CVE Tools

Shell investigates 'potential incident' after Clop data theft claims

BleepingComputerBy Sergiu Gatlan

Reported exploitedPTC WindchillClopPTC FlexPLM

Our summary

Major energy firm Shell has begun investigating a potential security incident following claims by the Clop ransomware group that they exfiltrated 89GB of sensitive data, including engineering drawings and facility reports. The theft is attributed to active exploitation of CVE-2026-12569, a critical input validation flaw in internet-facing instances of PTC Windchill and FlexPLM. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply patches released by PTC and check for indicators of compromise.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store