Suspected data theft

Following Clop Extortion: Shell Investigates Security Incident

Shell
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: FotograFFF/Shutterstock.com

Shell is investigating a suspected data theft. The Clop group claims to have stolen 89 GB of confidential data.

British energy giant Shell is currently investigating a potential security incident within its IT systems. The background involves claims by the Clop ransomware group, which states it has stolen roughly 89 gigabytes of sensitive company data. According to the attackers, the stolen files include technical engineering drawings, facility test reports, photographs of facilities, as well as strategic project plans. A Shell spokesperson confirmed the ongoing investigations to media representatives:

Ad

“We are aware of a potential incident. We are working with our security teams and relevant experts to investigate it.”

Shell

Ad

Shell is one of the world’s largest energy companies, serving more than 20 million customers daily across tens of thousands of service and charging stations. The company has not yet provided more specific details regarding the extent of the impact.

Exploitation of a Critical Vulnerability in PTC Software

The Clop extortion group listed Shell alongside 42 other companies as a new victim on its dark web leak platform. Other major conglomerates, such as General Electric and Philips, are also allegedly targeted in the campaign. According to security analysts, a critical vulnerability in the Product Lifecycle Management platforms PTC Windchill and FlexPLM, tracked as CVE-2026-12569, served as the entry point.

Security companies such as ReliaQuest and the organization Ransom-ISAC confirmed that attackers are actively exploiting the vulnerability. Threat actors deploy so-called JSP webshells onto publicly accessible servers to exfiltrate confidential development and corporate data. Both the US cybersecurity agency CISA and the German Federal Office for Information Security (BSI) had already warned of the acute threat in June and ordered the immediate patching of the flaw.

Recommended Protective and Remediation Measures

The affected PTC software is used worldwide by more than 30,000 customers in sectors such as aerospace, automotive, mechanical engineering, and energy. Security experts advise operators of the software to take the following steps:

  • Applying the security patches provided by PTC for Windchill and FlexPLM
  • Placing systems behind secured VPNs or trusted access gateways
  • In case of suspected compromise: Isolating affected servers, preserving forensic evidence, and rotating all credentials

(Editorial Team)

Ad

Weitere Artikel