Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Australia politics live: Malinauskas warns Albanese not to follow One Nation down rabbit hole of migration cuts | Australia news

    September 9, 2026

    Spanish intelligence warned of Ceuta mass crossing plans before surge

    September 9, 2026

    Labour picks Camden leader to stand for Keir Starmer’s old seat

    September 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Australia politics live: Malinauskas warns Albanese not to follow One Nation down rabbit hole of migration cuts | Australia news
    • Spanish intelligence warned of Ceuta mass crossing plans before surge
    • Labour picks Camden leader to stand for Keir Starmer’s old seat
    • OpenAI’s sly mathematical breakthrough sends a chill through academia
    • AdaptHealth confirms 4.1 million people exposed in July cyberattack
    • Scott Bessent ‘Strongly Urges’ Senate To Pass Clarity Act
    • Winter work shows it really pays to be a smart mountain chickadee
    • An education in the arts should be available to all | Education
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Shell investigates ‘potential incident’ after Clop data theft claims

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.

    Shell is a British multinational energy conglomerate and one of the world’s top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily.

    According to a recent post on Clop’s dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.

    image

    “We are aware of a potential incident. We are working with our security teams and relevant experts to investigate,” a Shell spokesperson told BleepingComputer when asked to confirm Clop’s data theft claims.

    While the company has yet to share more information, the Clop gang listed it on its leak site as one of 43 new victims likely targeted in data theft attacks against Internet-exposed PTC Windchill and FlexPLM instances exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.

    As part of the same attacks, Clop also claimed it stole sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of tech conglomerates General Electric and Philips.

    GE and Philips spokespersons were not immediately available for comment when BleepingComputer contacted them earlier today. A PTC spokesperson has also yet to reply to a request for comment.

    Clop data theft claims
    Clop data theft claims (BleepingComputer)

    ​PTC began releasing CVE-2026-12569 security patches on June 17 and, even though it didn’t confirm in-the-wild exploitation, it also released a private advisory urging customers to review environments for indicators of compromise (IOCs).

    After PTC warned customers of “heightened threat activity” on June 26, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed that the flaw is actively exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog, and ordering federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

    CVE-2026-12569 also prompted emergency action from German authorities, with the Federal Office for Information Security (BSI) warning PTC customers in the middle of the night to patch their systems as quickly as possible.

    Clop’s Windchill and FlexPLM attacks were also confirmed by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats, and by cybersecurity company ReliaQuest, which said that the threat actors have been deploying JSP webshells that allow them to steal sensitive data from victims’ compromised PLM platforms.

    ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and, where possible, place them behind VPNs or trusted access gateways. Additionally, if compromise is suspected, they should isolate affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.

    PTC FlexPLM and PTC Windchill are enterprise software platforms in the Product Lifecycle Management (PLM) category, used to track, design, and manage products up to final manufacturing.

    The two systems are widely popular among engineering, manufacturing, quality, and supply chain teams at high-profile companies across the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says that its products are used by over 30,000 customers globally, including more than 1,500 brand and retail customers using FlexPLM.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    claims Clop data incident investigates potential Shell theft
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AdaptHealth confirms 4.1 million people exposed in July cyberattack

    U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

    China slams US claims of ‘industrial-scale’ AI theft | Science and Technology News

    Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

    How to pen test LLM, RAG and GenAI applications

    US says Chinese firms extracted billions of tokens from frontier AI models

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Australia politics live: Malinauskas warns Albanese not to follow One Nation down rabbit hole of migration cuts | Australia news

    September 9, 2026

    Spanish intelligence warned of Ceuta mass crossing plans before surge

    September 9, 2026

    Labour picks Camden leader to stand for Keir Starmer’s old seat

    September 9, 2026

    OpenAI’s sly mathematical breakthrough sends a chill through academia

    September 9, 2026
    Latest Posts

    Justice Dept. Subpoenas Times Freelancer in Effort to Identify Sources

    August 1, 2026

    Michigan joins Minnesota in reporting cyberattacks, with FBI investigating | Cybercrime News

    August 1, 2026

    Tiny aerosol particles could supercharge tropical storm clouds

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Australia politics live: Malinauskas warns Albanese not to follow One Nation down rabbit hole of migration cuts | Australia news

    September 9, 2026

    Spanish intelligence warned of Ceuta mass crossing plans before surge

    September 9, 2026

    Labour picks Camden leader to stand for Keir Starmer’s old seat

    September 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.