Skip to content
Tech News
← Back to articles

Shell investigates 'potential incident' after Clop data theft claims

read original more articles
Why This Matters

The investigation into Shell's potential data breach highlights the growing threat of ransomware gangs targeting critical infrastructure and multinational corporations. This incident underscores the importance of robust cybersecurity measures for large organizations to protect sensitive data and maintain operational integrity. For consumers and the industry, it emphasizes the need for heightened vigilance and proactive security protocols to prevent costly data breaches.

Key Takeaways

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.

Shell is a British multinational energy conglomerate and one of the world's top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily.

According to a recent post on Clop's dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.

"We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer when asked to confirm Clop's data theft claims.

While the company has yet to share more information, the Clop gang listed it on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.

As part of the same attacks, Clop also claimed it stole sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of tech conglomerates General Electric and Philips.

GE and Philips spokespersons were not immediately available for comment when BleepingComputer contacted them earlier today. A PTC spokesperson has also yet to reply to a request for comment.

Clop data theft claims (BleepingComputer)

​PTC began releasing CVE-2026-12569 security patches on June 17 and, even though it didn't confirm in-the-wild exploitation, it also released a private advisory urging customers to review environments for indicators of compromise (IOCs).

After PTC warned customers of "heightened threat activity" on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog, and ordering federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

... continue reading