← All stories
● Covered by 3 sources · 5 reportsMedium impact5 negative

Shell investigates potential data theft after Clop ransomware gang claims 89GB stolen

🔄 Updated 44d ago — new reporting from The Hacker News, SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Clop gang claims 89GB of Shell data stolen.
  • Stolen data includes engineering drawings and project plans.
  • Incident linked to CVE-2026-12569 exploitation in PTC Windchill/FlexPLM.
  • CISA confirmed active exploitation of the vulnerability.
  • General Electric (GE) is investigating Clop ransomware data theft claims.
  • Philips is investigating Clop ransomware data theft claims.
  • Philips confirmed a contained cybersecurity compromise of an internal server.
  • Philips stated the compromise had no impact on customer environments.
  • Clop created a custom Java web shell for PTC Windchill and FlexPLM servers.
  • The web shell decrypts credentials, enumerates file repositories, and steals files.
  • ReliaQuest analyzed the web shell after its deployment in attacks.
  • The web shell shows detailed knowledge of Windchill's internal APIs and database.
  • The web shell is a fully equipped extortion platform.
  • The web shell can run additional code via a custom Java class loader.
  • The web shell acts as a backdoor for remote access and post-exploitation activity.
  • CVE-2026-12569 has a CVSS score of 9.3.
  • CVE-2026-12569 is an improper input validation issue.
  • CVE-2026-12569 allows remote, unauthenticated arbitrary code execution.
  • CISA added CVE-2026-12569 to its KEV catalog in June.
  • PTC warned of attacks targeting CVE-2026-12569 in June.
  • CVE-2026-12569 is the first Windchill vulnerability exploited in the wild.
  • Clop affiliates exploited the flaw in late July.
  • Clop has named over 40 organizations targeted in the campaign.

Shell Investigates Data Theft Claims

Oil giant Shell is investigating a potential security incident following claims by the Clop ransomware gang that it stole 89GB of data. The alleged stolen files include sensitive information such as engineering drawings, facility testing reports, photos, and project plans.

Vulnerability Exploitation

The Clop gang listed Shell as one of 43 new victims, suggesting the data theft occurred through attacks targeting internet-exposed PTC Windchill and FlexPLM instances. These attacks exploited a critical improper input validation vulnerability, tracked as CVE-2026-12569.

Broader Impact and Official Warnings

Clop also claimed to have stolen data from General Electric and Philips using the same method. PTC began releasing security patches for CVE-2026-12569 on June 17. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the flaw is actively exploited and added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to secure affected systems. German authorities also issued an emergency warning to PTC customers.

Updates

🕒 2026-08-19 · new reporting from The Hacker News, SecurityWeek
  • The web shell is a fully equipped extortion platform.
  • The web shell can run additional code via a custom Java class loader.
  • The web shell acts as a backdoor for remote access and post-exploitation activity.
  • CVE-2026-12569 has a CVSS score of 9.3.
  • CVE-2026-12569 is an improper input validation issue.
  • CVE-2026-12569 allows remote, unauthenticated arbitrary code execution.
  • CISA added CVE-2026-12569 to its KEV catalog in June.
  • PTC warned of attacks targeting CVE-2026-12569 in June.
  • CVE-2026-12569 is the first Windchill vulnerability exploited in the wild.
  • Clop affiliates exploited the flaw in late July.
  • Clop has named over 40 organizations targeted in the campaign.
🕒 2026-08-18 · new reporting from BleepingComputer
  • Clop created a custom Java web shell for PTC Windchill and FlexPLM servers.
  • The web shell decrypts credentials, enumerates file repositories, and steals files.
  • ReliaQuest analyzed the web shell after its deployment in attacks.
  • The web shell shows detailed knowledge of Windchill's internal APIs and database.
🕒 2026-08-17 · new reporting from BleepingComputer
  • General Electric (GE) is investigating Clop ransomware data theft claims.
  • Philips is investigating Clop ransomware data theft claims.
  • Philips confirmed a contained cybersecurity compromise of an internal server.
  • Philips stated the compromise had no impact on customer environments.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Cl0p ransomware group has publicly identified more than 40 organizations allegedly targeted in a campaign exploiting CVE-2026-12569, a vulnerability in PTC's Windchill and FlexPLM platforms. This development confirms widespread exploitation of the flaw, leading to significant data theft from affected companies.

The Clop ransomware operation is deploying a specialized JavaServer Pages (JSP) web shell to exploit a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM servers. This web shell can decrypt credentials, map sensitive data, and execute arbitrary code, enabling data exfiltration and further compromise of engineering data and product designs.

The Clop ransomware group created a custom Java web shell specifically for PTC Windchill and FlexPLM servers to steal data, exploiting CVE-2026-12569. This specialized tool indicates a targeted approach to data theft from enterprise platforms, impacting organizations using these PTC products.

General Electric (GE) and Philips are investigating claims by the Clop ransomware gang that their systems were breached and data was stolen. Philips confirmed a contained cybersecurity compromise of an internal server, stating no customer impact, while GE is assessing the potential issue. This follows similar claims against Shell and is linked to an exploited vulnerability in PTC Windchill and FlexPLM software.

Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. This incident is linked to the exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM instances, a vulnerability that CISA has confirmed is actively exploited.