, it issued a private advisory urging customers to review their environments for indicators of compromise.
On June 26, PTC warned customers of "heightened threat activity." Subsequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of the flaw, adding it to its Known Exploited Vulnerabilities catalog and mandating federal agencies to secure their PTC Windchill and FlexPLM instances within three days. German authorities, specifically the Federal Office for Information Security (BSI), also issued an urgent warning to PTC customers to patch their systems.
The Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) and cybersecurity firm ReliaQuest have both corroborated Clop's Windchill and FlexPLM attacks. ReliaQuest noted that threat actors have been deploying JSP webshells to exfiltrate sensitive data from compromised Product Lifecycle Management (PLM) platforms.
ReliaQuest has advised PTC customers to patch their Windchill and FlexPLM systems and, where feasible, to place them behind VPNs or trusted access gateways. In cases of suspected compromise, the firm recommends isolating affected servers, collecting forensic artifacts, and rotating any exposed credentials before restoring service.
PTC FlexPLM and PTC Windchill are enterprise software platforms used for tracking, designing, and managing products through their lifecycle up to manufacturing. These systems are widely adopted by engineering, manufacturing, quality, and supply chain teams in high-profile companies across various sectors, including aerospace, defense, automotive, heavy machinery, retail, and medtech. PTC states that its products serve over 30,000 customers globally, with more than 1,500 brand and retail customers utilizing FlexPLM.






