← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Shell investigates potential data theft after Clop ransomware gang claims 89GB stolen

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Clop gang claims 89GB of Shell data stolen.
  • Stolen data includes engineering drawings and project plans.
  • Incident linked to CVE-2026-12569 exploitation in PTC Windchill/FlexPLM.
  • CISA confirmed active exploitation of the vulnerability.

Shell Investigates Data Theft Claims

Oil giant Shell is investigating a potential security incident following claims by the Clop ransomware gang that it stole 89GB of data. The alleged stolen files include sensitive information such as engineering drawings, facility testing reports, photos, and project plans.

Vulnerability Exploitation

The Clop gang listed Shell as one of 43 new victims, suggesting the data theft occurred through attacks targeting internet-exposed PTC Windchill and FlexPLM instances. These attacks exploited a critical improper input validation vulnerability, tracked as CVE-2026-12569.

Broader Impact and Official Warnings

Clop also claimed to have stolen data from General Electric and Philips using the same method. PTC began releasing security patches for CVE-2026-12569 on June 17. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the flaw is actively exploited and added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to secure affected systems. German authorities also issued an emergency warning to PTC customers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. This incident is linked to the exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM instances, a vulnerability that CISA has confirmed is actively exploited.