Oil giant Shell is investigating a potential security incident following claims by the Clop ransomware gang that it stole 89GB of data. The alleged stolen files include sensitive information such as engineering drawings, facility testing reports, photos, and project plans.
The Clop gang listed Shell as one of 43 new victims, suggesting the data theft occurred through attacks targeting internet-exposed PTC Windchill and FlexPLM instances. These attacks exploited a critical improper input validation vulnerability, tracked as CVE-2026-12569.
Clop also claimed to have stolen data from General Electric and Philips using the same method. PTC began releasing security patches for CVE-2026-12569 on June 17. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the flaw is actively exploited and added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to secure affected systems. German authorities also issued an emergency warning to PTC customers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. This incident is linked to the exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM instances, a vulnerability that CISA has confirmed is actively exploited.